CDPG 1 of 2025 — Compliance Assessments
CDPG-1-2025-CA · v1 · release faf85cbc
CDPG 1 of 2025 — Compliance Assessments — Verbatim Transcription
Citation key: CDPG-1-2025-CA · Category: Implementation Guideline · Pages: 13
Source PDF: CDPA Implementation Guidelines/CDPG 1 of 2025 - Compliance Assessments.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 4
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Compliance Assessments CDPG 1 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 5
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Compliance Assessments
1. INTRODUCTION
These guidelines establish the framework, standards, and procedures for compliance assessments to be carried out by the Data Protection Authority (DPA), hereinafter referred to as the Authority, in respect of data controllers operating under the Cyber and Data Protection Act [CDPA]. The purpose of these guidelines is to ensure that all data controllers subject to the Act are held to a consistent, transparent oversight process, thereby strengthening the culture of accountability and compliance in Zimbabwe’s data protection landscape. The guidelines are issued in terms of section 6(1)(a) of the Cyber and Data Protection Act, which empowers the Authority to regulate the manner in which personal information may be processed through the establishment of clear conditions for the lawful processing of data. In line with this mandate, these guidelines provide a structured approach for assessing whether data controllers have in place the necessary governance, technical, and organisational measures to comply with the law. By issuing these guidelines, the Authority seeks to promote a consistent, fair, and transparent compliance assessment regime that not only enforces the law but also supports data controllers in building robust data protection practices. Ultimately, the objective is to ensure that the processing of personal information in Zimbabwe is conducted in a lawful, fair, and accountable manner, thereby safeguarding the rights and freedoms of data subjects while fostering trust in the digital economy.
2. OBJECTIVES OF COMPLIANCE ASSESSMENTS
The main objectives of the compliance assessment are:
3. TYPES OF COMPLIANCE ASSESSMENTS
In carrying out its mandate under the Cyber and Data Protection Act (CDPA), the Authority adopts a risk-based, proportionate, and transparent approach to compliance monitoring. The following types of compliance assessments may be conducted for data controllers to ensure compliance with the conditions for lawful processing of personal information.
3.1. Voluntary Assessment
‘creating a level playing field’
A voluntary assessment is an evaluation initiated at the request of the data controller. In this instance, the data controller submits a written invitation to the Authority, indicating its willingness to undergo a compliance review. The invitation should include a proposed date and time for the assessment.
Data Protection Authority Implementation Guidelines on the
Page 6
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
This type of assessment is collaborative, advisory, and non-punitive. It is not intended to result in the imposition of fines, sanctions, or corrective orders. Instead, it serves as a mechanism for data controllers to identify compliance gaps, strengthen their internal processes, and demonstrate commitment to lawful data processing practices. By taking the initiative, data controllers can proactively rectify deficiencies before they escalate into regulatory violations. Procedure:
3.2. Routine Planned Assessment
A routine planned assessment is a scheduled evaluation conducted by the Authority as part of its annual compliance monitoring programme. These assessments are intended to promote a culture of sustained readiness among data controllers and ensure that compliance with the CDPA is embedded in day-to-day operations. The Authority will provide the data controller with at least seven (7) days’ written notice before the assessment. The notification will outline the scope of the evaluation, the methodology to be applied, and the preliminary documentation required. It will also specify the categories of records that may be reviewed and the key personnel who are expected to participate in interviews or discussions. It must be noted that during a routine planned assessment, the Authority retains the right to request additional documentation, test relevant systems, or interview personnel not initially listed in the notification, where such measures are reasonably necessary to fulfil its mandate. Procedure:
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 7
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
3.3. Ad Hoc (Unannounced) Assessment
An ad hoc, or unannounced, assessment is conducted by the Authority without prior notice to the data controller. Such assessments are triggered by specific circumstances, including receipt of a complaint by a data subject, a data breach notification, intelligence suggesting non-compliance, or other factors that raise reasonable suspicion of unlawful processing. The purpose of an ad hoc assessment is to enable the Authority to investigate urgent or high-risk compliance concerns in a timely and effective manner. The fact that such an assessment is carried out does not, in itself, imply that the data controller has committed a violation; rather, it reflects the Authority’s obligation to verify compliance where risks have been identified. Data controllers should therefore ensure that they are in a state of readiness at all times to facilitate such inspections. Procedure:
3.4. Self-Assessment by Data Controllers
In addition to compliance assessments conducted by the Authority, a Data Controller may undertake a self-assessment to evaluate its own level of compliance with the Cyber and Data Protection Act and any subsidiary regulations or guidelines. The self-assessment shall be carried out using an approved self- assessment tool or online link provided by the Authority. This tool is designed to enable Data Controllers to identify compliance gaps, evaluate internal data protection controls, and measure progress in implementing the Act’s requirements. Alternatively, a Data Controller may engage the services of a Certified Data Protection Officer (DPO) or a data protection consultancy that is duly registered and authorised by the Authority to conduct compliance assessments on its behalf. Such engagements shall be voluntary and undertaken in accordance with the standards and methodologies prescribed by the Authority. Upon completion of the self-assessment, the Data Controller shall prepare a Self-Assessment Report summarising the findings, identified gaps, and corrective measures to be implemented. This report shall be submitted to the Authority for verification and record-keeping. The Authority may, where necessary, conduct a follow-up review or verification assessment to confirm the accuracy of the self-assessment and
‘creating a level playing field’
the adequacy of remedial measures taken. The purpose of this provision is to promote a culture of accountability and continuous improvement among Data Controllers.
Data Protection Authority Implementation Guidelines on the
Page 8
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
These four categories of assessments, voluntary, routine planned, ad hoc and self-assessments, collectively provide the Authority with a comprehensive toolkit for monitoring compliance. They balance encouragement of proactive cooperation by data controllers with the need for regulatory vigilance to safeguard the rights of data subjects and uphold the principles of lawfulness, fairness, transparency and accountability in data processing.
4. ASSESSMENT METHODS
In fulfilling its compliance monitoring mandate, the Authority applies a range of assessment methods designed to ensure flexibility, proportionality, and effectiveness. The choice of method will depend on the nature of the assessment, the data controller’s risk profile, and the circumstances giving rise to the review. The principal techniques are outlined below.
4.1. Onsite Assessment
An on-site assessment involves the Authority’s officials visiting the data controller’s premises to evaluate compliance with the Cyber and Data Protection Act directly. This method allows the Authority to observe processing operations in their actual environment, conduct face-to-face interviews with staff, and review relevant documents and systems. During an on-site assessment, the Authority may also conduct inspections of physical and digital security measures and observe how data-handling practices align with stated policies. Where necessary, the Authority may record proceedings or take photographs as evidence, strictly for official use in preparing the compliance assessment report. This approach provides a comprehensive and holistic view of the data controller’s operations.
4.2. Offsite Assessment
An off-site assessment is conducted at the Authority’s offices, where the data controller is invited to attend for a compliance review. The Authority will specify the required documentation and records to be submitted in advance or presented on the day of the assessment. The data controller may bring along relevant personnel who can demonstrate compliance, answer questions, and provide clarifications. Although the assessment occurs at the Authority’s premises, the Authority retains the discretion to conduct an on-site evaluation if deemed necessary to validate claims or verify operational practices. Attendance at the Authority’s offices for such assessment is mandatory for the data controller upon formal request.
4.3. Virtual Assessment
A virtual assessment is conducted remotely via digital communication tools, including telephone calls, video conferencing platforms (such as Zoom or Microsoft Teams), or email. This method is particularly suitable for preliminary compliance checks, follow-up assessments, or targeted reviews where a physical presence is not immediately required.
‘creating a level playing field’
Data controllers may be required to submit documentation electronically before the assessment. As with off-site assessments, the Authority reserves the right to conduct a subsequent on-site assessment where additional verification is necessary. Virtual assessments ensure efficiency and accessibility, primarily where geographical or logistical constraints exist.
Data Protection Authority Implementation Guidelines on the
Page 9
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
5. GENERAL ASSESSMENT PROCEDURE
While the specific sequence of activities may vary depending on the type of assessment, the Authority applies a structured and transparent process to ensure fairness and consistency. The general procedure is as follows:
‘creating a level playing field’
include a risk assessment highlighting risks to personal data and prioritising corrective actions based on their potential impact and likelihood of occurrence. Finally, where follow-up assessments are conducted, the Authority will issue a supplementary section or report to confirm whether the identified gaps have been addressed and closed to the Authority’s satisfaction.
Data Protection Authority Implementation Guidelines on the
Page 10
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
CONCLUSION
These guidelines provide a clear, transparent framework for conducting compliance assessments under the Cyber and Data Protection Act (CDPA). By outlining the types of assessments, methods, procedures, and reporting requirements, the Authority seeks to ensure consistency, fairness, and accountability in its oversight role. The ultimate objective is not only to enforce compliance but also to support data controllers in building robust governance structures, strengthening organisational practices, and safeguarding the personal information of data subjects. Through voluntary, routine, and ad hoc assessments, the Authority balances proactive engagement with regulatory vigilance, thereby fostering a culture of continuous improvement in data protection practices across all sectors. The assessment process, combined with transparent reporting and follow-up mechanisms, is intended to promote trust, transparency, and accountability in Zimbabwe’s digital ecosystem. In this way, the Authority reaffirms its commitment to protecting the rights and freedoms of individuals while enabling responsible innovation and growth in the digital economy. For further guidance on licensing requirements and process, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48 .
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 11
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Annexure A: Data Protection Compliance Assessment
Checklist Name of Data Controller: _____________________________________________ Sector: ______________________________________________________________ Date of Assessment: _________________________________________________ Type of Assessment: Voluntary ☐ Routine ☐ Ad Hoc ☐ Method: Onsite ☐ Offsite ☐ Virtual ☐ Assessor(s): _________________________________________________________ A. Governance & Accountability Requirement Yes/No Evidence/Remarks Has the organisation appointed a qualified Data Protection Officer
(DPO)?
Is the organisation registered and licensed by the Authority? Are data protection roles and re- sponsibilities clearly defined and documented? Is there an approved Data Protec- tion Policy? Is there evidence of senior man- agement commitment to the pro- tection compliance? Lawful Basis for Processing Requirement Yes/No Evidence/Remarks Has the organisation identified a lawful basis for each category of processing? Is consent obtained where re- quired, and is it specific, informed,
‘creating a level playing field’
and freely given? Is there a system to record and manage consents?
Data Protection Authority Implementation Guidelines on the
Page 12
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Is data processing limited to the stated purposes? Are Data Processing Agreements in place with third parties? B. Data Subject Rights Requirement Yes/No Evidence/Remarks Are there documented procedures for handling data subject rights requests (access, rectification, deletion, objection, etc.)? Are requests responded to within 30 Days? Is there a record of all rights requests received and actions taken? C. Data Security & Breach Management Requirement Yes/No Evidence/Remarks Are appropriate technical and or- ganisational security measures in place? Is there an incident response and breach notification procedure? Have staff been trained on breach reporting obligations? Are breaches reported to the DPA and affected individuals in line with CDPA requirements? D. Cross-Border Data Transfers Requirement Yes/No Evidence/Remarks Are cross-border transfers conducted only with the prior Authority’s authorisation were required? Are adequate safeguards (e.g., Standard Contractual Clauses, ‘cIDTrAse) in palace?ting a level playing field’ Are data subjects informed of cross-border transfers?
Data Protection Authority Implementation Guidelines on the
Page 13
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
E. Data Minimisation & Retention Requirement Yes/No Evidence/Remarks Is only the minimum necessary data collected for each purpose? Are retention periods defined and documented? Is there a process for the secure disposal of personal data? F. Training & Awareness Requirement Yes/No Evidence/Remarks Have staff received initial and refresher data protection training? Is there evidence of training completion records? Is data protection awareness included in induction programmes? G. Risk Management & DPIAs Requirement Yes/No Evidence/Remarks Are Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities? Are DPIAs reviewed and updated when necessary? Are risks to personal data identified, assessed, and mitigated? H. Findings Summary Compliance Area Status (Compliant / Partial / Non- Priority (High / Medium / Compliant) Low) Governance & Accountability
‘creating a level playing field’
Lawful Basis for Processing Data Subject Rights Data Security & Breach Management
Data Protection Authority Implementation Guidelines on the
Page 14
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Cross-Border Data Transfers Data Minimisation & Retention Training & Awareness Risk Management & DPIAs Recommendations (To be completed in a separate Report) Assessor(s) Name & Signature: ___________________________ Date: __________________________ Data Protection Compliance Assessment Scoring Checklist Scoring Method Yes = 2 points Partial = 1 point No = 0 points Not Applicable (N/A) = Excluded from scoring Compliance Percentage Formula:
1. Governance & Accountability (Max 10 points)
Requirement Score (0–2) Evidence/Remarks
1.1 Appointment of qualified DPO
1.2 DPO registered with DPA (if applicable)
1.3 Clear roles & responsibilities documented
1.4 Approved Data Protection Policy in place
1.5 Senior management commitment evidenced
2. Lawful Basis for Processing (Max 10 points)
Requirement Score (0–2) Evidence/Remarks
2.1 Lawful basis identified for all processing
2.2 Consent obtained where required
2.3 Consent records maintained
2.4 Processing limited to stated purposes
2.5 Valid Data Processing Agreements in place
3. Data Subject Rights (Max 6 points)
‘creating a level playing field’
Requirement Score (0–2) Evidence/Remarks
3.1 Procedures for handling rights requests
3.2 Requests responded to within timelines
POTRAZ is the Postal and Telecommunications Regulatory Authority of Zimbabwe. Zimbabwe’s Cyber and Data Protection Act designates it as the Data Protection Authority, giving it functions related to regulating personal-data processing, guidance, complaints, investigations and enforcement. This article describes its data-protection role; it does not suggest that POTRAZ is the regulator for other jurisdictions.
A privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.
The Cyber and Data Protection Act [Chapter 12:07] is Zimbabwe’s primary data-protection statute. It establishes core rules for processing personal information, identifies POTRAZ as the Data Protection Authority and addresses security, individual rights, controller and processor duties, cross-border transfers and offences. Regulations and POTRAZ guidance add important operational detail.