By Jabulani Simplisio Chibaya
HARARE – FROM 23 to 26 September 2026, the Enterprise Risk Management Institute of Zimbabwe (ERMIZ) will gather chief executives, risk managers, compliance officers, auditors, regulators , and information security professionals at Montclair Hotel in Nyanga for the Risk Management Annual Conference 2026, themed “Navigating Uncertainty: Innovative Risk Management for Sustainable Growth.” On paper, it looks like another entry on the corporate calendar — teas, lunches, a certificate of participation. In practice, the timing could not be more pointed. The conference lands three weeks after Zimbabwe’s data protection regulator started knocking on doors, in a year when cybersecurity has been formally reclassified, globally, as a board-level economic risk rather than an IT problem. Read against that backdrop, the conference’s four-day agenda on data protection, cybersecurity , and governance is less a training exercise and more a survival briefing.
POTRAZ’s September 1 Deadline Has Already Arrived
The single most consequential development for Zimbabwean organisations this quarter is not on the conference poster, but it will dominate the conversation in Nyanga’s conference rooms nonetheless. Under Regulatory Notice 2 of 2026, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), acting as the country’s Data Protection Authority, began mandatory compliance inspections on 1 September 2026 — the same date this article is being written. The inspections assess whether organisations that collect or process personal information have obtained the required data controller licence, appointed a certified Data Protection Officer, and put in place adequate cybersecurity and data governance measures under the Cyber and Data Protection Act.
This is not a symbolic exercise. POTRAZ has said it will work through sectors in order of data sensitivity and volume, starting with financial institutions, insurance companies, local authorities, healthcare providers, mining enterprises , and religious organisations, before moving on to schools, universities, government ministries, professional bodies , and NGOs. Almost every organisation operating in Zimbabwe today, from a church to a bank to a private school, holds personal data — names, national ID numbers, phone numbers, medical records, biometrics — and the threshold for needing a licence is modest: as few as 50 data subjects on record is enough to trigger the requirement.
The consequences of non-compliance are severe and personal. Processing data without a licence can attract a Level 11 fine , or up to seven years’ imprisonment for the responsible chief executive, or both. Data breaches must be reported to POTRAZ within 24 hours, with affected individuals notified within 72 hours where the breach poses significant risk. Compliance itself is not free: Data Protection Officer certification alone runs to roughly US$1,250 plus a US$30 application fee, meaning a small organisation’s first-year compliance bill, licence and certification combined, can exceed US$1,300 before it hires any external help. Legal commentators have noted that entities first need to determine whether they qualify as “data controllers” and confirm they are not exempt , before applying for the appropriate licence tier and appointing an officer whose duties include running compliance audits, training staff, and acting as the liaison with POTRAZ.
For risk professionals gathering at the conference, the message is blunt: this is no longer a future compliance project to be scoped for next financial year. Inspectors are already in the field.
Cybersecurity Has Moved From the Server Room to the Boardroom
The World Economic Forum’s Global Cybersecurity Outlook 2026 research frames cybersecurity as a strategic economic issue rather than a technical one, pointing to rising incident costs driven by controls, insurance, skills shortages , and mounting compliance demands. That global reframing has sharp local relevance. Zimbabwe was ranked among the most heavily targeted countries globally for cyberattacks in recent years, and analysts tracking the local threat landscape point to phishing and social engineering, mobile money and online banking fraud, ransomware, data breaches , and insider threats as the dominant risks facing Zimbabwean organisations. The consistent advice from security practitioners operating in-market is that the old siloed, IT-owned approach to security no longer holds; organisations are being pushed toward an “assume breach” posture that integrates protection, detection , and response as one continuous discipline rather than a checklist exercise run once a year.
This matters directly for the POTRAZ inspection regime, because data protection and cybersecurity are not separate conversations under the Cyber and Data Protection Act — a weak security posture is itself a compliance failure. An organisation can hold a valid data controller licence and still be found wanting if it cannot demonstrate encryption, access controls, breach detection capability , and a tested incident response plan.
Governance Is the Thread That Ties It Together
Academic and industry commentary on cybersecurity governance in Zimbabwe converges on one point: boards, not just IT departments, are now expected to own cyber risk. Effective governance frameworks require boards to evaluate whether cybersecurity responsibility is clearly assigned across management, internal teams , and external stakeholders, to set expectations for adequate resourcing, and to actively monitor how well those functions are performing — rather than delegating the entire subject to a systems administrator and receiving no further update until something breaks. That shift mirrors what is happening in local authorities, financial institutions , and increasingly mid-sized private companies: cyber governance frameworks that assign clear ownership, track incidents, and hold management accountable for remediation timelines.
Broader ESG and governance trends reinforce the same direction of travel — regulatory compliance, climate-related risk, business continuity , and crisis management are converging into a single integrated governance conversation rather than sitting in separate departmental silos. This is precisely the ground ERMIZ’s 2026 agenda is built to cover.
What a Modern Organisation Should Actually Be Doing Right Now
Stripped of jargon, the practical checklist emerging from this moment looks like this:
- Confirm your status. Determine whether your organisation is a “data controller” under the Act, and if it is not exempt, apply for the correct licence tier without delay.
- Appoint and certify a Data Protection Officer, and make sure the role has real authority to run audits, train staff , and liaise with POTRAZ — not just a title on an org chart.
- Build (or test) a 24-hour breach reporting pathway. If your organisation cannot detect and report a breach to POTRAZ within a day, and notify affected individuals within 72 hours, that gap is itself a compliance failure.
- Move security ownership to the board. Cyber risk briefings belong in board and audit committee papers, with named accountability for remediation, not an annual IT slide deck.
- Budget compliance as a recurring operating cost, not a one-off project — licences are renewed annually, and certification and training costs recur.
- Treat governance, cybersecurity , and data protection as one integrated function, since gaps in any one area routinely surface as failures in the others during an inspection or an actual breach.
Compliance as a Core Pillar, Not a Checkbox
The throughline of this year’s conference, and of the regulatory moment it sits inside, is a shift in how compliance is understood. It is no longer a defensive, once-a-year formality handled by a small compliance team ahead of an audit. With inspectors now active in the field, breach-reporting clocks running in hours rather than months, and executives personally exposed to criminal liability, data protection, cybersecurity , and governance have become a standing, resourced, board-owned pillar of how an organisation operates — as central to strategy as finance or operations. Organisations that scale their compliance, security , and governance initiatives together, rather than bolting each on separately after the fact, are the ones best positioned to survive an inspection, absorb a breach without reputational collapse, and still call themselves fit for sustainable growth by the time ERMIZ convenes again next year.
Jabulani Simplisio Chibaya is a Data and AI Consultant specializing in data science, artificial intelligence, blockchain, and cryptocurrency innovation. A seasoned conference speaker, he also writes on the intersection of technology, regulation, and economic development. Contact: Cell: +263 778 921 881 | Email: simplisiochibaya22@gmail.com | LinkedIn: https://www.linkedin.com/in/jabulani-simplisio-chibaya
Discover more from Etimes
Subscribe to get the latest posts sent to your email.

