The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) announced that mandatory compliance inspections of data controllers will commence on 1 September 2026. The inspections will span both the public and private sectors, targeting banks, insurance companies, healthcare providers, schools, local authorities, telecommunications companies and many other organisations that process personal data. The sweeping nature […] The post Why Our Data Protection Regulations Need Review app
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) announced that mandatory compliance inspections of data controllers will commence on 1 September 2026. The inspections will span both the public and private sectors, targeting banks, insurance companies, healthcare providers, schools, local authorities, telecommunications companies and many other organisations that process personal data.
The sweeping nature of the compliance requirements prompts us to question whether our current regulatory approach is the right one.
Data protection is not the problem
Few would disagree that personal data needs protection. So, Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] was an important milestone. Enacted in 200, it introduced long overdue protections for personal information, established data subject rights and designated POTRAZ as the country’s Data Protection Authority.
However, the subsequent Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155 of 2024) went further to introduce mandatory licensing fees for data controllers and required many organisations to appoint Data Protection Officers (DPOs).
This brought significant recurring compliance costs making data protection a cost of doing business across the entire economy. This counters government’s recent efforts to reduce the cost of doing business in the country.
We borrowed from the GDPR—but not its philosophy
Zimbabwe’s legislation certainly draws inspiration from the European Union’s General Data Protection Regulation (GDPR). The terminology and concepts are familiar and both frameworks claim to adopt a risk-based approach. Yet, the implementation is vastly different!
The GDPR is fundamentally accountability-driven whereas Zimbabwe’s framework is primarily licensing-driven. Under the GDPR, organisations are not required to obtain permission from the regulator before processing personal data. Instead, they are expected to assess the risks created by their processing activities, implement safeguards that are proportionate to those risks, and demonstrate compliance if challenged.
The Zimbabwean regulation takes a different route. It requires organisations to obtain licences, pay annual fees and appoint Data Protection Officers before undertaking any processing activities.
Assumed risk not actual risk
The biggest difference is how Zim’s current framework interprets risk.
The GDPR deliberately avoids fixed numerical thresholds when determining whether processing presents significant risk. Instead, regulators consider several factors together:
In contrast, Zimbabwe’s licensing obligations are tied largely to prescribed categories and processing thresholds based on the number of data subjects. This results in organisations with very different risk profiles facing broadly similar compliance obligations.
One size for all regulation
Consider a small private medical practice. Its patient records are undoubtedly sensitive, but it serves a relatively small number of patients, has limited staff and operates within a constrained budget and pre-existing regulations. Under the current framework, that clinic is required to obtain a data controller licence and engage a Data Protection Officer. Whereas in the E.U it would not be required to do so
A school, a pharmacy, a local NGO and a growing software startup find themselves navigating comparable licensing requirements with a bank or insurance company despite having fundamentally different operational risks and financial capacity. The current data regulatory framework ignores that the scale, complexity and potential consequences of a data breach are vastly different even though they may handle the same number of data subjects.
The impact on startups
This has a negative bearing on Zimbabwe’s technology ecosystem.
For many startups, the first objective is to build a minimum viable product (MVP), validate a market and secure investment. Every additional regulatory obligation increases the cost and complexity of reaching that milestone. Under the current framework, a founder developing a healthcare app, educational platform or logistics solution needs to also budget for data controller licensing fees and DPO-related costs before engaging in any data collection or processing. Some founders have responded by obtaining DPO certification themselves simply to satisfy compliance requirements—an investment that can cost over US$1,250 before they have acquired a single customer. Large corporations can absorb these costs whereas early stage startups often cannot. When regulation creates significant upfront fixed costs, it unintentionally favours established incumbents over innovators.
Regulation should enable innovation, not discourage it
Zimbabwe’s recently launched National Artificial Intelligence Strategy (2026–2030) recognises that the country’s regulatory environment must evolve to make Zimbabwe “AI-ready.” It explicitly calls for achieving an appropriate balance between protecting personal data and enabling innovation. That balance is essential. As POTRAZ begins nationwide inspections, there may be no better time to revisit whether our data protection regulations are achieving that balance.
Good regulation should scale according to risk. A revised framework could retain strong protections for citizens while adopting a genuinely risk-based model. Regulatory obligations such as licensing or DPO appointments should reflect the nature, scope, context and purpose of processing rather than relying primarily on broad categories or numerical thresholds. This reduces unnecessary compliance costs for low-risk organisations while allowing regulators to focus on where the greatest risks actually exist.
Dr Marlon-Ralph Nyakabau
Medical Doctor, Digital Health Consultant, Public Policy Analyst
The post Why Our Data Protection Regulations Need Review appeared first on Techzim.