Privacy Hub · plain-language reference
Privacy Hub articles
Full explanations with jurisdiction guidance and sources you can read in the Legal Library. Looking for a quick definition? Start from the A–Z on the Privacy Hub.
- ArticleCross-border transfer of personal dataA cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.ZW CDPAEU GDPRGB UK GDPR
- ArticleData controllerA data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.ZW CDPAEU GDPRGB UK GDPR
- ArticleData processorA data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.ZW CDPAEU GDPRGB UK GDPR
- ArticleData Protection Officer (DPO)A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.ZW CDPAEU GDPRGB UK GDPR
- ArticleData subjectA data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.ZW CDPAEU GDPRGB UK GDPR
- ArticlePersonal data and personal informationPersonal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.ZW CDPAEU GDPRGB UK GDPR
- ArticlePersonal-data breachA personal-data breach is a security failure that leads to personal data being lost, destroyed, changed, disclosed or accessed without proper authority. It can result from a cyberattack, mistake, lost device, misdirected message or supplier incident. Not every security incident is a personal-data breach, but every suspected breach should be assessed promptly under the applicable jurisdiction.ZW CDPAEU GDPRGB UK GDPR
- ArticlePOTRAZ and its data-protection rolePOTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.ZW CDPAEU GDPRGB UK GDPR
- ArticlePrivacy noticeA privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.ZW CDPAEU GDPRGB UK GDPR
- ArticleProcessing personal dataProcessing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.ZW CDPAEU GDPRGB UK GDPR
- ArticleZimbabwe’s Cyber and Data Protection Act (CDPA)The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.ZW CDPAEU GDPRGB UK GDPR