Zimbabwe healthcare data protection
POTRAZ Data Controller Licence for Clinics and Hospitals in Zimbabwe
A Zimbabwean clinic group, hospital, pharmacy chain or laboratory that holds more than 1,000 records sits in POTRAZ Tier 2 or above. Licence fees run $300 at Tier 2, $500 at Tier 3 and $2,500 at Tier 4, exclusive of VAT, plus a $30 application fee which applies from Tier 2 upward. Larger providers also carry departmental ROPAs, third-party agreements and multi-site evidence.
How a multi-site provider works out its tier
The tier is set by the total number of individuals whose personal data the licensed entity holds, counted across the whole organisation rather than per branch. A group with four clinics does not get four Tier 1 licences. If one legal entity operates all four sites, the record counts add together and the group is licensed once at the combined tier.
The count includes patients, both current and historical, employees, locums and contractors, and business contacts. For a hospital this typically means the patient master index, the human resources records and the supplier contact list all contribute. Laboratories and radiology centres often carry a larger record count than expected, because every referred patient creates a record even when the patient never attended the site in person.
| POTRAZ tier | Records held | Licence fee (ex VAT) | Application fee (ex VAT) |
|---|---|---|---|
| Tier 1 | Up to 1,000 records | $50 | Not applicable at Tier 1 |
| Tier 2 | 1,001 to 100,000 records | $300 | $30 |
| Tier 3 | 100,001 to 500,000 records | $500 | $30 |
| Tier 4 | Over 500,000 records | $2,500 | $30 |
What the fees are and how they are billed
POTRAZ fees are government fees. We pass them through at cost with no markup, and we quote them separately from our service fee so you always see two numbers rather than one blended figure.
- A $30 POTRAZ application fee, exclusive of VAT, applies from Tier 2 upward. It is not charged at Tier 1 and it is not charged on renewals.
- The Data Controller licence fee is $300 at Tier 2, $500 at Tier 3 and $2,500 at Tier 4, exclusive of VAT.
- POTRAZ adds VAT on its own invoice, at a rate we do not set, which is why we never quote an all-in total.
- The licence renews annually at the tier fee.
The sequence matters. The application fee is paid first, POTRAZ issues its references, and the licence fee follows only once the application is approved. Clients pay POTRAZ directly and we never handle the fee.
What changes when you are bigger than a single practice
The statutory obligations are the same at every tier. What changes is the volume of evidence, the number of internal relationships that have to be documented, and the number of third parties in the picture. A solo practice has one consulting room and one filing cabinet. A hospital has a records department, a laboratory, a radiology unit, a pharmacy, a billing function, a claims relationship with medical aid societies and often an outsourced IT provider, and every one of those is a data flow an inspector can ask about.
A ROPA that reflects departments, not just the organisation
Records of Processing for a hospital cannot be a single page. Each department processes different categories of data for different purposes and keeps it for different periods. Radiology holds imaging, the laboratory holds specimen and result data, pharmacy holds dispensing histories, human resources holds employee records including medical information about staff. The ROPA has to be expanded across departments and systems so that each processing activity is traceable to a purpose, a lawful basis and a retention period.
Third-party agreements and data sharing
Larger providers share data constantly: with medical aid societies for claims, with referring and receiving practitioners, with reference laboratories, with outsourced IT and billing providers, and with cloud vendors. Each of those relationships needs a written data processing agreement or data sharing agreement that sets out what may be processed, for what purpose, under what security conditions and what happens on termination. An undocumented sharing arrangement is one of the clearest findings an inspector can record.
Cross-border transfers
If patient data leaves Zimbabwe, and it does whenever a provider uses an offshore cloud platform, an offshore billing bureau or an overseas reference laboratory, the transfer has to be assessed and, where required, notified. A cross-border transfer assessment identifies where the data goes, on what basis, and what safeguards apply at the destination. Providers are often surprised to learn they make cross-border transfers, because the transfer happens inside a software product they think of as local.
A full DPIA rather than a standard-form one
A multi-site provider processing health data at scale needs a full Data Protection Impact Assessment, including a legitimate interest assessment where that is the basis relied on and a transfer assessment where data moves offshore. The scale and the number of systems involved make the risk analysis substantively different from a single practice.
Training across shifts and sites
Training under CDPG 1 of 2025 has to reach every member of staff who handles personal data, which in a hospital means reception, records, nursing, laboratory, pharmacy, billing and portering, across shifts and across sites. This usually takes multiple sessions rather than one, and the training record has to show who attended which session and when.
Which package fits a larger provider
Compliance packages start at $250 as a one-off service fee, which is scoped for a solo, single-site practice. Group practices, pharmacy chains, busy laboratories and small to mid-size hospitals generally need the Pro engagement at $650, which adds the full DPIA with legitimate interest and transfer assessments, an expanded ROPA across departments and systems, third-party data processing and sharing agreements, a prioritised remediation plan, a cross-border transfer assessment and training extended across multiple sessions.
Hospital groups, multi-site providers and medical aid societies take the Enterprise engagement from $1,500, which adds a full compliance audit, multi-site rollout, board and all-staff training, cross-border data transfer notifications and quarterly compliance reviews. Every engagement begins with the $90 consultation, credited in full toward the package.
A Data Protection Officer is a condition of holding the licence at every tier. Larger providers usually appoint an external DPO on record or designate an internal one supported externally. The engagement options are on the main compliance page.
Sequencing a multi-site rollout
With inspections beginning on 1 September 2026 and healthcare in the first wave, order of work matters. The licence application and processing notification go first, because those are the items whose absence is an offence in itself. The ROPA and DPIA follow, because they are what the rest of the evidence hangs off. The remediation plan then sequences the fixes by risk, so that the highest-risk gaps, usually unsecured transmission of patient data and uncontrolled access to records areas, are closed before the lower-risk ones. Training runs in parallel because it can be scheduled around clinical work.
Frequently asked questions
Does each branch of a clinic group need its own POTRAZ licence?
No, not where one legal entity operates the branches. The record counts across all sites add together and the entity is licensed once at the combined tier. Where a group is made up of separate legal entities, each entity is a data controller in its own right and is licensed separately.
How much is a POTRAZ licence for a hospital?
It depends on the record count. Tier 2, covering 1,001 to 100,000 records, is $300. Tier 3, covering 100,001 to 500,000 records, is $500. Tier 4, above 500,000 records, is $2,500. All figures are exclusive of VAT and a $30 application fee applies from Tier 2 upward.
Do employee records count towards the tier?
Yes. The tier is based on the total number of individuals whose personal data you hold, which includes employees, locums and contractors as well as current and historical patients and business contacts.
Does a hospital using an offshore cloud system make a cross-border transfer?
If patient data is stored or processed outside Zimbabwe then yes, a cross-border transfer is taking place. This is common and often unnoticed, because the transfer happens inside a software product that feels local. The transfer has to be assessed and, where required, notified.
What is the difference between the Pro and Enterprise packages?
Pro at $650 covers group practices, pharmacy chains, busy laboratories and small to mid-size hospitals, adding a full DPIA, an expanded departmental ROPA, third-party agreements, a remediation plan and a cross-border transfer assessment. Enterprise from $1,500 adds a full compliance audit, multi-site rollout, board and all-staff training, cross-border transfer notifications and quarterly reviews.
Get licensed and inspection-ready
Compliance packages start at $250. Every engagement begins with a one-hour consultation at $90, credited in full toward your package when you proceed. POTRAZ fees are separate and passed through at cost.