Data TrustData Trust
CDPA & GDPR compliant

Run your DPO practice from one dashboard

Manage POTRAZ licensing, breach response, DPIAs, ROPA, policies, staff training and audits for every client company you serve, with compliance percentages you can explain at a glance.

No card required Set up in minutes Cancel anytime
CDPA & GDPR compliant

Built for Zimbabwe's CDPA, and GDPR too

Customisable ROPA and DPIA templates aligned to the Cyber and Data Protection Act, ready to hand to any client company from day one.

No card required Set up in minutes Cancel anytime
CDPA & GDPR compliant

Grow from one client to an unlimited practice

Start on a single company, scale to a full roster. Sub-accounts, granular permissions and a compliance API grow with you.

No card required Set up in minutes Cancel anytime
11Compliance modules
24/7Secure cloud access
100%Auditable activity trail
14-dayFree trial on every plan
The platform

Everything a DPO practice needs

Eleven compliance modules per client company, one login for you and your team.

01

Licensing & Policies

Track POTRAZ certificate expiry and policy review cycles with automatic status flags, so nothing lapses without warning.

Learn more
02

Breach & Ticket Management

Log incidents and data subject requests with full status workflows, owners, deadlines and a complete response history.

Learn more
03

Customisable ROPA & DPIA

CDPA-aligned templates you can adapt per client, with pre-population, risk scoring and formal company sign-off.

Learn more
04

Training & Exams

Run staff awareness training with a built-in exam engine: retries, cooldowns, CSV question upload and certificates.

Learn more
05

Granular Sub-Accounts

Give each client login exactly the modules they need to edit; everything else stays safely view-only.

Learn more
06

Compliance API

Pull compliance scores, tickets and breach data into your own dashboards and client portals with a personal API key.

Learn more
How it works

From signup to your first audit

Four steps, and most practices are running live client work on day one.

1

Create your practice

Register your DPO account, choose a plan and invite the colleagues who work alongside you.

2

Add client companies

Each company gets its own workspace, its own documents and its own compliance percentage.

3

Work the modules

Licensing, breaches, ROPA, DPIA, policies, training and audits, all tracked with owners and due dates.

4

Report with confidence

Export a defensible record of everything done on each client's behalf, ready for the board or the regulator.

CDPA & GDPR aligned
About Data Trust

Compliance you can stand behind

Data Trust was built for the people who actually carry the compliance workload: independent Data Protection Officers and the in-house teams supporting them across Zimbabwe.

Instead of scattered spreadsheets and buried email trails, every client company gets its own workspace, its own compliance percentage, and an auditable record of everything done on its behalf. When a regulator asks what you did and when you did it, the answer is already documented.

Our aim is simple: make it straightforward to meet Cyber and Data Protection Act and GDPR obligations without a large compliance department, so a single DPO or a small advisory team can confidently serve any number of client companies.

  • Built around Zimbabwean law, not retro-fitted from abroad
  • Every action time-stamped and attributable
  • Your clients see only their own workspace
11compliance modules
CDPA& GDPR aligned
24/7access, any device
Talk to our team
What drives us

Our vision, mission and goal

Three statements that decide what we build and how we work with every client.

Vision

A Zimbabwe where personal data is handled with genuine care

We want to see a business landscape where protecting personal information is ordinary practice rather than a scramble before an inspection, where every organisation, from a five-person startup to a national bank, can show exactly how it safeguards the people it serves.

Goal

Be the platform behind Zimbabwe's most trusted practices

Our goal is to become the standard workspace for data protection work in the region: continually widening our module coverage, keeping our templates current with every regulatory update, and supporting our clients so well that their compliance percentage never has to be explained twice.

Integrity first
Confidentiality by default
Practical over theoretical
Respect for data subjects
Always improving
Use cases

Built for how DPOs actually work

Whichever kind of practice you run, the same platform scales with you.

Independent DPO practice

Serve multiple client companies from one login: track POTRAZ licensing, breaches and ROPA/DPIA per client, and show each of them their own compliance percentage.

Outsourced corporate DPO function

Act as the named DPO for a group of subsidiaries. Give each one a scoped login so their team can complete their own ROPA while you retain oversight and sign-off.

Legal & advisory firms

Layer data protection advisory onto existing client relationships: log advisory notes, run audits, and keep an auditable record of every recommendation given.

Fintech & regulated industries

Meet CDPA breach-notification and staff-training obligations with a documented exam trail, incident workflow and policy review schedule your regulator can see.

Testimonials

What practitioners tell us

Our clients handle sensitive information, so these accounts are shared anonymously at their request.

I was running six client companies out of three spreadsheets and a shared inbox. Now each one has its own workspace and I can answer "where are we on this?" in about four seconds instead of half an afternoon.
DPO Independent DPO Harare · verified client
The breach workflow is the part that earned its keep. We logged an incident, assigned it, and had the whole notification timeline documented without anyone having to remember what the Act requires.
DPO Independent DPO Financial services · verified client
Getting staff through data protection training used to be an annual argument. The exam engine handles retries and records who passed, so I just check the dashboard and move on.
DPO Independent DPO Retail group · verified client


Names and companies withheld at our clients' request, in keeping with our own confidentiality commitments.

Pricing

Simple, transparent pricing

All plans include a free trial. No setup fees, no long contracts, cancel anytime.

Starter
$5/mo

14-day free trial · 1 company

  • Manage 1 company
  • All core modules
  • Email support
Get started
Unlimited
$20/mo

14-day free trial · Unlimited companies

  • Unlimited companies
  • All modules
  • Dedicated support
Get started
Custom
Let's talk

Need something specific: a franchise network, a regulator, or a bespoke rollout?

  • Custom company limits
  • Custom onboarding & training
  • Dedicated support contact
  • Bespoke integrations on request
Contact us
Secure payments via Paynow Change plan at any time Support included on every plan
FAQ

Frequently asked questions

The things practitioners ask us most. If your question is not here, just send it through.

No. The platform is built around the way an independent Data Protection Officer works, but in-house compliance teams, legal firms and IT security providers use it just as effectively. If you are working towards POTRAZ registration, the licensing module will help you keep that process on track too.

Yes. The ROPA and DPIA templates, breach notification workflow and policy review cycles are all built around the CDPA and its requirements. The same records also map onto GDPR obligations, which matters if any of your clients process data belonging to people in Europe.

That depends on your plan. Entry plans cover a single company, and higher plans move up to unlimited. You can change plan at any time as your practice grows, and your existing data carries across untouched.

They can. Each client company can be given sub-accounts with granular permissions, so their staff can complete their own ROPA entries or training while everything else stays view-only. You keep oversight and final sign-off.

It is derived from the status of each module for that company: what has been completed, what is outstanding and what has lapsed. Because every item is visible underneath the score, you can always explain exactly how the number was reached.

Data is held on encrypted connections, access is scoped per account, and every action is logged with a user and a timestamp. We hold ourselves to the same standards we help our clients meet, our privacy policy sets out the detail.

Nothing is deleted. Your account moves to a read-only state until you choose a plan, so you keep access to everything you have recorded and can pick up exactly where you left off.

Yes. You can export your records, and the read-only REST API lets you pull compliance scores, tickets, breaches, ROPA and DPIA data into your own reporting tools with a personal API key.

We do. Every plan includes support, and we run onboarding sessions and monthly CDPA practitioner workshops. Larger rollouts can have dedicated onboarding arranged as part of a custom plan.

Payments are processed through Paynow, which covers local mobile money and card options. For annual or custom arrangements, get in touch and we will invoice you directly.

Still have a question?

Ask us directly

Need a custom Data Trust system?

Franchise networks, regulators and larger practices sometimes need a bespoke rollout. Tell us what you're running and we'll design a plan around it.

Contact us
Contact

Get in touch

Questions about pricing, onboarding, or the platform itself. We usually reply within a business day.

Phone / WhatsApp
+263 715 546 570
Office
Harare, Zimbabwe
Hours
Mon – Fri, 08:00 – 17:00 CAT
Developers
API documentation

Send us a message

Subscribe to our newsletter

Occasional updates on new compliance modules, CDPA guidance and product news. No spam.