๐Ÿšจ

POTRAZ Enforcement Active: The data controller licensing deadline was 12 March 2025. Non-compliant organisations face Level 11 fines and up to 7 years imprisonment. Regularise now.

Zimbabwe's CDPA Compliance Platform

Is Your Organisation Legally Compliant with Zimbabwe's Data Law?

Under the Cyber & Data Protection Act [Chapter 12:07] and S.I. 155 of 2024, every organisation processing personal data must be POTRAZ-licensed. CDPA Solutions provides automated compliance tools, POTRAZ-certified DPO services, and sector-specific frameworks โ€” so you stay protected.

๐Ÿ“‹ Compliance Status Dashboard
โš 
POTRAZ Data Controller Licence (Form DP1)
Mandatory for all organisations processing personal data. Deadline: 12 March 2025.
Required
๐ŸŽ“
POTRAZ-Certified DPO Appointment (Form DP2)
Must be certified by POTRAZ or an Authority-accredited institution. Notify within 14 days of appointment.
Pending
๐Ÿ“„
Written Consent & Cross-Border Authorisation
Written consent required for sensitive data. Separate POTRAZ authorisation needed for offshore cloud storage.
Required
๐Ÿšจ
24-Hour Breach Protocol (Form DP3)
Notify POTRAZ within 24hrs via Form DP3. Notify affected data subjects within 72hrs.
Set Up Now
5,000+
Organisations at Risk in Zimbabwe
7 yrs
Max Imprisonment โ€” Unlicensed Processing
24 hrs
Statutory Breach Notification to POTRAZ
30 days
Time to Full Compliance with Our Toolkit
The Compliance Crisis

The Deadline Has Passed.
POTRAZ is Auditing Now.

Most organisations in Zimbabwe are legally exposed. They know the law exists but lack the tools and expertise to comply. CDPA Solutions changes that.

S.I. 155 of 2024 โ€” Section 3 & 4

Data Controller Licensing

Every entity processing personal data for commercial gain must hold a POTRAZ licence before processing begins. The deadline was 12 March 2025. Operating without a licence is now a criminal offence liable to Level 11 fines or up to 7 years imprisonment.

S.I. 155 of 2024 โ€” Section 12 | CDPG 1 of 2024

Mandatory DPO Appointment

Every data controller must appoint a DPO and notify POTRAZ via Form DP2 within 14 days. The DPO must hold a certification course approved by POTRAZ. Failure to appoint carries a fine not exceeding Level 7 and/or up to 2 years imprisonment. Note: Tier 1 controllers may be exempt from DPO appointment depending on sector and nature of processing โ€” schools processing children's data are NOT exempt.

CDPA Section 28 | CDPG 5 of 2024

Cross-Border Transfer โ€” Separate Authorisation Required

Using Google Workspace, Microsoft 365 or any offshore cloud constitutes a cross-border transfer. You must: notify POTRAZ in writing, conduct a DPIA, obtain data subject consent, and apply for a separate POTRAZ authorisation. Disclosure to parents alone is insufficient.

CDPA Section 12 | CDPG 2 of 2024

Children's Data โ€” Highest Risk Category

Schools processing children's data face the strictest obligations: written parental consent, regular DPIAs, data protection by design and default, verification of guardian identity, and no automated decision-making affecting children's rights. Cross-border transfers of children's data require prior POTRAZ authorisation.

โš– What Non-Compliance Costs
L11
Processing Without a Licence Level 11 fine and/or up to 7 years imprisonment. Applies to unlicensed processing, security breaches, cross-border violations, and children's data contraventions. (S.I. 155 Sections 3, 10, 16, 17)
L7
Failure to Appoint a DPO Level 7 fine and/or up to 2 years imprisonment specifically for failing to appoint a DPO or notify POTRAZ of the appointment. (S.I. 155 Section 12(6))
21d
Breach Investigation Report After reporting a breach to POTRAZ, a full investigation report must be submitted within 21 days. Failing to cooperate or respond within 14 days to POTRAZ information requests is a separate Level 11 offence.
Our Solutions

Compliance Tools Built for Zimbabwe

Sector-specific frameworks built around the exact requirements of the CDPA, S.I. 155 of 2024, and the POTRAZ Implementation Guidelines โ€” not generic templates.

๐Ÿซ SafeSchool Edition

Complete CDPA Compliance for Schools & Educational Institutions

Schools are the highest-risk category. You process sensitive data of children (under 18) โ€” placing you under the strictest provisions of both CDPA Section 12 and CDPG 2 of 2024. Schools are not eligible for Tier 1 DPO exemption due to the nature of their processing.

  • โœ“
    Board-approved Internal Data Protection Policy tailored for schools
  • โœ“
    CDPA-compliant Parental Consent Forms with guardian identity verification
  • โœ“
    DPIA template for new digital systems (CCTV, biometrics, e-learning apps)
  • โœ“
    Staff Confidentiality Agreement + Data Awareness Training & Quiz
  • โœ“
    Vendor Data Processing Agreements (Google, Microsoft, EdTech)
  • โœ“
    Cross-Border Transfer Notification package + POTRAZ authorisation assistance
  • โœ“
    24-Hour Breach Protocol with Form DP3 pre-filled template
  • โœ“
    POTRAZ-certified DPO to sign Form DP2 and liaise with POTRAZ
Get SafeSchool โ†’
๐Ÿ“ SafeSchool Document Bundle
๐Ÿ“‹
Data Protection Policy
Board-ready ยท .DOCX
Included
โœ๏ธ
Parental Consent Form (3-tier)
Guardian verified ยท .PDF
Included
๐Ÿ”
DPIA Template
Risk assessment ยท .DOCX
Included
๐ŸŒ
Cross-Border Transfer Package
POTRAZ authorisation ยท .DOCX
Professional+
๐Ÿค
Vendor DPA Agreement
IT vendors ยท .DOCX
Included
๐Ÿ‘จโ€๐Ÿ’ผ
Staff NDA + Training Quiz
10 questions ยท .PDF
Included
๐Ÿšจ
Form DP3 Breach Template
24hr protocol ยท .PDF
Included
๐Ÿ†
Certificate of Conformance
Post-POTRAZ filing ยท .PDF
Professional+
๐Ÿฅ MedShield Edition

Patient Data Protection for Clinics, Practices & Pharmacies

Health data is explicitly classified as sensitive data under CDPA Section 12. Only a health professional may process health-related data, and written consent is required for biometric, genetic and health data processing.

  • โœ“
    Medical Practice Data Protection Policy (CDPA Section 12-compliant)
  • โœ“
    Patient Information & Written Consent Form
  • โœ“
    Health Record Data Processing Agreement for labs and specialists
  • โœ“
    Pharmacy dispensing data retention & deletion policy
  • โœ“
    POTRAZ-certified DPO with health sector understanding
  • โœ“
    POTRAZ Form DP1 & DP2 filing assistance
Get MedShield โ†’
๐Ÿ“ MedShield Document Bundle
๐Ÿฅ
Medical Practice Privacy Policy
CDPA Section 12 ยท .DOCX
Included
๐Ÿฉบ
Patient Written Consent
Sensitive data ยท .PDF
Included
๐Ÿ’Š
Pharmacy Data Protocol
Dispensing records ยท .DOCX
Included
๐Ÿ”ฌ
Lab/Specialist DPA
Referral data ยท .DOCX
Included
๐Ÿšจ
Breach Response Protocol + DP3
24hr rule ยท .PDF
Included
๐Ÿฆ FinGuard Edition

CDPA Compliance for MFIs, SACCOs & Credit Providers

MFIs process National IDs, financial history and credit data โ€” all classified as sensitive data under the CDPA. FinGuard addresses both POTRAZ data protection obligations and RBZ KYC requirements.

  • โœ“
    MFI/SACCO Data Protection Policy (POTRAZ & RBZ aligned)
  • โœ“
    KYC & Loan Application Privacy Consent Form
  • โœ“
    Debt Collection Agent Data Processing Agreement
  • โœ“
    Credit Bureau data sharing protocol and client disclosure
  • โœ“
    POTRAZ-certified DPO for Form DP1 & DP2 filing
Get FinGuard โ†’
๐Ÿ“ FinGuard Document Bundle
๐Ÿฆ
MFI Privacy Framework
RBZ & CDPA ยท .DOCX
Included
๐Ÿ“
KYC Consent Form
Loan applications ยท .PDF
Included
๐Ÿ“ž
Debt Collector DPA
Agent agreements ยท .DOCX
Included
๐Ÿ”
Credit Data Protocol
Bureau sharing ยท .DOCX
Included
๐Ÿ  PropSafe Edition

Tenant & Buyer Data Protection for Real Estate Agencies

Property managers collect ID copies, payslips, and bank statements from every tenant and buyer. PropSafe legally secures your data handling and ensures cross-border compliance if your landlords are international.

  • โœ“
    Real Estate Agency Data Protection Policy
  • โœ“
    Tenant Application Written Consent & Disclosure Form
  • โœ“
    Right to Erasure procedure for expired lease data
  • โœ“
    Cross-border transfer protocol for international landlords
  • โœ“
    POTRAZ Form DP1 filing guide and DPO matching
Get PropSafe โ†’
๐Ÿ“ PropSafe Document Bundle
๐Ÿ 
Agency Privacy Policy
CDPA-compliant ยท .DOCX
Included
๐Ÿ“‹
Tenant Consent Form
Lease applications ยท .PDF
Included
๐Ÿ—‘๏ธ
Data Erasure Protocol
Post-lease deletion ยท .DOCX
Included
๐Ÿช BizSecure Edition

Affordable CDPA Compliance for Zimbabwean SMEs

If you collect customer names, emails or payment data and have 50 or more data subjects, you are a Data Controller under the CDPA. BizSecure covers the Tier 1 licensing threshold (50โ€“1,000 data subjects).

  • โœ“
    SME Data Protection Policy (Tier 1 POTRAZ licensing)
  • โœ“
    Customer Privacy Notice (website & physical display)
  • โœ“
    POTRAZ Form DP1 step-by-step completion guide
  • โœ“
    Basic Staff Acceptable Use Policy
  • โœ“
    Data Asset Register (Excel) with retention schedule
Get BizSecure โ†’
๐Ÿ“ BizSecure Document Bundle
๐Ÿช
SME Privacy Policy
Tier 1 POTRAZ ยท .DOCX
Included
๐ŸŒ
Customer Privacy Notice
Web & print ยท .PDF
Included
๐Ÿ“Š
Data Asset Register
Excel tracker ยท .XLSX
Included
How It Works

From Zero to Audit-Ready in 30 Days

1

Purchase & Onboard

Select your sector toolkit. Pay via EcoCash, Zimswitch or bank transfer. Access your compliance dashboard immediately.

2

POTRAZ-Certified DPO Assigned

A POTRAZ-certified DPO is matched to your account. They review your data footprint and initiate POTRAZ filings within 24 hours.

3

Documents, Filing & Authorisation

Forms DP1 and DP2 filed with POTRAZ. Cross-border authorisation applied for if required. All within 5 business days.

4

Certified & Protected

Receive your Certificate of Conformance. Organisation is POTRAZ-registered, legally protected, and audit-ready.

Transparent Pricing

Compliance That Fits Your Budget

Every tier includes core CDPA documentation. Upgrade for POTRAZ-certified DPO oversight and ongoing compliance management.

Starter Kit
Digital Toolkit
USD299
Once-off ยท Annual update subscription

For smaller organisations ready to manage compliance internally with the right documents.

  • โœ“ All sector-specific document templates
  • โœ“ POTRAZ Form DP1 & DP2 completion guide
  • โœ“ Data Asset Register (Excel)
  • โœ“ Cross-border transfer checklist
  • โœ“ Email support
Get Starter Kit
Full DPO Service
Enterprise
USD2,500
Per year ยท Multi-campus available

For school groups, hospital networks, or MFIs with multiple branches requiring a dedicated compliance programme.

  • โœ“ Everything in Professional
  • โœ“ Fully customised documentation suite
  • โœ“ On-site staff training workshop
  • โœ“ Named dedicated POTRAZ-certified DPO
  • โœ“ Multi-campus / multi-branch licensing
  • โœ“ POTRAZ inspection preparation
Contact Sales

All prices in USD. EcoCash, Zimswitch and bank transfer accepted. POTRAZ licensing fees (Tier 1: $50 | Tier 2: $300 | Tier 3: $500 | Tier 4: $2,500) are separate government charges payable directly to POTRAZ.

Industries We Serve

Sector-Specific Compliance Frameworks

๐Ÿซ
SafeSchool

Schools & Education

Highest-risk category. Children's data obligations, parental consent, DPIAs and cross-border authorisation for cloud services.

Explore SafeSchool โ†’
๐Ÿฅ
MedShield

Medical & Pharmacy

Health, biometric and genetic data require written consent under CDPA Section 12. Only health professionals may process health data.

Explore MedShield โ†’
๐Ÿฆ
FinGuard

Finance & MFIs

Financial history and ID data are sensitive under CDPA. FinGuard satisfies both POTRAZ and RBZ compliance obligations.

Explore FinGuard โ†’
๐Ÿ 
PropSafe

Real Estate

Every tenancy application collects sensitive data. PropSafe ensures legally compliant data handling from Day 1.

Explore PropSafe โ†’
For DPO Professionals

Join the CDPA Solutions POTRAZ-Certified DPO Partner Network

Are you a POTRAZ-certified Data Protection Officer? We provide the clients and infrastructure โ€” you provide the professional certification and oversight.

  • ๐Ÿ’ผ

    Zero Client Acquisition Cost

    We handle all sales and marketing. You focus on delivering compliance services to organisations we place with you.

  • ๐Ÿ“ˆ

    Manage Multiple Clients Efficiently

    Our automated toolkit handles 80% of groundwork. You review, advise, sign Form DP2, and liaise with POTRAZ.

  • ๐Ÿ’ฐ

    60% of Monthly Retainer

    You carry the professional oversight responsibility and receive the larger share. The data controller remains ultimately liable under CDPA Section 33(2).

  • ๐Ÿ”’

    Governed by Formal SLA

    Clear response time obligations: 4 hours for critical breaches, 24 hours for high-priority POTRAZ requests, 48 hours for standard queries.

Apply to Join the Network โ†’
๐ŸŽ“POTRAZ Certified

Certified DPOs

POTRAZ-approved certification or accredited equivalent required. Foreign nationals may qualify if registered by POTRAZ.

โš–๏ธLaw Firms

Tech Law Specialists

Lawyers with POTRAZ-certified DPO status can provide clients both legal advice and official DPO oversight.

๐Ÿ’ปIT Auditors

IT Audit Firms

IT security professionals with POTRAZ certification can extend compliance services through our platform.

๐Ÿค60/40 Model

Clear Revenue Share

60% of retainer to POTRAZ-certified DPO. 40% to CDPA Solutions platform. 30/70 on one-off toolkit sales.

๐Ÿ›๏ธ

POTRAZ โ€” Data Protection Authority

1110 Performance Close, Mt Pleasant Business Park, Harare
P.O. Box MP 843, Mt Pleasant

๐Ÿ“ง

Contact POTRAZ Directly

dataprotectionunit@dpa.zw
regulator@potraz.zw
+263 242 333032/46/48

๐ŸŒ

Online Resources

Forms DP1, DP2 and DP3 available at
www.potraz.zw
Consult the registration guide before completing Form DP1.

Every Day Without Compliance is a Criminal Liability

POTRAZ is actively auditing. The 12 March 2025 deadline has passed. There is no "I didn't know" defence under the CDPA. Get your organisation protected today.

Start Compliance Today โ†’ View Pricing
Get in Touch

Let's Get Your Organisation Compliant This Week

Our team responds within 24 hours. Tell us about your organisation and we will recommend the right compliance framework and connect you with a POTRAZ-certified DPO partner.

  • ๐Ÿ“
    Location
    Harare, Zimbabwe
  • ๐Ÿ“ฑ
    WhatsApp
    +263 7XX XXX XXX
  • ๐Ÿ“ง
    Email
    info@cdpasolutions.co.zw
  • ๐Ÿ’ป
    Client Portal
    portal.cdpasolutions.co.zw

Request a Compliance Assessment

We respond within 24 hours. Your data is processed under our own CDPA-compliant privacy policy.