CDPG 6 — Processing by Political Parties & Electoral Stakeholders
CDPG-6 · v1 · release faf85cbc
CDPG 6 — Processing by Political Parties and Electoral Stakeholders — Verbatim Transcription
Citation key: CDPG-6 · Category: Implementation Guideline · Pages: 8
Source PDF: CDPA Implementation Guidelines/CDPG 6 - Processing by Political Parties & Electoral Stakeholders.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 40
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines: Processing of Personal Data by Political Parties, Independent Candidates and Electoral Stakeholders CDPG 6 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 41
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines: Processing of Personal Data by Political Parties, Independent Candidate and Electoral Stakeholders
1. INTRODUCTION
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), as the designated Data Protection Authority under section 5 of the Cyber and Data Protection Act, [Chapter 12:07] (hereinafter referred to as “CDPA”) is mandated to regulate, promote, and enforce the fair processing of personal data by data controllers in Zimbabwe. The Authority therefore establishes these guidelines to ensure that political parties, their electoral candidates, independent candidates, and electoral stakeholders process personal data lawfully, transparently, and fairly, thereby protecting the rights of citizens and maintaining public trust during and after elections.
2. WHY THESE GUIDELINES?
The Election cycle is data-driven and involves the collection of personal data from voter registration, voter authentication, voting, and results transmission. Electoral candidates rely on data to inform their campaigns, and they determine where to hold rallies and which campaign messages to focus on in specific areas. Electoral processes rely heavily on the collection and use of personal data; therefore, electoral candidates must process personal data lawfully, transparently, and fairly in accordance with the CDPA and S.I 155 of 2024.
3. SCOPE AND PURPOSE
These guidelines are issued in terms of Section 11(3) of the CDPA, which provides that the Authority shall lay down the conditions and circumstances for processing certain categories of sensitive information. By interpretation, membership of a political party and political opinions are classified as sensitive information according to data protection laws in Zimbabwe. Section 20 of the Electoral Act [Chapter 2:13] provides that the voters’ roll shall specify, in relation to each registered voter, the voter’s first and last names, date of birth, national registration number, and sex; the place where the voter ordinarily resides; and any other information as may be prescribed or as the Commission considers appropriate. In light of the above, these guidelines provide practical advice to all stakeholders involved in electoral processes, including aspiring and elected Members of Parliament, Senators, and Councillors from political parties, as well as independent candidates. It outlines responsibilities, procedures, and safeguards to ensure lawful data processing by aspiring and elected Parliamentarians, Senators, and Councillorss during and after elections.
4. DEFINITIONS OF TERMS
a. Act: Refers to the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe.
‘creating a level playing field’
b. Canvassing: refers to the direct engagement with voters by political parties, candidates, or campaign teams to influence voting behaviour, gather support, and promote political messages. It includes activities such as:
Data Protection Authority Implementation Guidelines on the
Page 42
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
i. Door-to-door visits, where canvassers speak with voters, distribute flyers, and record voter preferences or concerns, ii. Phone banking, where calls are made to voters to discuss issues, encourage participation, or persuade undecided individuals. iii. Postal canvassing, involving sending election materials to voters using addresses from the voters’ roll. iv. Online canvassing, which includes digital outreach via websites, social media, and targeted advertising. c. Commission: Refers to the Zimbabwe Electoral Commission (ZEC) established under the Constitution of Zimbabwe. d. Consent: Any clear, informed, and voluntary agreement by a data subject to the processing of their personal data. e. Data Controller: A person or entity that determines the purpose and means of processing personal data. f. Data Processor: A person or entity that processes personal data on behalf of the data controller. g. Data Protection Authority: means Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ). h. Data Subject: An individual whose personal data is being processed. i. Personal Data: Any information relating to an identified or identifiable individual. j. Political Party: means any political organisation. k. Sensitive Personal Data: Sensitive Information: refers to personal data that includes biometric data, racial or ethnic origin, political opinions, membership of a political association, and any information that may be considered as presenting a major risk to the rights of the data subject. l. Processing: Any operation performed on personal data, such as collection, storage, use, deletion, and transfer.
5. REQUIREMENTS FOR PROCESSING OF PERSONAL DATA DURING AND AFTER ELECTIONS
‘creating a level playing field’
The processing of personal information by aspiring and or elected officials, political parties, and electoral stakeholders, whether during or after electoral processes, constitutes the handling of sensitive data as defined under Section 11 of the CDPA. Such processing is strictly prohibited unless it fully complies with the
Data Protection Authority Implementation Guidelines on the
Page 43
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
specific conditions prescribed by the Act, including obtaining clear, informed consent from the data subject or meeting other lawful grounds for processing as outlined in the Act. Any deviation from these conditions makes the processing unlawful and subject to regulatory enforcement and penalties.
5.1. General Principles
Before processing people’s personal information for electoral purposes, the data controller shall: a. Inform the data subjects of the purpose and b. obtain consent before processing people’s personal data.
5.2. Licensing and Registration
All political parties, the Commission, and independent candidates shall be licensed and register as data controllers before processing personal data of Zimbabweans and shall abide by all the provisions of the CDPA and SI 155 of 2024.
5.3. Appointment of a Data Protection Officer
In line with the provisions of sections 20(5 and 6) and 12 of the CDPA and SI 155 of 2024, respectively, all political parties, independent candidates, and the commission shall appoint a Data Protection Officer
5.4. DATA PROTECTION PRINCIPLES
Political parties and actors increasingly rely on personal data to engage voters. The personal information must be processed lawfully, transparently, and fairly. Therefore, all election candidates shall adhere to the following:
1.1.1 Process data only for the specified use, and the information may not be used for any other
purposes.
6. LAWFUL BASIS FOR PROCESSING PERSONAL DATA
Personal data may only be processed under the following lawful basis: a. Explicit consent must be sought from the data subject before the processing of personal data. This consent must be freely given, specific, informed, and unambiguous, and must be documented in compliance with the provisions of the Act.
‘creating a level playing field’
b. All Political parties, independent candidates, the commission, and electoral stakeholders must inform data subjects of their rights, including their right to withdraw consent. c. The Authority does not recommend the use of legitimate interest as a lawful basis for processing information by Political parties, independent candidates, the commission, and electoral stakeholders.
Data Protection Authority Implementation Guidelines on the
Page 44
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
d. All personal data needs to be processed fairly and lawfully, and in a completely transparent way. In this case, all political parties, their members shall be responsible for informing data subjects of the intention to collect data, how the data will be used, and whether the data is to be shared with other parties, and who the said third party is. e. Personal data collected must be for a lawful reason and transparent, and it must not be processed in a way that is different from the original purpose. f. All the personal information collected during and after elections must not be excessive, given the purpose of the collection. Therefore, the personal data should be adequate, relevant, and not excessive. g. All personal data collected during and after elections must be up to date and accurate, which requires a regular review of data held for the purpose of amending any outdated or inaccurate information. Individuals have the right to have inaccurate data about them erased. h. Data relating to a data subject must be deleted or anonymised once it has served its purpose, subject to the entity having any other grounds for retaining the information. i. All political parties collecting or processing data have a responsibility to ensure that reasonable steps have been taken to implement security safeguards. This includes ascertaining the integrity of all employees authorised to access an individual’s personal information. j. Political parties, independent candidates, collecting and/or processing data, must ensure that their practices are compliant with the requirements of processing personal data.
7. DATA SECURITY AND DATA SUBJECTS’ RIGHTS
To secure and safeguard personal data being processed, political parties, independent candidates, the commission, electoral stakeholders, or the processor shall: a. Safeguard the security, integrity, and confidentiality of the data by putting in place appropriate technical and organisational measures that are necessary to protect data from negligent or unauthorised destruction, negligent loss, unauthorised alteration or access, and any other unauthorised processing of the data collected for electoral purposes. Implement privacy by design and by default to ensure that innovation can co-exist with privacy protection in all electoral processes. b. Restrict physical access to records and supervise access to voter information. c. Use encryption and password protection when using electronic gadgets. d. Notify the Data Protection Authority within 24 hours of a breach of personal data being processed. e. Inform affected individuals within 72 hours if their rights are at risk. f. Political parties, independent candidates, the commission, electoral stakeholders, or the processor must have robust, real-time mechanisms in place to respond to Data Subject Access Requests (DSARs)
‘creating a level playing field’
8. SECURING AND SHARING THE VOTER’S ROLL
a. The Electoral Commission must create a secure online portal for accessing the Voter’s Roll, ensuring strong access control mechanisms to prevent unauthorized access and maintain security.
Data Protection Authority Implementation Guidelines on the
Page 45
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
b. Any information shared with candidates, particularly the Voter’s Roll, must be fully anonymized, adhering strictly to the principle of data minimization and purpose limitation.
9. DUTY TO INFORM DATA SUBJECTS PRIOR TO THE COLLECTION OF THEIR PERSONAL
DATA
One of the key principles of data protection is transparency. The personal data processed by political parties, independent candidates, the Commission, and other electoral stakeholders shall be processed fairly and in a transparent manner. They must comply with the obligations under Section 14(1) of the Act, which states that data controllers and data processors have a duty to notify data subjects of the following before the collection of personal data: a. the rights of the data subject specified under section 14. b. the fact that personal data is being collected. c. the purpose for which the personal data is being collected. d. the third parties whose personal data has been or will be transferred to, including details of safeguards adopted. e. the contacts of the data controller or data processor, and whether any other entity may receive the collected personal data. f. a description of the technical and organizational security measures taken to ensure the integrity and confidentiality of the data. g. the data being collected pursuant to any law and whether such collection is voluntary or mandatory; and h. the consequences, if any, where the data subject fails to provide all or any part of the requested data. The above information should be provided to data subjects to enable them to understand how their personal data is used; this can be achieved by a privacy notice. The Authority advises that the information in a privacy notice must be provided in clear, plain language and be provided free of charge. The privacy notice must be kept up to date to meet any changes to the processing of data.
10. DATA COLLECTION AND USE
Aspiring and elected officials shall: a. Collect only personal data necessary for specific purposes (e.g., political membership, petitions, and grievances). b. Avoid collecting other sensitive data unless it is necessary and justified.
11. DATA QUALITY AND RETENTION
Political parties, their candidates, and electoral stakeholders shall: ‘ca.r Keeep daata atcciunrate agnd u p tao date . level playing field’ b. Allow the electorate to correct their information. c. State how long they will keep the data for.
Data Protection Authority Implementation Guidelines on the
Page 46
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
d. Securely delete or anonymize data when no longer needed.
12. TRAINING AND AWARENESS
Political parties, independent candidates, the commission, and related organisations shall: a. Ensure all electoral stakeholders, including candidates and campaign teams, receive mandatory training on the principles and obligations of data protection under the Act. b. Promote awareness of data subject rights, including consent, access, correction, and objection to data processing. c. Educate stakeholders on the definition and handling of personal and sensitive data, especially political opinions, affiliations, and biometric data. d. Clarify the roles of data controllers and processors, and the requirement to appoint a Data Protection Officer (DPO) where applicable. e. Emphasize the importance of lawful, fair, and transparent data processing, especially during voter outreach, canvassing, and digital campaigning. f. Highlight the need for secure data storage and transmission, including protection against unauthorized access, breaches, and cyber threats. g. Encourage the development and implementation of Data protection policies and internal codes of conduct approved by the Data Protection Authority. h. Provide guidance on reporting mechanisms for data breaches and non-compliance, including whistleblowing provisions. i. Reinforce the legal consequences of violating data protection laws, including penalties and reputational risks. j. Collaborate with the Data Protection Authority to ensure continuous education and compliance monitoring throughout the electoral cycle.
13. ETHICAL CONSIDERATIONS
All people involved in the electoral process must: a. Respect the dignity and privacy of citizens. b. Uphold all the rights of data subjects enshrined in the CDPA and CDPR. c. Do not use personal data for any other purposes separate from the initial purpose.
‘creating a level playing field’
d. Appoint a Data Protection Officer who shall assist in ensuring compliance with the requirements of processing personal data.
Data Protection Authority Implementation Guidelines on the
Page 47
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
14. PROHIBITED PRACTICES
Processing of information under the following conditions shall be prohibited: a. Processing data without being licensed and registered as a data controller. b. Processing and sharing data without consent from data subjects or a legal basis for processing such information. c. Retaining data indefinitely without justification. d. Transferring and sharing collected information for the purpose of elections outside Zimbabwe.
15. PENALTIES AND FINES FOR NON-COMPLIANCE
Any person who does not comply with the provisions of the Cyber and Data Protection Act and SI 155 of
‘creating a level playing field’
Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.