Skip to content

Research · authority data, public-interest

← Back to Legal library

CDPG 3 of 2025 — Conducting a DPIA

CDPG-3-2025 · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

CDPG-3-of-2025-Conducting-a-DPIA.pdf

application/pdf · 3.2 MB

Sanitised text

CDPG 3 of 2025 — Conducting a Data Protection Impact Assessment (DPIA) — Verbatim Transcription

Citation key: CDPG-3-2025 · Category: Implementation Guideline · Pages: 8

Source PDF: CDPA Implementation Guidelines/CDPG 3 of 2025 - Conducting a (DPIA).pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 8

Data Protection Authority Implementation Guidelines on the

Page 23

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on how to conduct a Data Protection Impact Assesment (DPIA) CDPG 3 of 2025

‘creating a level playing field’

Page 2 of 8

Data Protection Authority Implementation Guidelines on the

Page 24

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on How to Conduct a Data Protection Impact Assessment (DPIA)

1. Purpose And Effective Date

These guidelines are issued in accordance with section 18 of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA”). The CDPA mandates the Authority to produce guidelines to facilitate and promote the fair processing of personal data in Zimbabwe. These guidelines seek to assist data controllers in conducting Data Protection Impact Assessments (DPIAs to promote compliance with the law and to promote responsible data governance. The Guidelines shall take effect on the date of publication.

2. INTERPRETATION

In these Guidelines, the following shall mean: “CDPA” refers to the Cyber and Data Protection Act [Chapter 12:07] “Data Protection Authority (DPA) or “the Authority” refers to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as such in terms of section 5 of the Cyber and Data Protection Act. “DPIA” refers to a Data Protection Impact Assessment “Data Controller” refers to any natural person or legal person who is licensable by the Authority, including public bodies and any other person who determines the purpose and means of processing personal data. “Data protection officer” or “DPO” refers to any individual appointed by the data controller and who is charged with ensuring, in an independent manner, compliance with the obligations provided for in the CDPA. “Personal information” means information relating to a data subject which can be used to identify an individual. “Processing” refers to any operation or set of operations which are performed upon data, whether or not by automatic means, such as obtaining, recording or holding the data or carrying out any operation or set of operations on data. “Data Subject” means an identified or identifiable natural person who is the subject of data. “Sensitive data” refers to information or any opinion about an individual which reveals or contains, racial or ethnic origin; political opinions; membership of a political association; religious beliefs or

‘creating a level playing field’

affiliations; philosophical beliefs; membership of a professional or trade association; membership of a trade union; sex life; criminal, educational, financial or employment history; gender, age, marital status or family status.

Page 3 of 8

Data Protection Authority Implementation Guidelines on the

Page 25

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

“Transborder flow” refers to international flows of data by means of transmission, including data transmission electronically or by satellite. “Risk” refers to the likelihood and impact of harm that may result from the processing of personal data. “Risk assessment” refers to identifying, assessing, and mitigating potential risks associated with certain processing activities.

These guidelines are grounded in:

1.Section 18 (2) of the Cyber and Data Protection Act [Chapter 12:07] (CDPA) which requires data controller to into account measures that balance the need for processing data and the need to mitigate the risks to the rights of the data subjects.
2.Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 They can be read with the following:

3. Implementation Guidelines Implementation Guideline on Cross-Border Transfer of Personal

Information (CDPG 5 of 2024)

5.Cyber and Data Protection Implementations Guidelines on Appointment, Roles, Responsibilities, Training and Certification of Data Protection Officers (CDPG1 of 2024).

6. Cyber and Data Protection Implementations Guidelines on Processing of Children’s Personal

Information (CDPG 2 of 2024).

4. INTRODUCTION

A DPIA is a systematic process employed to identify, assess and mitigate the privacy risks associated with a specific data processing activity. It serves as a significant tool in demonstrating compliance with the CDPA, and it promotes the safeguarding of data subjects’ privacy rights and freedoms outlined in terms of sections 14,11, and 25 of the CDPA.

5. IMPORTANCE OF CONDUCTING A DPIA

5.1.DPIAs are an essential part of a data controller’s accountability obligations.
5.2.Conducting a DPIA is a legal requirement in terms of section 18 of the CDPA; as a DPIA is a form of organisational measure that seeks to identify risks for specified types of processing that are likely to adversely impact the rights and freedoms of individuals.

5.3. DPIAs play a key role in raising awareness about privacy and data protection within an

organisation. ‘cr5e.4. aBeytonid nmeetging le gaal req uirlemeentsv in teerms lof thpe Aclt, aDPIAys offeir nbroagder c omfpliianece ld’ advantages by helping data controllers to evaluate and demonstrate adherence to data protection principles and responsibilities.

5.5. DPIAs are more than just a regulatory formality because when done effectively, they help

identify and resolve potential risks to data privacy early, benefiting both individuals and the

Page 4 of 8

Data Protection Authority Implementation Guidelines on the

Page 26

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

organisations.

5.6. Conducting a DPIA can also reassure data subjects that their data is being handled

responsibly and that any risks to them have been minimised.

5.7. Conducting DPIAs can help a data controller to embed privacy by design and default at the

beginning of high-risk processing activities.

6. PURPOSE OF A DPIA

6.1. As emphasised above, DPIA is an important tool to demonstrate compliance with the law

in line with the principle of accountability enshrined in section 24 of the CDPA; however, it should not be viewed as a one-time exercise.

6.2.It should be a ‘living’ document that helps a data controller to manage and review the risks of a processing activity, and the effectiveness of measures put in place to mitigate the identified risks on an ongoing basis throughout the lifecycle of the processing activity.

7. INSTANCES WHEN A DPIA SHOULD BE CONDUCTED

7.1.A DPIA is a mandatory requirement where a type of processing activity is, after taking into account the nature, scope, context and purposes of the processing, likely to result in a high risk to the rights and freedoms of data subjects.
7.2.It is part of the mandatory requirement in terms of section 18 of the CDPA.
7.3.A DPIA is mandatory when:
Processing involves sensitive personal data as defined in sections 11 and 12 of the Act
Processing involves cross-border transfer of personal data in terms of sections 28 and
29.of the CDPA.
The transborder notification of processing of data to the Authority must be accompanied by a DPIA.
There is large-scale profiling or automated decision-making
Surveillance or monitoring of public spaces occurs
Data subjects include vulnerable groups (e.g., children, the elderly)
New technologies are deployed in a business (e.g., Biometrics, AI, IoT)
When the Authority calls upon a data controller to conduct a DPIA

8. PRACTICAL STEPS TO FOLLOW WHEN CONDUCTING A DPIA

Step 1: Identify the need for a DPIA The first step is to determine if a DPIA is necessary. Use a screening checklist as provided in section 7 of these Guidelines. Step 2: Describe the processing Provide a clear description of the data processing activities, including but not limited to;

‘creating a level playing field’

Types of personal data being processed,
Lawful basis for processing
Purpose of processing
Data sources and data recipients,
Page 5 of 8

Data Protection Authority Implementation Guidelines on the

Page 27

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Data Sharing protocols and involvement of third parties
Data retention and deletion schedules specify how long the data will be kept and when it will be deleted. Step 3: Consultation Consult internal and external stakeholders, ie DPO, project owners, managers, industry experts, IT professionals, legal advisors, user departments, data processors, and data subjects. Consult and seek expert guidance from the DPA where necessary. Define roles and responsibilities. Step 4: Assess necessity and proportionality Evaluate whether there are other alternative ways to achieve the same goal with less data or lower risks. Assess compliance with data protection principles as enshrined in the CDPA. Step 5: identify and assess risks Identify risks, risk level vis-à-vis a vee nature of processing and the level of sensitivity of the data as provided herein in section 9. The use of risk assessment tools such as specialised software to generate standardised reports is encouraged. Step 6: Identify measures to mitigate risks After identifying risks, set up measures to mitigate them. Implement technical and organisational measures to secure the security and confidentiality of data. Step 7: Sign off and record outcomes Maintain all documentation Submit the DPIA to the Authority if it’s necessary in terms of the law Map a strategy for the implementation of identified outcomes

9. WAYS OF ASSESSING RISKS IN DATA PROCESSING ACTIVITIES WHEN CONDUCTING A

DPIA

9.1. Mapping of the Data Flow

9.1.1. The data controller can assess risks in processing activities by doing a data inventory

focusing primarily on;

Type of personal data involved
Amount and range of data handled
Level of sensitivity
the extent and frequency of processing

‘creating a level playing field’

the duration of processing
the geographical area covered

9.1.2. Risks can be classified into three categories, ie, Low, medium and high and risk

Page 6 of 8

Data Protection Authority Implementation Guidelines on the

Page 28

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

classification is important as it guides the data controller on the implementation of appropriate organisational and technical measures to employ on different sets of processing activities.

9.1.3.It is important to map out the data accurately, setting out data collection, processing, and storage to reveal any weak points or vulnerabilities.

9.2. Scope of impact

9.2.1. The Data controller should ensure that a comprehensive assessment of the potential

impact on the rights and freedoms of individuals is conducted.

9.2.2. This assessment must be in light of the harm or damage a certain processing activity

may cause, whether physical, emotional or material. In particular, the assessment can primarily focus on whether the processing could contribute to;

inability of data subjects to exercise their rights
inability of individuals to access services or opportunities;
loss of control or autonomy by data subjects over the use of their personal data;
discrimination;
identity theft or fraud;
financial loss;
reputational damage;
physical harm;
loss of confidentiality;
re-identification of pseudonymised data; or
any other significant economic or social disadvantage.
9.3.Data controllers can also assess risks considering their standing in society as a corporate institution, for example, the impact of regulatory action by the DPA on their operations, reputation, and public trust.

10. EXAMPLES OF HIGH-RISK PROCESSING ACTIVITIES

High-risk processing activities include the following:

10.1. When processing involves the use of automated systems, innovative technologies, or the

novel application of existing technologies (including AI).

10.2. When decisions about an individual’s access to a product, service, opportunity or benefit

are based on automated decision-making.

10.3.When processing involves any profiling of individuals on a large scale.
10.4.When processing involves health, biometric and genetic data or any of the sensitive data in terms of section 3 of the CDPA.

10.5. When personal data, obtained from multiple sources, is combined, compared or matched

in one processing activity. ‘cre10.6.a Wtheinn procgessin g oaf per solnael datav hase not ble enp obtalinead diryectlyi frnom thge da ta fsubijeect inl d’ circumstances in terms of section 16 of the CDPA.

10.7.When processing involves tracking an individual’s geolocation or behaviour.
10.8.When processing involves children’s information or any other vulnerable data subjects.

10.9. Where the processing is of such a nature that a personal data breach could jeopardise the

Page 7 of 8

Data Protection Authority Implementation Guidelines on the

Page 29

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

health or safety of individuals.

11. ROLE OF A DATA PROTECTION OFFICER (DPOs) IN CONDUCTING A DPIA

11.1. The DPO plays a pivotal role in assisting the Data Controller in conducting a DPIA

11.2.The DPO does not conduct the DPIA. The Data Controller must conduct the DPIA.

11.3. In conducting a DPIA, the DPO’s role is advisory and they

a. Guide the process by identifying the need for a DPIA. b. Assisting in the documentation of the DPIA process. c. Assisting in risk assessment to identify the risks inherent in data processing d. Advising on risk mitigation measures e. Monitor the adherence and compliance to the outcomes, findings and the DPIA to ensure that there is implementation of all technical and organisational measures as rolled out or planned.

12. DPIA CHECKLIST/CONTENT REQUIREMENTS

A comprehensive DPIA is expected to provide adequate information on the following:

-Overview: Title and description of the processing activity, objectives and expected outcomes.
-Data Inventory: Categories of data collected and data flow diagram (collection, storage, sharing, disposal).
-Data Subjects: a list and category of data subjects whose personal information will be processed.
-Establishment of a legal basis: Consent, contractual obligation, legal obligation, public interest, vital interest of data subject, legitimate interest.
-Evidence and results of consultation: Engagement with internal and external stakeholders, data subjects, designation of roles and responsibilities/ ownership of processing activity.
-Adequacy assessment: in terms of section 28 of the Act, in cases of cross-border transfer of data
-Risk Assessment: Identification of risks and their likelihood to adversely affect data subjects, classification of identified risks, for example, (high/medium and low), and likelihood and severity of harm.
-Mitigation Measures: Technical and organisational safeguards implemented,
-Necessary Approvals: Sign-off by Data Protection Officer (DPO), Authorised representatives of the Controller, date and version control and submission to the DPA for assessment/ approval if the DPIA is an annexure to a notification required in terms of section 20 of the Act.

12.1. A DPIA submitted to the Authority, accompanying a specific notification arising from an

obligation in terms of the Act, should be accompanied by an annexure of source documents which serve as a demonstration of proof and the accuracy of the DPIA. ‘cr1e2.2. aExatmpilens of tghese doacum enlts emay ivncluede: l playing field’

Adequacy assessment demonstrating data residency in cross-border processing of data
Data processing/ sharing agreements with data processors
Consent forms when processing sensitive data.
Page 8 of 8

Data Protection Authority Implementation Guidelines on the

Page 30

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

12.3. Before submission of a DPIA to the Authority, the data controller must ensure that it

encompasses all the information provided above.

13.1. Stakeholder Engagement

-When conducting a DPIA, it is important to use accurate and timely information from all relevant stakeholders; therefore, all relevant stakeholders in an organisation should be involved.
-As emphasised, the DPO’s advice is very crucial in determining whether a certain processing activity needs a prior conducting of a DPIA, and how to conduct the same.
-Relevant project team and relevant departments should work in consultation with the DPO.
-A wide internal consultation can uncover data protection risks that might only be apparent to individuals working on specific aspects of the project.
-It is also important to consult the DPA, if necessary, to seek additional expert advice and guidance.
-This might include bringing in external specialists if our organisation lacks sufficient expertise or if a project holds a very high level of risk. We should also think about how to consult individuals or their representatives, perhaps through focus groups or surveys.

13.2. Documentation and Record Keeping

-Record keeping is essential for demonstrating compliance with the DPA; therefore, data controllers are encouraged to keep detailed and updated records of the DPIA process.
-The exercise can also be a key identifier of gaps which can be used to monitor the level of compliance for an organisation, in the same vein, fostering review and improvements.

13.3. Continuous Review

-A DPIA is not a one-time exercise; it is an ongoing process that needs to be integrated into the data controller’s organisational processes.
-The tool assists controllers in staying on top of changing risks and ensuring that data protection measures remain effective.
-A strategic review of the DPIA in a processing activity enables effective monitoring of the
-Data controllers are encouraged to set review schedules to keep track of any actions that result from the same.
-A DPIA should be conducted when there is a modification to the processing of personal data. The modification should be notified to the Authority, outlining the nature, scope, context, or purposes of processing/ modification.

14. PENALTIES AND FINES FOR NON-COMPLIANCE

Failure to conduct a DPIA when required may result in;

a)Fines up to level 11,
b)Imprisonment up to 7 years ‘crec) aAn ortdeir tno stogp the praocess inlg eof pevrsonael datla- (Cpancelllaation oyf Daitan Protegction Lifceinsee.) ld’ For compliance and further guidance, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) on regulator@potraz.zw or call +263 242 333032/48
Referenced by Privacy Hub
Processing personal data

Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.