Privacy Hub · plain-language reference
Public reference · plain language
Privacy Hub
Understand privacy terms and guidance in plain language. Browse the guides, read Zimbabwe’s data-protection instruments in full, or work through the A–Z. Pick one or more jurisdictions to see how a term plays out under that law.
Education, not legal advice. For a specific decision, consult a qualified adviser.
Search the Privacy Hub
16 published entries
Featured
Articles
Every published Privacy Hub article — plain-language explanations of a term, with the jurisdiction lenses it covers.
Guides
Longer, plain-language walkthroughs — DPOs, breach clocks, notices, and how the EU GDPR maps onto Zimbabwe’s CDPA.
Legal library
Zimbabwe’s data-protection statutes, statutory instruments and POTRAZ guidance — readable in full here, with the original PDFs where we hold them.
19 instruments published · 19 with a downloadable PDF · readable in full on this site
Acts of Parliament(1)
Statutory instruments(2)
POTRAZ guidelines (CDPG)(13)
- CDPG 1 of 2024 — Appointment, Roles, Training & Certification of DPOsPDF · 1.6 MB
- CDPG 1 of 2025 — Compliance AssessmentsPDF · 1.6 MB
- CDPG 1 of 2025 — Licensing of Data ControllersPDF · 4.8 MB
- CDPG 2 of 2024 — Processing of Children's Personal InformationPDF · 384 KB
+ 9 more in this group
Strategies & policies(3)
- National AI Strategy 2026 2030PDF · 1.6 MB
- National Cyber Security Strategy (draft 1.0)PDF · 3.1 MB
- Zimbabwe NDS 2 PolicyPDF · 7.8 MB
A–Z of privacy terms
Every published term and definition, in one place.
C
Sending personal data outside Zimbabwe — including using cloud services hosted abroad. The CDPA restricts this and usually requires safeguards.
For example: Using an overseas email or CRM provider counts as a transfer.
A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.
Learn more — read the full article
D
- Data breachTerm
When personal data is lost, exposed, changed, or accessed by someone who shouldn't see it — whether by accident or attack.
For example: A stolen laptop with unencrypted patient records; an email sent to the wrong list.
A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.
Learn more — read the full articleA data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.
Learn more — read the full articleA Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.
Learn more — read the full articleA data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.
Learn more — read the full article
P
- Personal dataTerm
Any information about a person that could identify them — a name and phone number, an ID or account number, a photo, a location, even an IP address alongside other details.
For example: Your customer list, staff records, a WhatsApp number tied to an order.
Personal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.
Learn more — read the full articleA personal-data breach is a security failure that leads to personal data being lost, destroyed, changed, disclosed or accessed without proper authority. It can result from a cyberattack, mistake, lost device, misdirected message or supplier incident. Not every security incident is a personal-data breach, but every suspected breach should be assessed promptly under the applicable jurisdiction.
Learn more — read the full article- POTRAZTerm
The Postal and Telecommunications Regulatory Authority of Zimbabwe — Zimbabwe's data-protection authority and licensing body under the CDPA.
POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.
Learn more — read the full articleA privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.
Learn more — read the full article- ProcessingTerm
Anything you do with personal data — collecting, storing, sharing, changing, or deleting it — counts as processing.
For example: Adding a customer to a CRM, backing up a database, sending a marketing email.
Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.
Learn more — read the full article
Z
The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.
Learn more — read the full article