Friday, 31 July 2026PREMIUM EDITORIAL
POTRAZ Data Licence Fees Draw Cost Burden Concerns

POTRAZ Data Licence Fees Draw Cost Burden Concerns

Z
ZimCelebs·July 31, 2026·4 min read

The government’s decision to require organisations that process personal data to obtain annual licences from the Postal and Telecommunications Regulatory Autho...

BREAKING:

The government’s decision to require organisations that process personal data to obtain annual licences from the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) has attracted criticism from analysts, who warn that the compliance costs could place a significant financial burden on businesses, churches, schools and civic organisations while increasing the cost of goods and services for consumers.

The concerns follow the publication of Regulatory Notice 2 of 2026, under which POTRAZ announced that mandatory compliance inspections and assessments of data controllers will begin on September 1, 2026, in accordance with the Cyber and Data Protection Act.

Under Statutory Instrument 155 of 2024, organisations that process the personal data of 50 or more individuals are required to obtain a data controller licence from POTRAZ. The law applies to organisations that collect or process personal information such as names, addresses, telephone numbers, national identity numbers, employment records, health information and biometric data.

Advertisement

Although the licensing requirement took effect in September 2024, with organisations expected to comply by March 12, 2025, many organisations are believed to have not yet registered. The licensing framework forms part of the Cyber and Data Protection Act, which designates POTRAZ as Zimbabwe’s Data Protection Authority.

Government says the regulations are intended to strengthen the protection of personal information and improve accountability in the handling of sensitive data as concerns over cybercrime, identity theft and data breaches continue to grow. However, the planned inspections have raised questions over whether many organisations understand that they fall within the scope of the law.

Schools maintaining class registers, churches keeping membership records, medical practices holding patient files and retailers operating customer databases may all be required to obtain licences if they process the personal information of at least 50 individuals. While the legislation exempts personal or household use, law enforcement activities and certain journalistic, historical or archival functions, organisations operating in some of those areas may still be required to register under the regulatory framework.

Under the fee structure, organisations processing data for between 50 and 1,000 people must pay an annual licence fee of US$50. Those handling between 1,001 and 100,000 records pay US$300 plus a US$30 application fee, while organisations with larger databases pay annual fees ranging from US$500 to US$2,500, depending on the number of records processed.

The licence fee represents only part of the compliance costs. Every registered organisation is required to appoint a certified Data Protection Officer and notify POTRAZ. Certification currently costs US$1,250, excluding a US$30 application fee, meaning even a small organisation paying the minimum licence fee could face first-year compliance costs exceeding US$1,300 unless it appoints an external consultant.

Failure to comply with the regulations carries significant penalties. Organisations processing personal data without a licence risk a Level 11 fine, imprisonment of up to seven years for their chief executive officer, or both. Similar penalties apply to organisations that fail to adequately safeguard personal information, while any data breach must be reported to POTRAZ within 24 hours, with affected individuals notified within 72 hours.

Legal expert Dr Vusumuzi Sibanda said regulating the use of personal information is common international practice but questioned Zimbabwe’s licensing model and associated fees. “The control of personal information is something that happens across the world to make sure that personal information is not abused or used beyond the interests of the owners of that information,” he said. “But what is new and strange is the need for registration and licence fees so that organisations must register. You can make sure people comply when they keep information without forcing companies to register and pay licence fees.”

Dr Sibanda said the regulations extend beyond large companies to churches, schools and voluntary organisations that keep basic membership records. “Imagine having licences for churches and voluntary organisations simply because they handle personal information,” he said. “In church, how do people really handle personal information? They don’t require identity documents in most cases because membership is voluntary. Why would you require those organisations to make such payments?” He added that the regulations could eventually affect burial societies, savings clubs and other community organisations, questioning whether the licensing framework was intended to strengthen data protection or raise revenue. Another analyst, Mxolisi Ncube, warned that organisations are likely to pass the cost of compliance on to consumers. “Complying with these rules costs stakeholders a lot of money, meaning people must expect more expensive airtime, data and other charges,” he said. While government maintains the regulations will improve privacy protection and accountability in the handling of personal information, critics argue that the high cost of compliance could place an excessive financial burden on businesses, churches, schools and community groups as mandatory inspections begin in September.

Advertisement

Comments

Leave a comment

Comments are moderated before appearing.

Advertisement

Next for you

Hand-picked stories you might have missed