Resource · Data Protection

The practical data-protection guide for Zimbabwean practices

A printable walkthrough of the Cyber and Data Protection Act [Chapter 12:07], S.I. 155 of 2024 and POTRAZ licensing — exactly what a healthcare practice must have in place before a 1 September 2026 inspection.

Take this guide with you

MedFi Healthcare Data Protection GuideSector Compliance Brief
Inspections begin 1 September 2026

Data protection for medical, dental & pharmacy practices in Zimbabwe

Under the Cyber and Data Protection Act [Chapter 12:07], every practice that processes patient data must register and licence as a data controller with POTRAZ and appoint a Data Protection Officer. This one-page brief sets out where you stand and what to do first.

Patient data you are likely holding

  • Patient names, ID numbers and contact details
  • Medical-aid membership and billing data
  • Diagnoses and clinical notes
  • Laboratory and imaging results
  • Biometric or genetic data, where captured

Where practices like yours slip

  • Patient files in unlocked cabinets or shared spreadsheets
  • One login shared by the whole front desk
  • Results sent over personal WhatsApp accounts
  • No signed agreement with the software vendor holding records
  • Backups that have never actually been tested

Six-step readiness checklist

1. Confirm you are a data controller — You decide the purposes and means of processing patient data; virtually every practice is.

2. Map what you hold — Build the processing register: what data, why, where it goes, who can reach it.

3. Appoint a DPO in writing — Name the person and document the appointment; informal delegation is not an appointment.

4. Register and licence with POTRAZ — File the application and keep the pack as your inspection file.

5. Issue notices and fix access — Give patients a privacy notice; tighten who can reach records.

6. Train your team and keep evidence — Record that staff were trained; the inspection finds awareness, not surprise.

What the law requires

Licensing — practices must register and licence with POTRAZ (Act 5 of 2021; S.I. 155 of 2024).
Data Protection Officer — the appointment must be made and documented in writing.
Criminal liability — non-compliance carries liability on conviction, not fines alone.

Why now

POTRAZ is rolling out inspections on a risk-based basis, with healthcare named in the first wave. Being outside that first named group is a queue position, not an exemption.

Speak to Coach Mike — no obligation, no jargon.

WhatsApp +263 776 167 076 · Calls +263 77 616 7076 · hello@medfi.co.zw

What has changed

On 26 July 2026, POTRAZ issued Regulatory Notice 2 of 2026. From 1 September 2026 it will run mandatory compliance inspections of data controllers under the Cyber and Data Protection Act and S.I. 155 of 2024. Healthcare providers are explicitly named in the first risk-based wave — alongside banks, insurers and local authorities. The original licensing deadline was 12 March 2025; POTRAZ has invited non-compliant organisations to still apply. Acting before an inspection is a materially better position than being found unlicensed during one.

Who needs a licence

Any controller processing the personal data of 50 or more data subjects — patients, staff, walk-in visitors, suppliers and website visitors combined. A solo GP with a modest patient list still crosses the threshold across all categories. Health data is expressly classified as sensitive under Section 12 of the Act and carries the strictest consent duties.

TierData subjects processedAnnual licence fee
Tier 150 – 1,000$50
Tier 21,001 – 100,000$300
Tier 3100,001 – 500,000$500
Tier 4500,000 +$2,500

Fees from CDPG 1 of 2025. Tier 2–4 carry a $30 application fee. DPO certification costs $1,250 per person (Zimbabwean citizens). Plan for US$1,300–$1,600 in year one for most single-site practices.

What an inspector expects to see

Data Controller Licence (Form DP1) — required if you process data on 50+ data subjects

Certified Data Protection Officer appointed and notified to POTRAZ (Form DP2)

Written data protection policy and a patient privacy notice

Record of processing activities — what data, why, how long, who sees it

Signed processing agreements with every software and IT vendor

Role-based access controls with a written access list

Patient consent forms at registration, including parental consent for children

Documented breach response plan (24-hour POTRAZ notification clock)

Tested backups, encryption and an audit trail of record access

Staff training records kept by the DPO

Where practices most often fail

Patient files in unlocked cabinets. One login shared by the whole front desk. Results sent over personal WhatsApp. No signed agreement with the software vendor holding every record. Each is a finding waiting to be written up.

Want this handled for your practice?

Book a free 45-minute consultation with our certified DPO. We turn this guide into a prioritised, written action list for your actual systems — no payment required.

Sources: Cyber and Data Protection Act [Chapter 12:07], S.I. 155 of 2024 (POTRAZ), CDPG 1 of 2025 (POTRAZ), POTRAZ Regulatory Notice 2 of 2026. This guide is for general information and is not legal advice. Verify current requirements with POTRAZ and obtain advice from a qualified legal practitioner for your specific circumstances.