CDPG 3 of 2025 — Conducting a DPIA
CDPG-3-2025 · v1 · release faf85cbc
CDPG 3 of 2025 — Conducting a Data Protection Impact Assessment (DPIA) — Verbatim Transcription
Citation key: CDPG-3-2025 · Category: Implementation Guideline · Pages: 8
Source PDF: CDPA Implementation Guidelines/CDPG 3 of 2025 - Conducting a (DPIA).pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 23
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on how to conduct a Data Protection Impact Assesment (DPIA) CDPG 3 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 24
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on How to Conduct a Data Protection Impact Assessment (DPIA)
1. Purpose And Effective Date
These guidelines are issued in accordance with section 18 of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA”). The CDPA mandates the Authority to produce guidelines to facilitate and promote the fair processing of personal data in Zimbabwe. These guidelines seek to assist data controllers in conducting Data Protection Impact Assessments (DPIAs to promote compliance with the law and to promote responsible data governance. The Guidelines shall take effect on the date of publication.
2. INTERPRETATION
In these Guidelines, the following shall mean: “CDPA” refers to the Cyber and Data Protection Act [Chapter 12:07] “Data Protection Authority (DPA) or “the Authority” refers to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as such in terms of section 5 of the Cyber and Data Protection Act. “DPIA” refers to a Data Protection Impact Assessment “Data Controller” refers to any natural person or legal person who is licensable by the Authority, including public bodies and any other person who determines the purpose and means of processing personal data. “Data protection officer” or “DPO” refers to any individual appointed by the data controller and who is charged with ensuring, in an independent manner, compliance with the obligations provided for in the CDPA. “Personal information” means information relating to a data subject which can be used to identify an individual. “Processing” refers to any operation or set of operations which are performed upon data, whether or not by automatic means, such as obtaining, recording or holding the data or carrying out any operation or set of operations on data. “Data Subject” means an identified or identifiable natural person who is the subject of data. “Sensitive data” refers to information or any opinion about an individual which reveals or contains, racial or ethnic origin; political opinions; membership of a political association; religious beliefs or
‘creating a level playing field’
affiliations; philosophical beliefs; membership of a professional or trade association; membership of a trade union; sex life; criminal, educational, financial or employment history; gender, age, marital status or family status.
Data Protection Authority Implementation Guidelines on the
Page 25
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
“Transborder flow” refers to international flows of data by means of transmission, including data transmission electronically or by satellite. “Risk” refers to the likelihood and impact of harm that may result from the processing of personal data. “Risk assessment” refers to identifying, assessing, and mitigating potential risks associated with certain processing activities.
3. LEGAL FRAMEWORK
These guidelines are grounded in:
3. Implementation Guidelines Implementation Guideline on Cross-Border Transfer of Personal
Information (CDPG 5 of 2024)
4. Implementation guideline Implementation Guideline on the Right to Consent (CDPG 4 of 2024)
6. Cyber and Data Protection Implementations Guidelines on Processing of Children’s Personal
Information (CDPG 2 of 2024).
4. INTRODUCTION
A DPIA is a systematic process employed to identify, assess and mitigate the privacy risks associated with a specific data processing activity. It serves as a significant tool in demonstrating compliance with the CDPA, and it promotes the safeguarding of data subjects’ privacy rights and freedoms outlined in terms of sections 14,11, and 25 of the CDPA.
5. IMPORTANCE OF CONDUCTING A DPIA
5.3. DPIAs play a key role in raising awareness about privacy and data protection within an
organisation. ‘cr5e.4. aBeytonid nmeetging le gaal req uirlemeentsv in teerms lof thpe Aclt, aDPIAys offeir nbroagder c omfpliianece ld’ advantages by helping data controllers to evaluate and demonstrate adherence to data protection principles and responsibilities.
5.5. DPIAs are more than just a regulatory formality because when done effectively, they help
identify and resolve potential risks to data privacy early, benefiting both individuals and the
Data Protection Authority Implementation Guidelines on the
Page 26
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
organisations.
5.6. Conducting a DPIA can also reassure data subjects that their data is being handled
responsibly and that any risks to them have been minimised.
5.7. Conducting DPIAs can help a data controller to embed privacy by design and default at the
beginning of high-risk processing activities.
6. PURPOSE OF A DPIA
6.1. As emphasised above, DPIA is an important tool to demonstrate compliance with the law
in line with the principle of accountability enshrined in section 24 of the CDPA; however, it should not be viewed as a one-time exercise.
7. INSTANCES WHEN A DPIA SHOULD BE CONDUCTED
8. PRACTICAL STEPS TO FOLLOW WHEN CONDUCTING A DPIA
Step 1: Identify the need for a DPIA The first step is to determine if a DPIA is necessary. Use a screening checklist as provided in section 7 of these Guidelines. Step 2: Describe the processing Provide a clear description of the data processing activities, including but not limited to;
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 27
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
9. WAYS OF ASSESSING RISKS IN DATA PROCESSING ACTIVITIES WHEN CONDUCTING A
DPIA
9.1. Mapping of the Data Flow
9.1.1. The data controller can assess risks in processing activities by doing a data inventory
focusing primarily on;
‘creating a level playing field’
9.1.2. Risks can be classified into three categories, ie, Low, medium and high and risk
Data Protection Authority Implementation Guidelines on the
Page 28
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
classification is important as it guides the data controller on the implementation of appropriate organisational and technical measures to employ on different sets of processing activities.
9.2. Scope of impact
9.2.1. The Data controller should ensure that a comprehensive assessment of the potential
impact on the rights and freedoms of individuals is conducted.
9.2.2. This assessment must be in light of the harm or damage a certain processing activity
may cause, whether physical, emotional or material. In particular, the assessment can primarily focus on whether the processing could contribute to;
10. EXAMPLES OF HIGH-RISK PROCESSING ACTIVITIES
High-risk processing activities include the following:
10.1. When processing involves the use of automated systems, innovative technologies, or the
novel application of existing technologies (including AI).
10.2. When decisions about an individual’s access to a product, service, opportunity or benefit
are based on automated decision-making.
10.5. When personal data, obtained from multiple sources, is combined, compared or matched
in one processing activity. ‘cre10.6.a Wtheinn procgessin g oaf per solnael datav hase not ble enp obtalinead diryectlyi frnom thge da ta fsubijeect inl d’ circumstances in terms of section 16 of the CDPA.
10.9. Where the processing is of such a nature that a personal data breach could jeopardise the
Data Protection Authority Implementation Guidelines on the
Page 29
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
health or safety of individuals.
11. ROLE OF A DATA PROTECTION OFFICER (DPOs) IN CONDUCTING A DPIA
11.1. The DPO plays a pivotal role in assisting the Data Controller in conducting a DPIA
11.3. In conducting a DPIA, the DPO’s role is advisory and they
a. Guide the process by identifying the need for a DPIA. b. Assisting in the documentation of the DPIA process. c. Assisting in risk assessment to identify the risks inherent in data processing d. Advising on risk mitigation measures e. Monitor the adherence and compliance to the outcomes, findings and the DPIA to ensure that there is implementation of all technical and organisational measures as rolled out or planned.
12. DPIA CHECKLIST/CONTENT REQUIREMENTS
A comprehensive DPIA is expected to provide adequate information on the following:
12.1. A DPIA submitted to the Authority, accompanying a specific notification arising from an
obligation in terms of the Act, should be accompanied by an annexure of source documents which serve as a demonstration of proof and the accuracy of the DPIA. ‘cr1e2.2. aExatmpilens of tghese doacum enlts emay ivncluede: l playing field’
Data Protection Authority Implementation Guidelines on the
Page 30
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
12.3. Before submission of a DPIA to the Authority, the data controller must ensure that it
encompasses all the information provided above.
13. RECOMMENDED BEST PRACTICES IN CONDUCTING A DPIA
13.1. Stakeholder Engagement
13.2. Documentation and Record Keeping
13.3. Continuous Review
14. PENALTIES AND FINES FOR NON-COMPLIANCE
Failure to conduct a DPIA when required may result in;
Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.