CDPG 4 of 2025 — Cross Border Data Transfers
CDPG-4-2025 · v1 · release faf85cbc
CDPG 4 of 2025 — Cross-Border Data Transfers — Verbatim Transcription
Citation key: CDPG-4-2025 · Category: Implementation Guideline · Pages: 5
Source PDF: CDPA Implementation Guidelines/CDPG 4 of 2025 -Cross-Border Data Transfers.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 31
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Adequate Level Of Protection Under Cross-Border Data Transfers CDPG 4 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 32
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on Adequate Level of Protection Under Cross-Border Data Transfers
1. PURPOSE
These guidelines are issued in terms of Section 6(1) (a) as read with 28 (2) of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA”), which provides that the Authority shall lay down the conditions and circumstances for cross-border transfer of personal information. They are designed to ensure that cross-border transfers of personal data from Zimbabwe are conducted in a manner that guarantees an adequate protection level to data subjects’ personal data, in line with the Cyber and Data Protection Act,, its Regulations, as well as international best practices.
2. INTRODUCTION
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is the designated Data Protection Authority. According to Section 28, POTRAZ is responsible for specifying the categories of data that can be transferred outside Zimbabwe and the conditions under which they can be transferred. The reason for restrictions under cross-border transfer provisions in sections
3. DEFINITION OF TERMS
a. Act: Refers to the Cyber and Data Protection Act [Chapter 12:07] (CDPA) of Zimbabwe or any relevant legislation governing data protection. b. Data Controller: A person or entity that determines the purpose and means of processing personal data. c. Data Processor: A person or entity that processes personal data on behalf of the data controller. d. Personal Data: Any information relating to an identified or identifiable individual e. Processing: Any operation performed on personal data, such as collection, storage, use, deletion, and transfer. f. Sensitive Personal Data: Sensitive Information: refers to personal data that includes biometric data, racial or ethnic origin, political opinions, membership of a political association, and any information that may be considered to present a major risk to the rights of the data subject. g. Cross-border transfer: refers to the movement of personal data from Zimbabwe to another country’s geographical, technological, and legal borders
4. REQUIREMENTS FOR TRANSFER
‘creating a level playing field’
Data controllers are prohibited from transferring the personal information of data subjects to a third party outside Zimbabwe to a country that does not ensure an adequate level of protection. The data controller must first notify the Authority of their intention to transfer data and must then meet the following conditions before they receive the authorisation to transfer data from Zimbabwe:
Data Protection Authority Implementation Guidelines on the
Page 33
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
4.1 General Principle
No personal data shall be transferred outside Zimbabwe unless the destination country ensures an adequate level of protection for the data subject’s rights and freedoms.
4.2 Assessment of Adequacy
Data controllers must assess the adequacy of protection in the destination country based on: a. Legal Framework: Existence of data protection laws, independent supervisory authority, and enforcement mechanisms b. Data Subject Rights: Right to access, rectify, erase, and object; remedies for violations c. Security Measures: Technical and organisational safeguards; breach notification protocols d. International Commitments: Participation in international data protection agreements (e.g., Malabo Convention on Cyber and Data Protection)
4.3 Transfer Mechanisms
If adequacy is not established, data controllers must use alternative safeguards, such as: a. Standard Contractual Clauses (SCCs) b. Binding Corporate Rules (BCRs) c. Explicit Consent from the data subject d. Approved Codes of Conduct or Certification Mechanisms
4.4 Documentation & Notification
Data controllers must: a. Maintain records of cross-border transfers b. Notify the Data Protection Authority (DPA) before initiating transfers c. Submit Data Transfer Impact Assessments (DTIA)
4.5 Compliance Assessment
As per SI 155 of 2024 and the Act, Data Controllers must: a. Be licensed by the Authority. b. Appoint a Data Protection Officer (DPO) and notify the Authority. c. Report data breaches within 24 hours. d. Notify the Authority of the intention to transfer personal data outside of Zimbabwe. e. Maintain a record of processing activities (ROPA).
4.6 Technical and Organisational Safeguards
To ensure an adequate level of protection during cross-border data transfers, organisations must
‘creating a level playing field’
implement robust technical and organisational measures designed to safeguard personal data against unauthorised access, loss, or misuse. These measures should include, but are not limited to, the following:
Data Protection Authority Implementation Guidelines on the
Page 34
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
a. Encryption Implement robust end-to-end encryption to protect personal data both during transmission and while at rest. This ensures that data remains confidential and secure, even if intercepted or accessed without authorisation. b. Data Minimisation Limit the collection and transfer of personal data to only what is strictly necessary for the intended purpose (data minimisation). Apply pseudonymisation to reduce the risk of re-identification, especially when transmitting sensitive or high-risk data across borders. c. Access Control Mechanisms Enforce strict access control mechanisms, including role-based access and multi-factor authentication (MFA), to ensure that only authorised personnel can access or process personal data. Access rights should be regularly reviewed and updated. d. Monitoring logs Maintain comprehensive monitoring systems and audit logs for all cross-border data transfers. Logs should capture when, where, and how personal data is transferred, along with details of the data recipient. This supports accountability, traceability, and incident investigation. e. Incident response plan Establish and maintain a security incident response plan that includes timely detection, reporting, containment, and remediation of data breaches. In the event of a breach involving cross-border data, notify the appropriate supervisory authority and affected data subjects in accordance with applicable legal and regulatory requirements. f. Sensitive Information The Authority will not permit the migration or hosting of highly sensitive information, such as core banking platforms and critical financial systems, outside the borders of Zimbabwe. All such systems must be hosted locally, and any exceptions will require prior written approval from the Authority, supported by a detailed risk assessment and justification. g. Security Audits Regular audits and penetration testing are essential components of a robust data protection framework, particularly where cross-border data transfers are involved. Audits help assess compliance with legal, regulatory, and contractual obligations, ensuring that data protection controls such as encryption, access management, and third-party agreements are effectively implemented and maintained. h. For cross-border data transfers, penetration testing conducted periodically will enhance the organisation’s capability to identify and mitigate security vulnerabilities, thereby preventing potential breaches. This proactive approach not only demonstrates accountability but also helps ensure the ongoing integrity and confidentiality of personal data as it moves across international boundaries.
4.7 Security Standards
‘creating a level playing field’
In addition, the data controller should ensure that third-party recipients adopt the following standards: a. ISO/IEC 27001 for information security
Data Protection Authority Implementation Guidelines on the
Page 35
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
b. NIST SP 800-61 – Computer Security Incident Handling Guide c. ISO/IEC 27036 – Information Security for Supplier Relationships
4.8 Penalties or Fines for Non-Compliance
A data controller who shall not guarantee the above required minimum adequate level of protection shall attract the following fines or penalties: a. Fines up to level 11 b. Imprisonment up to 7 years c. Revocation of data controller license For complaints and further guidance, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/46/48.
‘creating a level playing field’
A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.