Healthcare providers are explicitly named in POTRAZ's first inspection wave beginning 1 September 2026. The licensing deadline was 12 March 2025. If your practice is not yet licensed, find out where you stand — in 60 seconds, no email required.
Free · No email gate · Built in Harare by AfrIgnite Smart Solutions
1 Sept
Inspections begin
7 yrs
Max imprisonment for unlicensed processing (S.I. 155)
24 hrs
To notify POTRAZ of a breach
50+
Data subjects triggers the licence requirement
The debrief
On 26 July 2026, POTRAZ issued Regulatory Notice 2 of 2026. From 1 September 2026 the Authority will conduct mandatory compliance inspections of data controllers under the Cyber and Data Protection Act [Chapter 12:07] (CDPA) and Statutory Instrument 155 of 2024.
POTRAZ has stated it will take a risk-based approach, starting with sectors that hold the most sensitive personal data. Healthcare providers are explicitly named in that first wave — alongside financial institutions, insurers, local authorities, schools and government departments.
The original deadline to be registered and licensed as a data controller was 12 March 2025. POTRAZ has expressly invited non-compliant organisations to still apply. Acting before an inspection is a materially better position than being found unlicensed during one.
Note: This page summarises the CDPA, S.I. 155 of 2024 and POTRAZ Regulatory Notice 2 of 2026 as published, and is current as at August 2026. It is not legal advice. Verify current requirements with POTRAZ and obtain advice from a qualified legal practitioner for your specific circumstances.
Plain-English applicability
Under Section 3 of the CDPA, a data controller is any natural or legal person who determines the purpose and means of processing personal data. A medical practice decides why and how patient data is used — so it is the controller. Outsourcing your software or billing does not transfer that duty.
Any controller processing the personal data of 50 or more data subjects — which includes patients, staff, walk-in visitors, suppliers and website visitors. Every practice in the country above that threshold must be licensed. Tier 1 (50–1,000 data subjects) starts at US$50.
Section 12 of the CDPA expressly prohibits processing genetic data, biometric data and health data without written consent from the patient. Clinical notes, diagnoses, lab results, medical-aid member numbers and national IDs all fall within this category. Health data is treated as the most sensitive class.
S.I. 155 of 2024 requires most licensed data controllers to appoint a certified DPO notified to POTRAZ on Form DP2. Tier 1 controllers (50–1,000 data subjects) may in some cases be exempt depending on the nature of processing. The DPO must complete an approved certification course ($1,250 per person). The DPO appointment deadline was 90 days after promulgation of the Regulations.
Any operation on personal data — collecting it at registration, storing it in practice software, sharing it with medical aids or laboratories, sending results by email or WhatsApp, backing it up to a cloud drive, or destroying it. Every one of those acts is governed by the Act.
The Medical and Dental Practitioners Council already requires every registered health institution to have a records management policy. The CDPA significantly raises the documentation bar: written access controls, consent records, processing registers, breach plans and vendor agreements are all required in addition to good clinical record-keeping.
What an inspector expects
When an inspector walks in, they are not looking for good intentions. They are looking for evidence.
Data Controller Licence (Form DP1)
Required if processing 50+ data subjects. Original deadline: 12 March 2025.
Certified Data Protection Officer (Form DP2)
Notified to POTRAZ. DPO certification costs $1,250 per person.
Written data protection policy and patient privacy notice
Patients must be told what you collect, why, and who sees it.
Record of processing activities
What data, why held, how long, who it is shared with.
Signed processing agreements with every software and IT vendor
Your billing bureau, claims switch, cloud host and IT provider all count.
Role-based access controls with a written access list
Reception cannot reach clinical notes they have no reason to see.
Patient consent forms at registration
Including parental consent for children. Consent must be verified and stored.
Documented breach response plan (24-hour POTRAZ notification clock)
Lost laptop or compromised record — you have 24 hrs to notify POTRAZ, 72 hrs to notify patients at high risk.
Tested backups, encryption and audit trail
An inspection can ask who accessed a specific record on a specific date.
Staff training records
DPO must run training and keep attendance records.
Where practices most often fail: Patient files in unlocked cabinets. One login shared by the whole front desk. Results sent over personal WhatsApp accounts. No signed agreement with the software vendor holding every record. Backups never tested. Nobody able to say who accessed a given file last Tuesday. Each of these is a finding waiting to be written up.
What compliance costs
Fees set by tier based on the total number of data subjects (patients + staff + others). Payable in USD or ZiG at the official rate.
| Tier | Data subjects processed | Application fee | Licence fee (annual) |
|---|---|---|---|
| Tier 1 | 50 – 1,000 | — | $50 |
| Tier 2 | 1,001 – 100,000 | $30 | $300 |
| Tier 3 | 100,001 – 500,000 | $30 | $500 |
| Tier 4 | 500,000 + | $30 | $2,500 |
DPO certification cost
$1,250 per person (Zimbabwean citizens) + $30 application fee. This is the single largest first-year cost for most practices — and it may be avoidable depending on how your practice is structured. The consultation will tell you honestly.
Realistic first-year picture
Most single-site practices fall into Tier 1 or Tier 2. Plan for US$1,300–$1,600 in year one (licence + DPO certification), then annual renewal — before any spend on securing systems, drafting policies or fixing how records are actually stored.
Just need the licence?
If licensing is the only piece you're missing, MedFi handles everything — Form DP1, POTRAZ submission and follow-up. Pricing depends on your tier:
Includes POTRAZ licence fee + MedFi service
$300 licence + $30 application + $100 service
$500 licence + $30 application + $100 service
$2,500 licence + $30 application + $100 service
Free 90-second check
Seven quick yes / no / not-sure questions about your consent, access, backups, breach plan and POTRAZ licensing. Your result appears immediately — no email gate. This is an indicator only; book the consultation for anything specific.
The MedFi compliance journey
From a free 90-second check to sustained, daily readiness — here's the full path.
Free compliance gap check (90-second chat or 20-min call) against the Act and S.I. 155. Tells you your licence tier and exact gaps.
We handle your Data Controller Licence application end to end. Tier 1 (50–1,000 data subjects): $150 all-in. Tiers 2–4: POTRAZ fee + $100 MedFi service fee.
Policies, consent capture, role-based access, encrypted backups, signed vendor agreements — and our in-house certified DPO/lawyer in place of the $1,250 certification course, where that route fits.
Staff training, audit trail, breach-response readiness, annual licence renewal. Inspection-ready every day, not just inspection day.
Why healthcare is first
Health data — diagnoses, clinical notes, lab results, member numbers, national IDs — is expressly classified as sensitive personal data under Section 12 of the Act. It carries the highest duty of care and the strictest consent requirements.
Medical aids, laboratories, specialists, pharmacies, billing bureaux, claims switches. Every share is a transfer under the Act. Each third party requires a written processing agreement. Most practices do not have a single one.
One login for the whole front desk. Results sent over personal WhatsApp. Patient files in unlocked cabinets. Under Section 18, you must have documented access controls — and an inspector can ask who accessed a record on any given day.
POTRAZ issued Regulatory Notice 2 of 2026 on 26 July 2026. Mandatory compliance inspections begin 1 September 2026. Healthcare providers are explicitly named in the first risk-based wave, alongside financial institutions and insurers.
Under S.I. 155 of 2024, processing without a licence or failing to secure data carries a fine at level 11 or up to seven years' imprisonment, or both. Failing to appoint a DPO: level 7 fine or two years. These provisions attach to the responsible individuals, not an abstract entity.
The Medical and Dental Practitioners Council requires every registered practice to have a records management policy. The CDPA raises the documentation bar significantly above that baseline — and an MDPCZ disciplinary matter can follow a data breach.
What a consultation includes
We look at how your practice actually runs — your systems, your access, your paperwork — and give you a written, prioritised list of what to fix and in what order. The aim is readiness you can defend in an inspection.
No payment required. About 45 minutes. We follow up personally within one business day.
Our DPO is a certified, practising lawyer with over 20 years' experience. The guidance you receive on your licence tier and obligations comes from someone properly qualified to give it — not an AI summary or a generalist checklist.
Why MedFi / AfrIgnite is credible here
AfrIgnite Smart Solutions, 30 Samora Machel Avenue, Harare. You can call, WhatsApp or visit. We understand medical-aid workflows, AHFoZ tariffs, CIMAS and PSMAS processing — not a foreign template applied to a different market.
MedFi was built with tenant separation, role-based access, consent capture at registration, full audit trails and tested backups. These are precisely the controls S.I. 155 and an inspection ask for — they are the platform, not an add-on.
Data protection sits at the intersection of law and systems. Most providers cover one side. Our DPO is certified and has over 20 years' legal practice. Depending on your structure, that expertise can be made available to your practice — potentially removing the $1,250 DPO training cost.
No payment required. We follow up within one business day.