Skip to content

Research · authority data, public-interest

← Back to Legal library

ACT — Cyber and Data Protection Act (Chapter 12 07)

ACT · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

Cyber-Data-Protection-Act-Cap1207-No-5-of-2021-gaz-2022-03-11.pdf

application/pdf · 1.2 MB

Sanitised text

Cyber and Data Protection Act [Chapter 12:07] (No. 5 of 2021) — Verbatim Transcription

Citation key: ACT · Category: Primary statute · Pages: 38

Source PDF: Cyber & Data Protection Act Cap1207 No 5 of 2021 gaz 2022-03-11.pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

CYBER AND DATA PROTECTION ACT [CHAPTER 12:07]

ARRANGEMENT OF SECTIONS

PART I

Preliminary

Section

DISTRIBUTED BY VERITAS

1.Short title. E-mail: veritas@mango.zw Website: www.veritaszim.net

2. Object. VERITAS MAKES EVERY EFFORT TO ENSURE THE PROVISION OF RELIABLE INFORMATION,

3.Interpretation.
4.Application.

PART II

Data Protection authority

5. Designation of Postal and Telecommunications Regulatory Authority as Data

Protection Authority.

6.Functions of Data Protection Authority.

PART III

Quality of Data

7.Quality of data.

PART IV

General rules on the ProcessinG of Data

8.Generality.
9.Purpose.
10.Non-sensitive data.
11.Sensitive information.
12.Genetic data, biometric sensitive data and health data.

PART V

Duties of Data controller anD Data Processor

13.Duties of Data Controller.
14.Rights of Data Subject.
15.Disclosures when collecting data directly from data subject.
16.Disclosures when not collecting data directly from data subject.
17.Authority to process.
18.Security.
19.Security breach notification.
20.Obligation of notification to Authority.
21.Content of notification.
22.Authorisation.
23.Openness of processing.
24.Accountability. 41
Page 2 of 38

No. 5/2021 Cyber and data ProteCtion Cap. 12:07

PART VI

Data subject

Section

25.Decision taken on basis of Automatic Data Processing.
26.Representation of data subjection who is a child.
27.Representation of physically, mentally or legally incapacitated data subjects.

PART VII

transborDer flow

28.Transfer of personal information outside Zimbabwe.

29. Transfer to country outside the Republic of Zimbabwe which does not assure

adequate level of protection.

PART VIII

coDe of conDuct

30.Code of conduct.

PART IX

whistleblowinG

31.Whistleblower.

PART X

General Provisions

32.Regulations.
33.Offences and penalties.
34.Appeals.

PART XI

conseQuential amenDments

35.Amendment of Chapter VIII of Cap. 9:23.
36.Amendment of Cap. 9:07.
37.Amendment of Cap. 11:20. 42
Page 3 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

ZIMBABWE

ACT

An Act to provide for data protection with due regard to the Declaration of Rights under the Constitution and the public and national interest; to establish a Cyber Security Centre; a Data Protection Authority and to provide for their functions; to create a technology driven business environment and encourage technological development and the lawful use of technology; to amend sections 162 to 166 of the Criminal Code (Codification and Reform) Act [Chapter 9:23] to provide for investigation and collection of evidence of cyber crime and unauthorised data collection and breaches, and to provide for admissibility of electronic evidence for such offences and to provide for matters connected with or incidental to the foregoing. ENACTED by the Parliament and the President of Zimbabwe.

PART I

Preliminary

1 Short title

This Act may be cited as the Cyber and Data Protection Act [Chapter 12:07].

2 Object

The object of this Act is to increase cyber security in order to build confidence and trust in the secure use of information and communication technologies by data controllers, their representatives and data subjects. Printed by the Government Printer, Harare 43

Page 4 of 38

No. 5/2021 Cyber and data ProteCtion Cap. 12:07

3 Interpretation

In this Act— “child” means any person under the age of eighteen years; “code of conduct” refers to the Data Use Charters drafted by the data controller in order to institute the rightful use of IT processes, the Internet, and electronic communications of the structure concerned, and which have been approved by the Data Protection Authority; “consent” refers to any manifestation of specific unequivocal, freely given, informed expression of will by which the data subject or his or her legal, judicial or legally appointed representative accepts that his or her data be processed; “critical database” means a computer data storage medium or any part thereof which contains critical data; “data” means any representation of facts, concepts, information, whether in text, audio, video, images, machine-readable code or instructions, in a form suitable for communications, interpretation or processing in a computer device, computer system, database, electronic communications network or related devices and includes a computer programme and traffic data; “data controller” or “controller”—

(a)refers to any natural person or legal person who is licensable by the Authority;
(b)includes public bodies and any other person who determines the purpose and means of processing data; “data controller’s representative” or “controller’s representative” refers to any natural person or legal person who performs the functions of the data controller in compliance with obligations set forth in this Act; “Data processor” refers to a natural person or legal person, who processes data for and on behalf of the controller and under the controller’s instruction, except for the persons who, under the direct employment or similar authority of the controller, are authorised to process the data; “Data Protection Authority” or “Authority” refers to Postal and Telecommunications Regulatory Authority of Zimbabwe established in terms of section 5 of the Postal and Telecommunications Act [Chapter 12:05]; “data protection officer” or “DPO” refers to any individual appointed by the data controller and is charged with ensuring, in an independent manner, compliance with the obligations provided for in this Act; “data subject” refers to an individual who is an identifiable person and the subject of data; “disproportionate effort” means effort that is so labour intensive as to consume a lot of time, money and manpower resources; “electronic communications network” means any electronic communication infrastructure and facilities used for the conveyance of data; “genetic data: refers to any personal information stemming from a Deoxyribonucleic acid (DNA) analysis; “health professional” refers to any individual determined as such by Zimbabwean law; “identifiable person” means a person who can be identified directly or indirectly, in particular by reference to an identification number or to one or more 44
Page 5 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

factors specific to his or her physical, physiological, mental, economic, cultural or social identity; “Minister” means the Minister responsible for information and communications technologies; “personal information” means information relating to a data subject, and includes—

(a)the person’s name, address or telephone number;
(b)the person’s race, national or ethnic origin, colour, religious or political beliefs or associations;
(c)the person’s age, sex, sexual orientation, marital status or family status;
(d)an identifying number, symbol or other particulars assigned to that person;
(e)fingerprints, blood type or inheritable characteristics;
(f)information about a person’s health care history, including a physical or mental disability;
(g)information about educational, financial, criminal or employment history;
(h)opinions expressed about an identifiable person;
(i)the individual’s personal views or opinions, except if they are about someone else; and
(j)personal correspondence pertaining to home and family life; “processing” refers to any operation or set of operations which are performed upon data, whether or not by automatic means, such as obtaining recording or holding the data or carrying out any operation or set of operations on data, including—
(a)organisation, adaptation or alteration of the data;
(b)retrieval, consultation or use of the data; or
(c)alignment, combination, blocking, erasure or destruction of the data; “recipient” a natural or legal person, agency or any other body to whom personal information is disclosed by a data controller, whether a third party or not; however, persons who receive personal information in the framework of a particular legal inquiry shall not be regarded as recipients; “sensitive data” refers to—
(a)information or any opinion about an individual which reveals or contains the following—
(i)racial or ethnic origin;
(ii)political opinions;
(iii)membership of a political association;
(iv)religious beliefs or affiliations;
(v)philosophical beliefs;
(vi)membership of a professional or trade association;
(vii)membership of a trade union;
(viii)sex life;
(ix)criminal educational, financial or employment history;
(x)gender, age, marital status or family status; 45
Page 6 of 38

No. 5/2021 Cyber and data ProteCtion Cap. 12:07

(b)health information about an individual;
(c)genetic information about an individual; or
(d)any information which may be considered as presenting a major risk to the rights of the data subject; “third party” refers to any natural or legal person or organisation other than the data subject, the controller, the processor and anyone who, under the direct authority of the controller or the processor, is authorised to process the data; “transborder flow” refers to international flows of data by the means of transmission including data transmission electronically or by satellite; “whistleblowing” refers to legal provisions permitting individuals to report the behaviour of a member of their organisation which, they consider contrary to a law or regulation or fundamental rules established by their organisation.

4 Application

(1)This Act shall apply to matters relating to access to information, protec- tion of privacy of information and processing and storage of data wholly or partly by automated means: and shall be interpreted as being in addition to and not in conflict or inconsistent with the Protection of Personal Information Act [Chapter 10:27].
(2)Subject to subsection (1) this Act shall be applicable—
(a)to the processing of data carried out in the context of the effective and actual activities of any data controller;
(b)to the processing and storage of data by a controller who is not permanently established in Zimbabwe, if the means used, whether electronic or otherwise is located in Zimbabwe, and such processing and storage is not for the purposes of the mere transit of data through Zimbabwe.
(3)In the circumstances referred to in subsection (2)(b), the controller shall designate a representative established in Zimbabwe, without prejudice to legal proceedings that may be brought against the controller.

PART II

Data Protection Authority

5 Designation of Postal and Telecommunications Regulatory Authority

as Data Protection Authority The Postal and Telecommunications Regulatory Authority established in terms of the Postal and Telecommunications Act [Chapter 12:05] is hereby designated as the Data Protection Authority.

6 Functions of Data Protection Authority

(1)The Authority shall perform the following functions—
(a)to regulate the manner in which personal information may be processed through the establishment of conditions for the lawful processing of data;
(b)to promote and enforce fair processing of data in accordance with this Act;
(c)to issue its opinion either of its own accord, or at the request of any person with a legitimate interest, on any matter relating to the application of the 46
Page 7 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

fundamental principles of the protection of privacy, in the context of this Act;

(d)to submit to any Court any administrative act which is not compliant with the fundamental principles of the protection of the privacy in the frame- work of this Act as well as any law containing provisions regarding the protection of privacy in relation to the processing of data in consultation with Minister responsible for Information, Publicity and Broadcasting Services;
(e)to advise the Minister on matters relating to right to privacy and access to information;
(f)to conduct inquiries or investigations either of its own accord or at the request of the data subject or any interested person, and in relation thereto may call upon the assistance of experts to carry out its functions and may request the disclosure of any documents that may be of use for their inquiry or investigation;
(g)to receive, by post or electronic means or any other equivalent means, the complaints lodged against data processing and give feed-back to the claimants or complainants;
(h)to investigate any complaint received in terms of this Act howsoever received;
(i)to conduct research on policy and legal matters relating to the development of international best practices on the protection of personal information in Zimbabwe and advise the Minister accordingly;
(j)in consultation with the Minister, to facilitate cross border cooperation in the enforcement of privacy laws and participating at national, regional and international forums mandated to deal with the protection of personal information initiatives.
(2)Subject to this Act, the Authority shall not, in the lawful exercise of its functions under this Act, be subject to the direction or control of any person or authority.

PART III

Quality of Data

7 Quality of Data

(1)The data controller shall ensure that data processed is—
(a)adequate, relevant and not excessive in relation to the purposes for which it is collected or further processed;
(b)accurate and, where necessary, kept up-to-date;
(c)retained in a form that allows for the identification of data subjects, for no longer than necessary with a view to the purposes for which the data is collected or further processed.
(2)The data controller shall take all appropriate measures to ensure that data processed shall be accessible regardless of the technology used and ensure that the evolution of technology shall not be an obstacle to the access or processing of such data.
(3)The controller shall ensure compliance with the obligations set out in subsections (1) and (2) by any person working under his or her authority and any subcontractor. 47
Page 8 of 38

No. 5/2021 Cyber and data ProteCtion Cap. 12:07

PART IV

General rules on the ProcessinG of Data

8 Generality

The data controller shall ensure that the processing of data is necessary and that the data is processed fairly and lawfully.

9 Purpose

(1)The data controller shall ensure that data is collected for specified, explicit and legitimate purposes and, taking into account all relevant factors, especially the reasonable expectations of the data subject and the applicable legal and regulatory provisions, that the data is not further processed in a way incompatible with such purposes.
(2)Under the conditions established by the Authority, further processing of data for historical, statistical or scientific research purposes is not considered incompatible.

10 Non-sensitive data

(1)Personal information may only be processed if the data subject or a competent person, where the data subject is a child, consents to the processing of such data.
(2)The consent referred to in subsection (1) may be implied where the data subject is an adult natural person or has a legal persona and has full legal capacity to consent.
(3)The processing of non-sensitive data is permitted, without the consent of the data subject, where necessary for purposes of—
(a)being material as evidence in proving an offence; or
(b)compliance with an obligation to which the controller is subject by or by virtue of a law; or
(c)protecting the vital interests of the data subject; or
(d)performing a task carried out in the public interest, or in the exercise of the official authority vested in the controller, or in a third party to whom the data is disclosed; or
(e)promoting the legitimate interests of the controller or a third party to whom the data is disclosed, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject claiming protection under this Act.
(4)The Authority may specify the circumstances in which the condition stipulated under subsection (3)(e) are considered as having been met.

11 Sensitive information

(1)No data controller shall process sensitive data unless the data subject has given consent in writing for such processing;
(2)The consent to the processing of data may be withdrawn by the data subject at any time and without any explanation and free of charge;
(3)The Authority shall determine the circumstances in which the prohibition to process the data referred to in this subsection (1) cannot be lifted even with the data 48
Page 9 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

subject’s consent (taking into account the factors surrounding the prohibition and the reasons for collecting the data).

(4)The Minister responsible for the Cyber security and Monitoring Centre in consultation with the Minister, may give directions on how to implement this section with respect to sensitive information affecting national security or the interests of the State.
(5)The provisions of subsection (1) shall not apply where—
(a)the processing is necessary to carry out the obligations and specific rights of the controller in the field of employment law; or
(b)the processing is necessary to protect the vital interests of the data subject or of another person, where the data subject is physically or legally incapable of giving his or her consent or is not represented by his or her legal, judicial or agreed representative; or
(c)the processing is carried out in the course of its legitimate activities by a foundation, association or any other non-profit organisation with a political, philosophical, religious, health-insurance or trade-union purpose and on condition that the processing relates solely to the members of the organisation or to persons who have regular contact with it in connection with such purposes and that the data is not disclosed to a third party without the data subjects’ consent; or
(d)the processing is necessary to comply with national security laws; or
(e)the processing is necessary, with appropriate guarantees, for the establishment, exercise or defence of legal claims; or
(f)the processing relates to data which has been made public by the data subject; or
(g)the processing is necessary for the purposes of scientific research: Provided the Authority shall be entitled to specify the conditions under which such processing may be carried out; or
(h)the processing of data is authorised by a law or any regulation for any other reason constituting substantial public interest.
(6)Without prejudice to the application of sections 5 to 8, the processing of data relating to sex life is authorised if—
(a)it is carried out by an association with a legal personality or by an organisation of public interest whose main objective, according to its Memorandum and Articles of Association, is the evaluation, guidance or treatment of persons of such sexual conduct, and who is recognised by a competent public body as being responsible for the welfare of such persons;
(b)the objective of the processing of the data consist of the evaluation, guidance and treatment of the persons referred to in this section, and the processing of data relates only to the afore-mentioned persons: Provided that the competent public body referred to in paragraph (a) grants a specific, individualised authorisation, having received the opinion of the Authority.
(7)The authorisation referred to in this section shall specify the duration of the authorisation, the conditions for supervision of the authorised association or organisation by the competent public body, and the way in which the processing must be reported to the Authority. 49
Page 10 of 38

No. 5/2021 Cyber and data ProteCtion Cap. 12:07

12 Genetic data, biometric sensitive data and health data

(1)The processing of genetic data, biometric data and health data is prohibited unless, the data subject has given consent in writing to the processing.
(2)The consent referred to in subsection (1) can be withdrawn by the data subject at any time without any reasons and free of charge.
(3)The provisions of subsection (1) shall not apply where—
(a)the processing is necessary to carry out the specific obligations and rights of the controller in the field of employment law; or
(b)the processing is necessary to comply with national security laws; or
(c)the processing is necessary for the promotion and protection of public health, including medical examination of the population; or
(d)the processing is required by or by virtue of a law or any equivalent legislative act for reasons of substantial public interest; or
(e)the processing is necessary to protect the vital interests of the data subject or another person, where the data subject is physically or legally incapable of giving his or her consent or is not represented by his or her legal, judicial or agreed representative; or
(f)the processing is necessary for the prevention of imminent danger or the mitigation of a specific criminal offence; or
(g)the processing relates to data which has apparently been made public by the data subject; or
(h)the processing is necessary for the establishment, exercise or defense of legal rights; or
(i)the processing is required for the purposes of scientific research; or
(j)the processing is necessary for the purposes of preventive medicine or medical diagnosis, the provision of care or treatment for the data subject or to one of his or her relatives, or the management of health-care services in the interest of the data subject, and the data is processed under the supervision of a health professional.
(4)Health-related data may only be processed under the responsibility of a health-care professional, except if the data subject has given his or her written consent or if the processing is necessary for the prevention of imminent danger or for the mitigation of a specific criminal offence.
(5)The Authority shall be entitled to specify the conditions under which such processing may be carried out.
(6)Health related data may only be collected from other sources where the data subject is incapable of providing the data.
(7)For the purposes of processing personal information under this section, the health professional and his or her agents are subject to the duty of professional secrecy.
(8)The processing of genetic data, shall be authorised if it is processed for what it reveals or contains and data concerning health shall be processed only if a unique patient identifier is given to the patient which is distinct from any other identification number, issued by the public authority established for this purpose.
(9)The association of the unique patient identifier with any other identifier which permits the identification of the data subject as provided for in section 8 is permissible only with the express authorisation of the Authority.
(10)The data of a child shall be processed subject to section 26. 50
Page 11 of 38

Cap. 12:07 Cyber and data ProteCtion No. 5/2021

PART V

Duties of Data controller anD Data Processor

13 Duties of Data Controller

Every data controller or data processor shall ensure that personal information is—

(a)processed in accordance with the right to privacy of the data subject;
(b)processed lawfully, fairly and in a transparent manner in relation to any data subject;
(c)collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes;
(d)adequate, relevant, limited to what is necessary in relation to the purposes for which it is processed;
(e)collected only where a valid explanation is provided whenever information relating to family or private affairs is required;
(f)accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure that any inaccurate personal data is erased or rectified without delay; and kept in a form which identifies the data subjects for no longer than is necessary for the purposes which it was collected.

14 Rights of Data Subject

A data subject has a right to—

(a)be informed of the use to which their personal information is to be put;
(b)access their personal information in custody of data controller or data processor;
(c)object to the processing of all or part of their personal information;
(d)correction of false or misleading personal information; and;
(e)deletion of false or misleading data about them.

15 Disclosures when collecting data directly from data subject

(1)When obtaining data directly from the data subject, the controller or the controller’s representative shall provide the data subject with at least the following information, unless the data subject has already received such information—
(a)the name and address of the controller and of his or her representative, if any;
(b)the purposes of the processing;
(c)the existence of the right to object, by request and free of charge, to the intended processing of data relating to him or her, if it is obtained for the purposes of direct marketing;
(d)whether compliance with the request for information is compulsory or not, as well as what the consequences of the failure to comply are;
(e)taking into account the specific circumstances in which the data is collected, any supporting information, as necessary to ensure fair processing for the data subject, such as—
(i)the recipients or categories of recipients of the data;
(ii)whether it is compulsory to reply, and what the possible consequences of the failure to reply are; 51
Referenced by Privacy Hub
Cross-border transfer of personal data

A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.

Data controller

A data controller is the person or organisation that decides why personal data will be used and the essential means of using it. A controller remains responsible even when another organisation processes the information on its behalf. The legal test, licensing duties and terminology can vary, so check the jurisdiction view for the rules that apply.

Data processor

A data processor is a person or organisation that handles personal data for a controller and under the controller’s instructions. Hosting companies, payroll providers and outsourced support services may act as processors in some arrangements. Their role depends on what they actually decide and do, not simply on the label used in a contract.

Data Protection Officer (DPO)

A Data Protection Officer is an independent privacy-compliance specialist who helps an organisation understand its duties, monitor its practices, advise on risk and act as a contact point for people and regulators. A DPO should have suitable expertise, resources and freedom from conflicting roles. Whether appointment, certification or notification is required depends on the jurisdiction.

Data subject

A data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.

Personal data and personal information

Personal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.

Personal-data breach

A personal-data breach is a security failure that leads to personal data being lost, destroyed, changed, disclosed or accessed without proper authority. It can result from a cyberattack, mistake, lost device, misdirected message or supplier incident. Not every security incident is a personal-data breach, but every suspected breach should be assessed promptly under the applicable jurisdiction.

POTRAZ and its data-protection role

POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.

Privacy notice

A privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.

Processing personal data

Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.

Zimbabwe’s Cyber and Data Protection Act (CDPA)

The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.