AvalonHealth

Zimbabwe healthcare data protection

Data Protection Officer for Healthcare Providers in Zimbabwe

Under SI 155 of 2024 a Data Protection Officer is a condition of holding a POTRAZ Data Controller licence, so for a Zimbabwean healthcare provider a DPO is required rather than optional. Because health data is sensitive data, the requirement reaches even a Tier 1 solo practice. The only real decision is whether the role is filled internally or by an external DPO on record.

Is a DPO actually mandatory for a healthcare provider?

Yes. SI 155 of 2024 makes the appointment of a Data Protection Officer a condition of holding a Data Controller licence. You cannot hold the licence without naming one, which removes the question of whether to have a DPO and leaves only the question of how the role is provided.

There is a second, independent reason the requirement is firm in healthcare. The obligation bites hardest where an organisation processes sensitive data, and health data is sensitive personal data under the Cyber and Data Protection Act [Chapter 12:07]. A practice that treats children holds children’s data as well, which is also sensitive. That combination is why a solo practice with a few hundred files is in the same position as a hospital, and why a Tier 1 healthcare provider cannot treat the DPO requirement as something that applies only to larger organisations.

What the Data Protection Officer actually does

The DPO is the named person accountable for data protection in the organisation and the point of contact for POTRAZ and for patients exercising their rights. The role is a standing function rather than a one-off appointment, and in a healthcare setting it covers:

Most of that work is periodic rather than daily, which is the practical reason so few practices can justify a dedicated internal post.

Internal DPO or external DPO on record

Both routes are legitimate. What separates them is competence and conflict of interest.

Appointing internally

An internal DPO has to be competent in data protection law and practice, not simply senior or trusted. They also have to be free of any conflict of interest with their other duties, which in a small organisation is the harder test. The person who decides how patient data is used commercially cannot credibly supervise whether that use is lawful, so the practice principal or the commercial manager is usually the wrong choice. The role also has to be reachable: patients and POTRAZ need a contact point that answers.

For a hospital or a large group with an existing compliance or risk function, an internal appointment often works well, sometimes supported externally for the specialist filings and the annual audit.

Appointing an external DPO

For a solo practice, doctors’ rooms, a single pharmacy or a small laboratory, an external DPO on record is usually the more realistic route. The organisation does not have a spare person with data protection training, and creating the conflict-free internal position would mean hiring for a function that is periodic. An external DPO brings the competence, carries the filings and the notifications, and is the contact point on record without adding a post to the payroll.

Avalon Health can act as your Data Protection Officer on record. The engagement is delivered by certified data protection officers and the options, including the choice between an outsourced, dedicated or full-time arrangement, are set out on the main compliance page.

What sits outside a DPO engagement

Being clear about the boundary avoids disputes later. Some work is project work rather than standing DPO work, and is quoted separately when it arises. That includes an impact assessment for a brand new system the organisation brings in, a material-change assessment when the way data is processed changes substantially, forensic investigation beyond the on-call incident response, and the POTRAZ licence fee itself, which is a government fee passed through at cost.

The initial compliance work is also distinct from the ongoing DPO function. Getting licensed and documented in the first place is a package: the gap analysis, the licence application and processing notification, the ROPA, the privacy and consent wording, the DPIA, the breach and access request procedures, the physical records security checklist and the staff training under CDPG 1 of 2025. The DPO engagement then keeps all of that current.

The DPO and the 1 September 2026 inspections

With inspections beginning on 1 September 2026 and healthcare in the first wave, the DPO appointment is one of the items an inspector asks about directly. They will want to know who holds the role, what makes them competent, and how they can be reached. A licence application filed without a real, reachable, conflict-free DPO behind it is an obvious weak point.

Where Avalon Health is the DPO on record, attending a POTRAZ inspection is part of the engagement, as is the annual licence renewal filing and keeping the ROPA current between inspections.

Getting started

The first step is a one-hour compliance consultation at $90, at your premises or on a call. Our data protection officers confirm your controller status, map how patient records are held, stored and shared, and confirm your POTRAZ licence tier. You then receive an assessment and an accurate quotation, and the $90 is credited in full toward your compliance package when you proceed. Packages start at $250.

Providers already on the Avalon Health platform start from a stronger technical position, because the platform provides PII tokenised at rest, AES-256 encryption, append-only audit logging, role-based access control, multi-factor authentication and consent capture, which are the technical controls a DPO would otherwise have to specify and chase.

Frequently asked questions

Does a small clinic in Zimbabwe need a Data Protection Officer?

Yes. Under SI 155 of 2024 a Data Protection Officer is a condition of holding a Data Controller licence, and because a healthcare provider processes health data, which is sensitive personal data, the requirement reaches even a Tier 1 solo practice.

Can the practice owner be the Data Protection Officer?

Usually not. The DPO has to be competent in data protection and free of conflicts of interest with their other duties. Someone who decides how patient data is used commercially cannot credibly supervise whether that use is lawful, which normally rules out the practice principal or the commercial manager.

What does a Data Protection Officer do day to day?

The work is periodic rather than daily. It covers being named on record with POTRAZ, keeping the Records of Processing current and notifying material changes, handling patient data access requests, breach and incident response including notifications, reporting to management, the annual audit and training refresher, filing the annual licence renewal, and attending a POTRAZ inspection.

What is an outsourced DPO?

An external specialist named as your Data Protection Officer on record with POTRAZ, who carries the filings, notifications and incident response and acts as the contact point for POTRAZ and patients, without the organisation creating an internal post. It is the common route for solo practices, single pharmacies and small laboratories.

Is the DPO the same thing as the compliance package?

No. The package is the one-off work of getting licensed and documented: the gap analysis, licence application, ROPA, privacy and consent wording, DPIA, breach and access request procedures, records security checklist and staff training. The DPO engagement is the standing function that keeps all of it current afterwards.

What is not covered by a DPO engagement?

Project work is quoted separately: an impact assessment for a brand new system, a material-change assessment, forensic investigation beyond the on-call incident response, and the POTRAZ licence fee itself, which is a government fee passed through at cost.

Get licensed and inspection-ready

Compliance packages start at $250. Every engagement begins with a one-hour consultation at $90, credited in full toward your package when you proceed. POTRAZ fees are separate and passed through at cost.