CDPG 7 of 2025 — Processing by MSMEs
CDPG-7-2025 · v1 · release faf85cbc
CDPG 7 of 2025 — Processing by MSMEs — Verbatim Transcription
Citation key: CDPG-7-2025 · Category: Implementation Guideline · Pages: 9
Source PDF: CDPA Implementation Guidelines/CDPG 7 of 2025 - Processing by MSMEs.pdf
Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.
Data Protection Authority Implementation Guidelines on the
Page 48
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on the Processing of Personal Information by Micro- Small to Medium Enterprises (MSMEs), in Zimbabwe. CDPG 7 of 2025
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 49
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
Implementation Guidelines on the Processing of Personal Information By Micro- Small To Medium Enterprises (MSMEs), in Zimbabwe.
1. PURPOSE AND EFFECTIVE DATE
These guidelines are issued in accordance with section 6 of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA”), which mandates the Authority to produce regulatory sectoral guidelines to facilitate and promote the fair processing of personal data in Zimbabwe. These guidelines seek to assist data controllers within the MSMEs sector to fully understand the application scope of the CDPA and effectively aid understanding of their respective compliance obligations. The guidelines shall be read in conjunction with the provisions of the CDPA and Section 11 of Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155 of 2024). The Guidelines shall be effective from the date of publication.
2. INTERPRETATION
In these Guidelines, the following shall mean: “CDPA” refers to the Cyber and Data Protection Act [Chapter 12:07] “Data Protection Authority (DPA) or “the Authority” refers to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as such in terms of section 5 of the Cyber and Data Protection Act. “Data Controller” refers to any natural person or legal person who is licensable by the Authority, including public bodies and any other person who determines the purpose and means of processing personal data. “Data protection officer” or “DPO” refers to any individual appointed by the data controller and who is charged with ensuring, in an independent manner, compliance with the obligations provided for in the
CDPA.
“Personal information” means information relating to a data subject which can be used to identify an individual. “Processing” refers to any operation or set of operations that are performed upon data, whether or not by automatic means, such as obtaining, recording or holding the data or carrying out any operation or set of operations on data. “Data Subject” means an identified or identifiable natural person who is the subject of data. “Sensitive data” refers to information or any opinion about an individual which reveals or contains, racial or ethnic origin; political opinions; membership of a political association; religious beliefs or affiliations; ‘pchilosropheical abeliefts; imenmbegrship ofa a pro feslseional vor traede asls ocpiationl; maembyershiipn of a tgrade unfioni; esex ld’ life; criminal, educational, financial or employment history; gender, age, marital status or family status. “Cross-border transfer of data” refers to the transfer of personal data beyond the borders of Zimbabwe.
Data Protection Authority Implementation Guidelines on the
Page 50
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
“SME Act” refers to the Small to Medium Enterprises Act [Chapter 24:12] “Micro- small to medium enterprises” refers to a business, either incorporated or not, run by one or more people, with or without branches or subsidiaries, that mainly operates in a specific sector of the economy of Zimbabwe.
SCOPE AND APPLICATION
These guidelines apply to the processing of personal data by MSMEs. They seek to provide a clear understanding of MSMEs’ obligations under the Cyber and Data Protection Act [Chapter 12:07]. They present a simplified approach to assist MSMEs in understanding the scope of their data processing activities, including the collection, use, retention, disclosure, and disposal of personal data, which incline to recommended data protection practices. These guidelines apply to all MSMEs established or ordinarily resident in Zimbabwe in terms of the Small to Medium Enterprises Act [Chapter 24:12], as read with section
3. BACKGROUND
Most business operations involve the processing of personal data. MSMEs collect personal data, and they must process data in a lawful, transparent and fair manner, ensuring that they implement all data protection principles in their processing activities to comply with the CDPA.
3. ARE ORGANISATIONS IN THE MSMEs SECTOR DATA CONTROLLERS IN TERMS OF THE
CDPA?
4. ARE MSMEs LICENSED BY THE AUTHORITY AS DATA CONTROLLERS?
4.1. Any person who processes personal information for more than 50 data subjects is licensable
by the Authority.
4.2. Classes of MSMEs
Data Protection Authority Implementation Guidelines on the
Page 51
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
data subjects. If a micro-enterprise processes information for fewer than 50 data subjects, it is not required to apply for a data controller licence. However, it must still comply with the data protection principles set out in the Cyber and Data Protection Act and its Regulations. Small enterprises Small enterprises are basically very small in size but generally larger than micro enterprises. They are formally structured and are either run by a sole trader or more people and typically employ more employees than micro enterprises. In Zimbabwe, licensing and registration are required for organisations that process personal information for 50 and above data subjects. In that regard, small enterprises must also carefully assess whether they process information for more than 50 data subjects. If they process personal information for less than 50 data subjects, they are not required to apply for a data controller licence. However, they must still comply with the data protection principles set out in the Cyber and Data Protection Act and its regulations.
4.3. See the definition of tiers below
PROTECTION OFFICER?
5.1. Any MSME that processes personal data subjects that are above 1000 are mandated to appoint
a DPO.
Data Protection Authority Implementation Guidelines on the
Page 52
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
6. APPLICATION OF DATA PROTECTION PRINCIPLES BY MSMEs
6.3. Simple Self-assessment Strategies for MSMEs to Implement Data Protection Principles
It is encouraged that MSMEs conduct an evaluation to determine the following;
7. RISKS THAT MSMEs SHOULD LOOK OUT FOR IN THE PROCESSING OF PERSONAL DATA
7.1. Unauthorised Access
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 53
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
7.2. Human Error
7.3. Excessive storage
Lack of defined periods of keeping personal data can lead to storage of large volumes of unnecessary personal information, which in turn;
8. INSTANCES OF NON-COMPLIANCE TO WATCH OUT FOR
8.5. Providing false information to the Authority
8.7. Processing and transferring personal data outside of Zimbabwe without approval from the
Authority.
9. PENALTIES AND FINES FOR NOT FOLLOWING THE LAW
Failure to follow the law will result in the following;
10. PRACTICAL RECOMMENDATIONS AND TIPS FOR MSMEs WHEN PROCESSING PERSONAL
INFORMATION
MSMEs should;
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 54
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
establish a communication framework in a way that respects data subject’s rights, e.g, consent forms, privacy notices, etc
part of the technical measures to secure the
integrity and confidentiality of personal data.
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 55
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
ANNEXURE 1: COMPLIANCE CHECKLIST FOR MSMEs
Description of requirement YES NO Comments Data controller licence If tier 2 and above- Appointment of a DPO A recognised reason for processing personal data Training and awareness Implementation of Data protection princi- ples Records of all Processing Activities Consent forms/ data subjects access request forms Data Protection Policy/ Privacy policies Periods of keeping data Approval for transfer of Data outside of Zim- babwe Data processing/ sharing agreements in place with processors Data Protection Impact Assessments when necessary (Transfer of data outside Zimba- bwe, integration of new technologies, data processing using digital means, processing sensitive data, children’s data) Measures to ensure the security and confi- dentiality of data Risk assessments and reports Valid consent- processing of children’s data For compliance and further guidance, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48
‘creating a level playing field’
Data Protection Authority Implementation Guidelines on the
Page 56
Cyber and Data Protection Act [Chapter 12:07]
‘creating a level playing field’
1110 Perfomance Close, Mt Pleasant Business Park
P.O Box MP 843, Mt Pleasant, Harare, Zimbabwe Toll Free Number: 0800 4303 Tel: +263 24-2-333032 Fax: +263 24-2-333041
‘creating a level playing field’
Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.