Data Protection Readiness Assessment
Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] applies to you whether or not anyone has come knocking. We tell you exactly where you stand, and what it takes to close the gap.
Read this before you buy anything from anyone
Compliance work in Zimbabwe splits into two halves that are easy to confuse. Being clear about which half we do is the whole reason to trust us with the other one.
What we do
- Assess your technical and organisational security posture
- Map where personal data actually lives in your business
- Test whether you would detect and survive a breach
- Build the systems that make compliance possible: consent capture, audit logs, retention, access control
- Train your staff on the security half of their obligations
- Hand you a written, risk-rated gap report you own outright
What we do not do
- Act as your appointed Data Protection Officer
- Provide legal advice or legal interpretation of the Act
- File breach notifications or represent you before POTRAZ
- Handle formal data subject complaints on your behalf
Those are the role of a Data Protection Officer. Under SI 155 of 2024, a DPO is certified through a course at the Harare Institute of Technology, run on behalf of POTRAZ as the Data Protection Authority. Your business separately needs its own data controller licence from POTRAZ. We hold neither, so if you need either we will say so and point you to someone who does. We would rather send you down the road than sell you something we are not.
What the assessment covers
Six areas, tested against what the Act expects rather than against a generic checklist written for somewhere else.
Personal Data Mapping
We trace every place personal data enters, moves through, and rests in your business: forms, spreadsheets, WhatsApp, CRMs, backups, and third-party tools. Most organisations are surprised by the list.
Security Controls Review
Encryption in transit and at rest, access control, password and account hygiene, database exposure, and whether your hosting arrangement stands up to scrutiny.
Breach Readiness
The Act expects you to detect and report. We test whether you would actually notice a breach, who would be told, and how fast, then write the runbook if one does not exist.
Third-Party and Processor Risk
Your payment gateway, hosting provider, email platform, and outsourced developer all touch customer data. We assess what each one holds and what your exposure looks like.
Data Subject Rights Capability
If a customer asked for a copy of their data, or asked you to delete it, could you comply? We test the request path end to end and flag where it breaks.
Public-Facing Compliance Signals
Privacy policy, cookie and tracker behaviour, consent capture, and retention practice on your live website, checked against what you actually do behind the scenes.
How it runs
01
Passive scan
We start outside your perimeter with the same free scan anyone can run, so you see the public evidence before you spend anything.
02
Discovery session
A structured 60 to 90 minute session with whoever handles your customer data. No forms to fill in beforehand.
03
Assessment and report
We test what we were told against what we can observe, then write it up: every gap rated by risk, with the fix and rough effort beside it.
04
Remediation
You take the report to your own team, to a certified DPO, or back to us to build the fixes. All three are fine. The report is yours either way.
Turnaround is typically one to two weeks from the discovery session, depending on how many systems are in scope.
Three ways to engage
No hourly billing, no surprise invoices. Every engagement is quoted on scope, which means how many systems hold personal data, not how large your logo is.
Readiness Assessment
One-off engagement
Where most SMEs start. Scoped on how many systems hold personal data.
- Full personal data map
- Security controls review
- Written gap report, risk rated
- Prioritised remediation plan
- 60 minute findings walkthrough
Assess and Remediate
Fixed-scope project
The assessment plus the engineering to close the gaps it finds.
- Everything in the assessment
- Consent capture and privacy policy build
- Data subject request handling
- Encryption, access control, and retention fixes
- Audit logging where it is missing
- Retest to confirm gaps are closed
Ongoing Compliance Support
Monthly retainer
For businesses whose data footprint keeps changing.
- Quarterly reassessment
- Continuous monitoring via Vanorika Shield
- Breach response on call
- Staff awareness refreshers
- Advisory on new systems before you buy them
Who this is for
If you hold names, phone numbers, ID numbers, medical records, or payment details for Zimbabwean residents, the Act applies to you. Size is not the test.
Start with the free scan
Before you commit to anything, run your own domain through our privacy and cookie scanner. It checks what your website is doing with visitor data right now. It takes about a minute and costs nothing.
Run the free scanBook a 30 minute callPrefer to read first? Start with our Data Protection Act compliance checklist or the plain-English guide to the Act.