CDPG 4 of 2024 — The Right to Consent
CDPG-4-2024 · v1 · release faf85cbc
CDPG 4 of 2024 — The Right to Consent — Verbatim Transcription
Citation key: CDPG-4-2024 · Category: Implementation Guideline · Pages: 5
Source PDF: CDPA Implementation Guidelines/CDPG 4 of 2024 - The Right to Consent Guideline.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
'creating a level playing field'
CYBER AND DATA PROTECTION
IMPLEMENTATION GUIDELINE ON THE RIGHT
TO CONSENT
CDPG 4 OF 2024
1. PURPOSE AND EFFECTIVE DATE
The guideline is issued in terms of section sections 6(1) (a),10, 11, 12, 13, 14, 15, 25, 28 & 29 of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as "the CDPA") which provides that the Authority shall lay down the conditions and circumstances for consent when processing personal information. The guideline seeks to give general guidance to data controllers and data subjects on the requirements for consent prior to processing personal information. It shall be read in conjunction with the provisions of the CDPA and the regulations. The guideline is effective from the date of publication.
2. WHAT IS CONSENT?
Section 3 of the CDPA defines "Consent" as any specific clear, freely provided, informed
statement of will by which the data subject or his or her legal, judicial, or legally appointed representative accepts that his or her data be processed by a data controller.
3. WHY IS CONSENT IMPORTANT?
4. LEGAL REQUIREMENTS OF CONSENT
4.3. informed, this means, the data subject must be adequately informed on the reasons for
processing, including further processing and their rights.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON THE RIGHT TO CONSENT
5. TYPES OF PROCESSING THAT REQUIRE CONSENT
A data controller must obtain consent from data subjects before processing the following types of data:
5.1. Processing of non-sensitive data (CDPA Section 10)
Personal information may only be processed if the data subject or a competent person, where the data subject is a child, consents to the processing of such data. The consent referred to above may be implied where the data subject is an adult natural person and has full legal capacity to consent. The catch is for the data controller to prove that indeed verbal consent was given.
5.2. Processing of sensitive data (CDPA Section 11)
No data controller shall process sensitive data unless the data subject has given consent in writing for such processing. NB# The Authority shall determine, the circumstances in which the prohibition to process sensitive data cannot be lifted even with the data subject's consent (considering the factors surrounding the prohibition and the reasons for collecting the data).
5.4. Automatic Data Processing (CDPA Section 25)
If a data controller is desirous to use automated means of data processing and decision making, they must first obtain the express consent of the data subjects concerned. The data controller may process the data by automated means if the processing is necessary to comply with a legal provision requiring them to conduct such processing.
5.5. Processing of personal data of incapacitated data subjects (CDPA Section 27)
A data subject who is physically, mentally, or legally incapable of exercising the rights given under the COPA and who is not a child, may exercise such rights through a parent or guardian or as provided for by law or as designated by a Court of competent jurisdiction.
5.6. Transfer of personal information outside Zimbabwe (CDPA Section 29)
A data controller must obtain explicit consent from data subjects if they wish to transfer personal information to a country outside Zimbabwe which does not assure an adequate level of protection.
6. OBTAINING, RECORDING AND MANAGING CONSENT?
6.1. Data controllers must make consent requests prominent, concise, separate from other
terms and conditions, and easy to understand. The request for consent should include the 2
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON THE RIGHT TO CONSENT
following:
6.1.3. reasons for the data collection and processing; and
6.3. Data controllers must keep records of evidence of consent - who consented, when, how, and
what they consented to.
7. WITHDRAWAL OF CONSENT
7.1. The CDPA stipulates that data subjects have the right to withdraw their consent to the
processing of their personal data.
8. LEGAL BASES FOR PROCESSING PERSONAL DATA WITHOUT CONSENT
8.1. Contractual Obligations: Personal data may be processed when it is essential for the
performance of a contract to which the data subject is a party. For this to apply, the processing must be necessary for fulfilling the specific obligations of the contract for the benefit of the data subject. The contract must clearly outline the purpose for which the data will be used. Example: Processing payment information to fulfill an online purchase agreement.
8.2. Legal Obligations: Data processing is permissible when required to comply with a legal
obligation to which the controller is subject. This applies when processing is mandated by a specific law or regulation. Example: Retaining employee tax records to comply with tax laws.
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON THE RIGHT TO CONSENT
a. The necessity of the processing. b. That the controller’s interest outweighs the data subject’s rights. Example: Using customer data for sending them notifications in the change in operating times.
8.6. Scientific Research: Personal data can be processed by public bodies for purposes such
as scientific research, statistical analysis, or historical research, provided appropriate safeguards are in place to protect the data subject’s rights. Example: Anonymizing patient data for clinical trials.
9. PENALTIES
A data controller shall take all necessary measures to comply with the principles and obligations set out in the Act and must have the necessary internal mechanisms in place for demonstrating such compliance to both the data subjects and the Authority in the exercise of its powers. Any data controller, his or her representative, agent or assignee who contravenes sections 11, 13 and 28 in relation to the requirements for consent shall be guilty of an offence and liable to a fine not exceeding level 11 or to imprisonment for a period not exceeding seven years or to both such fine and imprisonment. For complaints and further guidance, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) on dataprotectionunit@dpa.zw; regulator@potraz.zw or call +263 242 333032/46/48.
ISSUED ON THIS 13th DAY OF NOVEMBER 2024.
POTRAZ DIRECTOR GENERAL
4
CYBER AND DATA PROTECTION IMPLEMENTATION GUIDELINE ON THE RIGHT TO CONSENT
A data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.
A privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.