COMPLIANCE

Data Protection Readiness Assessment

Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] applies to you whether or not anyone has come knocking. We tell you exactly where you stand, and what it takes to close the gap.

Read this before you buy anything from anyone

Compliance work in Zimbabwe splits into two halves that are easy to confuse. Being clear about which half we do is the whole reason to trust us with the other one.

What we do

  • Assess your technical and organisational security posture
  • Map where personal data actually lives in your business
  • Test whether you would detect and survive a breach
  • Build the systems that make compliance possible: consent capture, audit logs, retention, access control
  • Train your staff on the security half of their obligations
  • Hand you a written, risk-rated gap report you own outright

What we do not do

  • Act as your appointed Data Protection Officer
  • Provide legal advice or legal interpretation of the Act
  • File breach notifications or represent you before POTRAZ
  • Handle formal data subject complaints on your behalf

Those are the role of a Data Protection Officer. Under SI 155 of 2024, a DPO is certified through a course at the Harare Institute of Technology, run on behalf of POTRAZ as the Data Protection Authority. Your business separately needs its own data controller licence from POTRAZ. We hold neither, so if you need either we will say so and point you to someone who does. We would rather send you down the road than sell you something we are not.

What the assessment covers

Six areas, tested against what the Act expects rather than against a generic checklist written for somewhere else.

Personal Data Mapping

We trace every place personal data enters, moves through, and rests in your business: forms, spreadsheets, WhatsApp, CRMs, backups, and third-party tools. Most organisations are surprised by the list.

Security Controls Review

Encryption in transit and at rest, access control, password and account hygiene, database exposure, and whether your hosting arrangement stands up to scrutiny.

Breach Readiness

The Act expects you to detect and report. We test whether you would actually notice a breach, who would be told, and how fast, then write the runbook if one does not exist.

Third-Party and Processor Risk

Your payment gateway, hosting provider, email platform, and outsourced developer all touch customer data. We assess what each one holds and what your exposure looks like.

Data Subject Rights Capability

If a customer asked for a copy of their data, or asked you to delete it, could you comply? We test the request path end to end and flag where it breaks.

Public-Facing Compliance Signals

Privacy policy, cookie and tracker behaviour, consent capture, and retention practice on your live website, checked against what you actually do behind the scenes.

How it runs

  1. 01

    Passive scan

    We start outside your perimeter with the same free scan anyone can run, so you see the public evidence before you spend anything.

  2. 02

    Discovery session

    A structured 60 to 90 minute session with whoever handles your customer data. No forms to fill in beforehand.

  3. 03

    Assessment and report

    We test what we were told against what we can observe, then write it up: every gap rated by risk, with the fix and rough effort beside it.

  4. 04

    Remediation

    You take the report to your own team, to a certified DPO, or back to us to build the fixes. All three are fine. The report is yours either way.

Turnaround is typically one to two weeks from the discovery session, depending on how many systems are in scope.

Three ways to engage

No hourly billing, no surprise invoices. Every engagement is quoted on scope, which means how many systems hold personal data, not how large your logo is.

Readiness Assessment

One-off engagement

Where most SMEs start. Scoped on how many systems hold personal data.

  • Full personal data map
  • Security controls review
  • Written gap report, risk rated
  • Prioritised remediation plan
  • 60 minute findings walkthrough
Book an assessment

Assess and Remediate

Fixed-scope project

The assessment plus the engineering to close the gaps it finds.

  • Everything in the assessment
  • Consent capture and privacy policy build
  • Data subject request handling
  • Encryption, access control, and retention fixes
  • Audit logging where it is missing
  • Retest to confirm gaps are closed
Scope a project

Ongoing Compliance Support

Monthly retainer

For businesses whose data footprint keeps changing.

  • Quarterly reassessment
  • Continuous monitoring via Vanorika Shield
  • Breach response on call
  • Staff awareness refreshers
  • Advisory on new systems before you buy them
Talk retainer

Who this is for

If you hold names, phone numbers, ID numbers, medical records, or payment details for Zimbabwean residents, the Act applies to you. Size is not the test.

SMEsNGOsSchools and collegesClinics and pharmaciesHotels and guest housesChurchesFinancial servicesLaw firms

Start with the free scan

Before you commit to anything, run your own domain through our privacy and cookie scanner. It checks what your website is doing with visitor data right now. It takes about a minute and costs nothing.

Run the free scanBook a 30 minute call

Prefer to read first? Start with our Data Protection Act compliance checklist or the plain-English guide to the Act.