Zimbabwe healthcare data protection
POTRAZ Inspections of Healthcare Providers: What Inspectors Ask For
POTRAZ inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026, with healthcare in the first wave. An inspection is a documentary exercise before it is anything else: inspectors ask for your Data Controller licence, your Records of Processing, your DPIA, your breach and access request procedures, your DPO appointment and your staff training records under CDPG 1 of 2025.
Why healthcare is first
Healthcare providers process sensitive data as their ordinary business. Health data is sensitive personal data under the Act, and providers treating minors hold children’s data as well, which is also sensitive. Concentrating enforcement where the data is most sensitive is the logical starting point, and it is why healthcare providers are in the first inspection wave rather than a later one.
The practical consequence is that clinics, hospitals, pharmacies, laboratories and radiology centres have less lead time than organisations in other sectors. A provider that is not licensed by 1 September 2026 has a problem that does not depend on being inspected at all, because operating as an unlicensed data controller is itself an offence under the Act.
What an inspector asks to see
An inspection tests whether the obligations exist on paper and hold up in the building. The document set below is what a healthcare provider should be able to produce without hunting for it.
- The POTRAZ Data Controller licence itself, and the processing notification that accompanied it.
- Records of Processing, the ROPA: what personal data you hold, the categories of data subject, the purpose and lawful basis for each processing activity, who it is shared with, and the retention period.
- The Data Protection Impact Assessment covering health data, and children’s data where minors are treated.
- The Data Protection Officer appointment: who holds the role, their competence, and how to reach them.
- The published privacy policy and the patient consent wording actually in use at reception.
- The written data breach response procedure and the incident register, including incidents assessed as not notifiable.
- The data subject access request procedure and the log of requests received and answered.
- Staff data protection training records under CDPG 1 of 2025, showing who was trained and when.
- Data processing and data sharing agreements with third parties: medical aid societies, reference laboratories, outsourced IT and billing providers, cloud vendors.
- Evidence of physical records security and of technical controls over electronic records.
Training records are asked for specifically
CDPG 1 of 2025, the POTRAZ assessment guidelines, makes data protection training mandatory for staff who handle personal data. This is one of the few items where the obligation and the evidence are the same thing: an inspector cannot observe training, so the training record is the proof. A provider that has briefed staff informally but recorded nothing is, from an inspection standpoint, in the same position as one that has done nothing at all.
A training record should show the date of the session, who delivered it, what it covered and who attended, with attendance signed. It has to reach everyone who handles personal data, which in healthcare means reception, records, nursing, laboratory, pharmacy and billing staff as well as clinicians. Large providers running shifts across multiple sites need several sessions and a record for each. New staff joining after the initial session need to be covered too, which is why training is better set up as a repeating obligation than a one-off event.
What inspectors look at beyond the file
The documentary review is the core of an inspection, but the walk through the premises is where documents are tested against reality. The recurring points of attention in a healthcare setting are:
- The records room: whether it is access controlled, whether files are secured outside working hours, and whether removals are signed out.
- The reception area: whether patient files, day registers or screens are visible to people in the waiting area.
- The archive: whether dormant files are stored securely and separately, and whether anything is due for destruction under a retention rule.
- Devices: whether laptops and phones holding patient data are encrypted and locked, and whether practice data sits in personal accounts or backups.
- Transmission: how results and referrals actually travel between the practice, laboratories, specialists and medical aid societies.
- CCTV: whether a notice is displayed, whether the footage has a stated purpose and retention period, and whether the processing appears in the ROPA.
- Access: who inside the organisation can open a patient record, and whether that is restricted by role rather than granted to everyone.
The findings that come up most often
Across gap analyses of Zimbabwean healthcare providers the same items recur: patient data sent over ordinary messaging and email, paper records that are not physically secured, consent wording that does not cover sharing with medical aid societies or referring practitioners, no retention rule so nothing is ever destroyed, CCTV with no notice and no ROPA entry, no written breach procedure, and no training record. These are covered in more detail in our guide to the data protection gaps we find most often in medical practices.
What to do if you are not ready
The order of work is what saves time. The licence application and processing notification come first, because their absence is an offence independently of any inspection. The ROPA and DPIA come next, because most of the remaining evidence refers back to them. The highest-risk practical fixes follow, which for almost every provider means securing the transmission of patient data and controlling access to the records area. Training can run in parallel, scheduled around clinical hours. Lower-risk housekeeping comes last.
A provider that has missed the date should not treat the position as fixed. Getting licensed and documented reduces exposure from the moment it is done, and being able to show an inspector a dated remediation plan that is actively being worked through is materially better than showing nothing.
How Avalon Health prepares a provider for inspection
Every engagement starts with a one-hour compliance consultation at $90, at your premises or on a call, credited in full toward your package when you proceed. Our certified data protection officers confirm your controller status, map how patient records are held, stored and shared, and confirm your POTRAZ tier. You then get an assessment, an accurate quotation and a plan sequenced by risk.
Packages start at $250 and include the gap analysis and report, the licence application and processing notification, the ROPA, the privacy and consent wording, the DPIA for health and minors’ data, the breach and access request procedures, the physical records security checklist and staff training under CDPG 1 of 2025 with the record retained. Where Avalon Health acts as your Data Protection Officer on record, attending a POTRAZ inspection is part of the retainer.
Frequently asked questions
When do POTRAZ inspections start in Zimbabwe?
Inspections under the Cyber and Data Protection Act [Chapter 12:07] begin on 1 September 2026, with healthcare providers in the first wave.
Why are healthcare providers inspected first?
Because they process sensitive data as their ordinary business. Health data is sensitive personal data under the Act, and providers treating minors also hold children’s data, which is sensitive as well. Enforcement starts where the data is most sensitive.
What documents does a POTRAZ inspector ask for?
The Data Controller licence and processing notification, the Records of Processing, the DPIA, the DPO appointment, the privacy policy and patient consent wording, the breach response procedure and incident register, the data subject access request procedure and log, staff training records under CDPG 1 of 2025, third-party data processing and sharing agreements, and evidence of physical and technical security.
Are staff training records really required?
Yes. Training is mandatory under CDPG 1 of 2025 for staff who handle personal data, and the record is the evidence. A provider that briefed staff informally without recording it has nothing to produce at inspection. The record should show the date, the content, who delivered the session and who attended.
What happens if a provider is not licensed when inspections begin?
Operating as an unlicensed data controller is an offence under the Act, independently of any inspection, and exposes the provider to enforcement action and penalties. Getting licensed and documented reduces exposure from the moment it is done, and a dated remediation plan actively being worked through is materially better than nothing.
Will an inspector look at more than the paperwork?
Yes. After the documentary review, the walk through the premises tests the documents against reality: the records room and archive, what is visible at reception, device encryption, how results and referrals actually travel, CCTV notices, and who can open a patient record.
Get licensed and inspection-ready
Compliance packages start at $250. Every engagement begins with a one-hour consultation at $90, credited in full toward your package when you proceed. POTRAZ fees are separate and passed through at cost.