POTRAZ Turns Spotlight on Churches, SMEs in Data Privacy Sweep

Religious institutions and small businesses face surprise audits as regulator expands crackdown beyond corporates.

By Jonathan Mbiriyamveka | Harare

Churches, informal traders, and small enterprises are the unexpected targets of POTRAZ’s 2025 data protection blitz, with mandatory licensing and audits set to roll out by September, the regulator confirmed at the weekend.

The move, part of POTRAZ’s Compliance and Enforcement Roadmap presented by Director General Gift Machengete on Friday, aims to plug gaps in sectors previously overlooked for data violations.

“Data privacy isn’t just for big corporations. Churches collect member details; vendors use mobile money—they must comply,” said Dr. Machengete during the roadmap’s unveiling.

License Deadline: All entities processing customer data must obtain a Data Controller License by October 2025 or face fines.

Surprise Inspections: POTRAZ will audit high-risk sectors, including churches storing congregant databases and SMEs using client WhatsApp groups.

Penalties: Non-compliance could trigger US$5,000 fines or operational suspension.

At Harare’s Jubilee Faith Ministries, administrator Tendai Moyo admitted ignorance: “We keep attendance registers, but no one told us about data licenses.”

Similar confusion reigns at Mbare Market, where vendor James Chidemo said, “I use EcoCash—does that mean I need a license?”

“Ignorance won’t be an excuse,” warned tech analyst Ruvimbo Gumbo. “POTRAZ’s nationwide training starts next month, but businesses must act fast.”

With 72% of Zimbabwe’s economy informal, the crackdown could disrupt operations but also curb rampant misuse of personal data.

About Author