Skip to content

Privacy Hub · plain-language reference

Public reference · plain language

Privacy Hub

Understand privacy terms and guidance in plain language. Browse the guides, read Zimbabwe’s data-protection instruments in full, or work through the A–Z. Pick one or more jurisdictions to see how a term plays out under that law.

Education, not legal advice. For a specific decision, consult a qualified adviser.

Search the Privacy Hub

16 published entries

Articles

Every published Privacy Hub article — plain-language explanations of a term, with the jurisdiction lenses it covers.

ArticleCross-border transfer of personal dataA cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.
ZW CDPA
EU GDPR
GB UK GDPR
ArticleData controllerA data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.
ZW CDPA
EU GDPR
GB UK GDPR
ArticleData processorA data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.
ZW CDPA
EU GDPR
GB UK GDPR
ArticleData Protection Officer (DPO)A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.
ZW CDPA
EU GDPR
GB UK GDPR
ArticleData subjectA data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.
ZW CDPA
EU GDPR
GB UK GDPR
ArticlePersonal data and personal informationPersonal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.
ZW CDPA
EU GDPR
GB UK GDPR
ArticlePersonal-data breachA personal-data breach is a security failure that leads to personal data being lost, destroyed, changed, disclosed or accessed without proper authority. It can result from a cyberattack, mistake, lost device, misdirected message or supplier incident. Not every security incident is a personal-data breach, but every suspected breach should be assessed promptly under the applicable jurisdiction.
ZW CDPA
EU GDPR
GB UK GDPR
ArticlePOTRAZ and its data-protection rolePOTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.
ZW CDPA
EU GDPR
GB UK GDPR
ArticlePrivacy noticeA privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.
ZW CDPA
EU GDPR
GB UK GDPR

Guides

Longer, plain-language walkthroughs — DPOs, breach clocks, notices, and how the EU GDPR maps onto Zimbabwe’s CDPA.

A–Z of privacy terms

Every published term and definition, in one place.

C

  • Sending personal data outside Zimbabwe — including using cloud services hosted abroad. The CDPA restricts this and usually requires safeguards.

    For example: Using an overseas email or CRM provider counts as a transfer.

  • Cross-border transfer of personal data
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.

    Learn more — read the full article

D

  • When personal data is lost, exposed, changed, or accessed by someone who shouldn't see it — whether by accident or attack.

    For example: A stolen laptop with unencrypted patient records; an email sent to the wrong list.

  • Data controller
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.

    Learn more — read the full article
  • Data processor
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.

    Learn more — read the full article
  • Data Protection Officer (DPO)
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.

    Learn more — read the full article
  • Data subject
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.

    Learn more — read the full article

P

  • Any information about a person that could identify them — a name and phone number, an ID or account number, a photo, a location, even an IP address alongside other details.

    For example: Your customer list, staff records, a WhatsApp number tied to an order.

  • Personal data and personal information
    Term
    ZW CDPAEU GDPRGB UK GDPR

    Personal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.

    Learn more — read the full article
  • Personal-data breach
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A personal-data breach is a security failure that leads to personal data being lost, destroyed, changed, disclosed or accessed without proper authority. It can result from a cyberattack, mistake, lost device, misdirected message or supplier incident. Not every security incident is a personal-data breach, but every suspected breach should be assessed promptly under the applicable jurisdiction.

    Learn more — read the full article
  • POTRAZ
    Term

    The Postal and Telecommunications Regulatory Authority of Zimbabwe — Zimbabwe's data-protection authority and licensing body under the CDPA.

  • POTRAZ and its data-protection role
    Term
    ZW CDPAEU GDPRGB UK GDPR

    POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.

    Learn more — read the full article
  • Privacy notice
    Term
    ZW CDPAEU GDPRGB UK GDPR

    A privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.

    Learn more — read the full article
  • Anything you do with personal data — collecting, storing, sharing, changing, or deleting it — counts as processing.

    For example: Adding a customer to a CRM, backing up a database, sending a marketing email.

  • Processing personal data
    Term
    ZW CDPAEU GDPRGB UK GDPR

    Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.

    Learn more — read the full article

Z

  • The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.

    Learn more — read the full article