Zimbabwe and UK data protection, in plain language
Zimbabwe and the UK have different rules and different deadlines. Pick one and we will only show what applies to you. Not sure yet? We will show both.
What do you want to sort out?
Ask a data-protection question in your own words, or pick one below. You will get a straight answer and one thing to do next.
We match your question to a free check. We do not store what you type.
What privacy question can we help with?
- Do data-protection laws even apply to my little business?
- Do I have to register with the ICO or pay the data-protection fee?
- Do I need a POTRAZ licence to hold customer data?
- Which POTRAZ tier am I, and how much is the licence?
- I'm not based in Zimbabwe or the UK but I have users there — do the rules apply?
- How much does compliance actually cost?
- Where do I even start?
- Do I need a Data Protection Officer?
- Can the same person be the DPO and the owner or founder?
- Does my DPO need a certificate or training in Zimbabwe?
- Do I need a privacy policy on my website?
- What has to go in a privacy notice?
- Do I have to tell people how I use data I got from somewhere else?
- Do I need a cookie banner?
- Do I need consent for Google Analytics or tracking?
- Do I always need consent to collect personal data?
- What's my lawful basis — and which one do I pick?
- Can I rely on legitimate interests instead of consent?
- Can I send marketing emails to people who haven't opted in?
- Can I email existing customers?
- Can I buy or rent a marketing list?
- Do I need consent for SMS or WhatsApp marketing?
- We had a data breach — do I have to report it?
- What actually counts as a data breach?
- How long do I have to report a breach — 72 hours or 24?
- Do I have to tell the customers whose data leaked?
- Someone asked for all the data I hold on them — what do I do?
- How long do I have to respond to a subject access request?
- Can I charge for a data request, or refuse it?
- Someone asked me to delete their data — do I have to?
- How long can I keep customer data?
- When do I have to delete old data?
- Do I need to write down everything I do with data?
- Can I store customer data on US servers or use a US cloud?
- Can I send personal data outside Zimbabwe or the UK?
- Do I need a contract with my software suppliers?
- Is my SaaS, CRM or email tool compliant?
- We share data with a partner — what do we need?
- Can I collect data about children, and do I need parental consent?
- What is special-category or sensitive data, and what's different?
- Can I use ChatGPT or AI tools with customer data?
- My staff are pasting data into AI tools — is that a problem?
- Do I need a DPIA, and how do I do one?
- I'm building an app — what privacy work do I need before launch?
- What are the fines if I get this wrong?
- What happens if the regulator gets a complaint about me?
I want to…
What Privacy Lab is
A free tool that tells you where your organisation stands on data protection — and what to do about it. Plain language, real answers, built for Zimbabwe and the UK.
How it works
- 1
Tell us what's on your mind. Ask a question, or start from your industry or your situation.
- 2
Run a free check. Five to twenty-five plain-language questions. No account, no email.
- 3
Get a straight answer. A grade, your biggest gap, and one thing to do next.
Why we built it
Every organisation has to start its privacy journey somewhere: figuring out how to use personal data responsibly, protect it properly, and stay on the right side of the law. We built Privacy Lab because that starting point should not cost anything — good privacy advice should not be something only large organisations can afford. Every check is free to run and free to read.
The questions people ask most
Every one of these opens a free check that answers it.
Do I have to register with the ICO or pay the data-protection fee?
Probably yes — in the UK you pay the ICO fee; in Zimbabwe you need a POTRAZ licence by tier. Two minutes to find out.
Start now — no account neededDo I need a privacy policy on my website?
If you collect any personal data, yes — and a copy-pasted template usually will not pass.
Start now — an account saves your resultWe had a data breach — do I have to report it?
Maybe, and fast: 24 hours to POTRAZ in Zimbabwe (including a suspected breach), 72 hours to the ICO in the UK. Triage it now.
Start — you will need an organisation code (we can make one)Someone asked for all the data I hold on them — what do I do?
You must respond, free, within a month. Check your DSAR readiness.
Start — you will need an organisation code (we can make one)Do I need a Data Protection Officer?
UK: usually no. Zimbabwe: usually yes, certified, within 90 days. Check your obligation.
Start now — an account saves your resultDo I need a cookie banner?
Non-essential cookies need real opt-in — scan your site.
Start now — an account saves your resultCan I send marketing emails to people who haven't opted in?
Only with consent or a valid soft opt-in. Check before you send.
Start now — an account saves your resultHow long can I keep customer data?
Only as long as you have a purpose — build a retention schedule.
Start — you will need an organisation code (we can make one)Can I use ChatGPT or AI tools with customer data?
Carefully — check your AI readiness and shadow-AI exposure.
Start now — an account saves your resultDo data-protection laws even apply to my little business?
Almost certainly — get your exposure score.
Start — you will need an organisation code (we can make one)Can I store customer data on US servers or use a US cloud?
It's a transfer and needs a safeguard — run a transfer check.
Start — you will need an organisation code (we can make one)Do I need a contract with my software suppliers?
Yes — every processor needs a DPA. Check your vendors.
Start — you will need an organisation code (we can make one)What are the fines if I get this wrong?
Zimbabwe: up to a level 11 fine and 7 years, but a DPO-appointment lapse is lower at level 7 and 2 years. We show the current cash value from the standard scale rather than a fixed number.
Start now — no account neededDo I always need consent to collect personal data?
Often not consent — find your correct lawful basis.
Start now — an account saves your resultI'm building an app — what privacy work do I need before launch?
A full pre-launch privacy stack — run the app-builder checklist.
Start now — an account saves your resultWhich POTRAZ tier am I, and how much is the licence?
Your data-subject count sets your tier — and your tier sets the licence fee, shown live from the current fee schedule.
Start now — an account saves your result
Don't just run one check — follow a pathway.
A pathway puts the right checks in the right order for your situation, from 'where do we stand?' to 'we can prove we are OK'. Free, like everything else here. An organisation code saves your progress — still no account, no email.
- I want a quick privacy checkA fast, honest read — a number, your biggest gap, and which rulebook applies. About five minutes.3 steps · about 34 min
- I want to win this contractAnswer the security and privacy questionnaire and pass, with an evidence pack mapped to what buyers ask.8 steps · about 75 min
- Something happened — I need to handle a breachDo the legally required things, in order, fast. Zimbabwe: 24 hours to POTRAZ, including a suspected breach. UK: 72 hours to the ICO.4 steps · about 33 min