Data Controller License Tiers and Fees in Zimbabwe (2026) β€” CDPA Compliance and DPO Requirements

Introduction

Zimbabwe’s Cyber and Data Protection Act (CDPA) requires many organisations and individuals who process personal data to obtain a Data Controller License from the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ). This annual licence is part of a larger data protection framework designed to protect privacy and regulate digital data processing across the country.

🎟️ What Is a Data Controller License?

A Data Controller License legally authorises a business or individual to process personal data within Zimbabwe. This applies to organisations that collect, store, or use information that can identify a person β€” like names, phone numbers, or email addresses.

πŸ“Š Data Controller License Tiers and Fees (2026)

The licensing fees are tiered based on the number of data subjects (individuals whose data you process):

Tier Number of Data Subjects Annual Fee (USD) Tier 1 50 – 1,000 $50 Tier 2 1,001 – 100,000 $300 Tier 3 100,001 – 500,000 $500 Tier 4 More than 500,000 $2,500

πŸ’‘ Licences are valid for 12 months and must be renewed before expiry.

πŸ“Œ Who Needs a License?

You must apply for a Data Controller License if you:

Collect or process personal data for commercial use

Operate online platforms, customer databases, or apps

Are a business, charity, church, or community group that keeps personal data (e.g., member info, customer details)

Even some WhatsApp group admins processing personal information may need a licence under the CDPA regulations.

Exemptions: Personal, family, household data or data used for law enforcement, archive, or historical purposes may be exempt.

πŸ‘©β€πŸ’Ό Certified Data Protection Officer (DPO) Requirement

Under the CDPA and its regulations, every data controller must appoint a certified Data Protection Officer (DPO).

πŸ” Who Can Be a DPO?

A DPO should:

Have knowledge of data protection laws

Understand data processing practices

Possess skills in data science, cybersecurity, law, or information systems

Pass a certification course approved by POTRAZ before appointment can be confirmed (certificate required to notify POTRAZ).

πŸ’° DPO Training & Certification Fees (2026)

POTRAZ regulations set the DPO training and certification costs as follows:

Zimbabwean citizens: US$1,250 per person

International applicants: US$1,450 per person

Application fee (Zim citizens): US$30 per person

Application fee (International): US$50 per person

πŸ”’ Note: This fee covers the DPO certification course β€” a statutory requirement before appointment notification.

πŸ—“οΈ Other Fee Notes

Additional application fees for licence submission may apply for certain tiers.

POTRAZ may charge for ad hoc training activities or accreditation events.

πŸ“ Why This Matters

Without a valid Data Controller License:

You may face fines or criminal penalties under the CDPA.

Operating without a licence could jeopardise your business’s legal compliance.

Appointing and certifying a DPO is not optional β€” it’s required by the CDPA’s regulations for organisations processing personal data.

Summary

Data Controller Licences are tiered annually from US$50 to US$2,500, depending on the data subject count.

Licences are valid for 12 months and must be renewed.

A certified DPO is required before you can complete your licence application.

Fees for DPO certification can be costly, but they’re mandatory for compliance.

πŸ“± Need Help With Your Application?

If you need support with applying for a Data Controller License, appointing or certifying a Data Protection Officer, or understanding CDPA compliance in Zimbabwe, πŸ‘‰ contact me on WhatsApp: πŸ“² https://wa.me/0775345860