Skip to content

Research · authority data, public-interest

← Back to Legal library

CDPG 7 of 2025 — Processing by MSMEs

CDPG-7-2025 · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

CDPG-7-of-2025-Processing-by-MSMEs.pdf

application/pdf · 8.0 MB

Sanitised text

CDPG 7 of 2025 — Processing by MSMEs — Verbatim Transcription

Citation key: CDPG-7-2025 · Category: Implementation Guideline · Pages: 9

Source PDF: CDPA Implementation Guidelines/CDPG 7 of 2025 - Processing by MSMEs.pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 9

Data Protection Authority Implementation Guidelines on the

Page 48

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on the Processing of Personal Information by Micro- Small to Medium Enterprises (MSMEs), in Zimbabwe. CDPG 7 of 2025

‘creating a level playing field’

Page 2 of 9

Data Protection Authority Implementation Guidelines on the

Page 49

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

Implementation Guidelines on the Processing of Personal Information By Micro- Small To Medium Enterprises (MSMEs), in Zimbabwe.

1. PURPOSE AND EFFECTIVE DATE

These guidelines are issued in accordance with section 6 of the Cyber and Data Protection Act [Chapter 12:07] (hereinafter referred to as “the CDPA”), which mandates the Authority to produce regulatory sectoral guidelines to facilitate and promote the fair processing of personal data in Zimbabwe. These guidelines seek to assist data controllers within the MSMEs sector to fully understand the application scope of the CDPA and effectively aid understanding of their respective compliance obligations. The guidelines shall be read in conjunction with the provisions of the CDPA and Section 11 of Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155 of 2024). The Guidelines shall be effective from the date of publication.

2. INTERPRETATION

In these Guidelines, the following shall mean: “CDPA” refers to the Cyber and Data Protection Act [Chapter 12:07] “Data Protection Authority (DPA) or “the Authority” refers to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), designated as such in terms of section 5 of the Cyber and Data Protection Act. “Data Controller” refers to any natural person or legal person who is licensable by the Authority, including public bodies and any other person who determines the purpose and means of processing personal data. “Data protection officer” or “DPO” refers to any individual appointed by the data controller and who is charged with ensuring, in an independent manner, compliance with the obligations provided for in the

CDPA.

“Personal information” means information relating to a data subject which can be used to identify an individual. “Processing” refers to any operation or set of operations that are performed upon data, whether or not by automatic means, such as obtaining, recording or holding the data or carrying out any operation or set of operations on data. “Data Subject” means an identified or identifiable natural person who is the subject of data. “Sensitive data” refers to information or any opinion about an individual which reveals or contains, racial or ethnic origin; political opinions; membership of a political association; religious beliefs or affiliations; ‘pchilosropheical abeliefts; imenmbegrship ofa a pro feslseional vor traede asls ocpiationl; maembyershiipn of a tgrade unfioni; esex ld’ life; criminal, educational, financial or employment history; gender, age, marital status or family status. “Cross-border transfer of data” refers to the transfer of personal data beyond the borders of Zimbabwe.

Page 3 of 9

Data Protection Authority Implementation Guidelines on the

Page 50

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

“SME Act” refers to the Small to Medium Enterprises Act [Chapter 24:12] “Micro- small to medium enterprises” refers to a business, either incorporated or not, run by one or more people, with or without branches or subsidiaries, that mainly operates in a specific sector of the economy of Zimbabwe.

SCOPE AND APPLICATION

These guidelines apply to the processing of personal data by MSMEs. They seek to provide a clear understanding of MSMEs’ obligations under the Cyber and Data Protection Act [Chapter 12:07]. They present a simplified approach to assist MSMEs in understanding the scope of their data processing activities, including the collection, use, retention, disclosure, and disposal of personal data, which incline to recommended data protection practices. These guidelines apply to all MSMEs established or ordinarily resident in Zimbabwe in terms of the Small to Medium Enterprises Act [Chapter 24:12], as read with section

4.(2) (b) of the CDPA.

3. BACKGROUND

Most business operations involve the processing of personal data. MSMEs collect personal data, and they must process data in a lawful, transparent and fair manner, ensuring that they implement all data protection principles in their processing activities to comply with the CDPA.

3. ARE ORGANISATIONS IN THE MSMEs SECTOR DATA CONTROLLERS IN TERMS OF THE

CDPA?

3.1.According to section 3 of the CDPA, a data controller refers to any natural or legal person who is licensable by the Authority, including public bodies and any other person who determines the purpose and means of processing personal data.
3.2.Additionally, section 3 of SI 155 further clarifies that a person must obtain a license if they process personal data with any of the following intentions:
Determining the means, purpose, or outcome of data processing.
Deciding what personal data to collect.
Selecting the individuals from whom to collect data.
Using personal data for commercial gain or other benefits
3.3.From the definition, MSMEs are data controllers.

4. ARE MSMEs LICENSED BY THE AUTHORITY AS DATA CONTROLLERS?

4.1. Any person who processes personal information for more than 50 data subjects is licensable

by the Authority.

4.2. Classes of MSMEs

-Micro enterprises ‘crea Mticrio nentergprise s aare ty piclaelly vevry smeall elnt itieps, oftlena infoyrmal iannd opgerate d fbyi ae solel d’ trader or a partnership of two individuals. In Zimbabwe, licensing and registration are required for organisations that process personal information for 50 and above data subjects. Micro enterprises must carefully assess whether they process information for more than 50
Page 4 of 9

Data Protection Authority Implementation Guidelines on the

Page 51

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

data subjects. If a micro-enterprise processes information for fewer than 50 data subjects, it is not required to apply for a data controller licence. However, it must still comply with the data protection principles set out in the Cyber and Data Protection Act and its Regulations. Small enterprises Small enterprises are basically very small in size but generally larger than micro enterprises. They are formally structured and are either run by a sole trader or more people and typically employ more employees than micro enterprises. In Zimbabwe, licensing and registration are required for organisations that process personal information for 50 and above data subjects. In that regard, small enterprises must also carefully assess whether they process information for more than 50 data subjects. If they process personal information for less than 50 data subjects, they are not required to apply for a data controller licence. However, they must still comply with the data protection principles set out in the Cyber and Data Protection Act and its regulations.

-Medium enterprises Medium enterprises are formally registered businesses that are larger than small enterprises but not as big as a large corporation. They typically employ more people than small enterprises, and they operate in different sectors of of the economy. Most medium-sized enterprises process personal information for more than 50 data subjects. Some are likely to fall within tier 1, with others slightly falling into tier 2, and if that is the case, they are required to register and apply for a license, in compliance with the Data Protection laws. In Zimbabwe, organisations are categorised into tiers for data protection licensing purposes and the type of data controller licence an organisation needs is based on the number of people whose personal data it processes, and not the number of employees

4.3. See the definition of tiers below

-MSMEs that process personal information for 50- 1000 data subjects fall under tier 1.
-MSMEs that process personal information for 1001 to 100,000 data subjects fall under tier 2. ‘5c. ArREe ORGaANItSAiTnIONSg WIT HIaN TH El MeSMEv COeMMUlN ITpY MAlNaDATyED TiOn APPgOIN T Af DiAeTA ld’

PROTECTION OFFICER?

5.1. Any MSME that processes personal data subjects that are above 1000 are mandated to appoint

a DPO.

Page 5 of 9

Data Protection Authority Implementation Guidelines on the

Page 52

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

5.2.Any MSME with 50 and above data subjects that processes sensitive information is also required to appoint a DPO.

6. APPLICATION OF DATA PROTECTION PRINCIPLES BY MSMEs

6.1.MSMEs must process data in a lawful, transparent and fair manner as enshrined in the law.
6.1.1.This entails that:
-All MSMEs should seek consent from the data subject before processing data.
-Consent shall be in writing for the processing of sensitive personal data, or for the transfer of personal data outside of Zimbabwe
-MSMEs can process personal data for a clear, known legitimate interest of the business, e.g. Human Resources Management, security reasons.
-MSMEs can also process data lawfully to fulfil obligations from a contractual agreement between themselves and other parties.
-It is also lawful for MSMEs to process personal data if the processing is in the vital interests of the data subject, e.g. in case of health emergencies where processing is necessary to save or protect a data subject’s life.
6.2.In the processing of personal data, MSMEs must ensure that:
-Personal data is processed for the purpose for which it was collected and it is prohibited to process data for another purpose that was not specified.
-Personal information is not kept for more than necessary in relation to the purposes for which it was collected.
-Personal data kept by MSMEs must be correct and up to date.
-They demonstrate compliance with all data protection principles and all obligations outlined in the CDPA and the Regulations-(SI 155 of 2024).
-All MSMEs are accountable to the DPA to follow the law.

6.3. Simple Self-assessment Strategies for MSMEs to Implement Data Protection Principles

It is encouraged that MSMEs conduct an evaluation to determine the following;

-The type of data they process
-Why they need to store that data, for example, for tax reasons
-How and where the data will be stored securely, either by the business or a third- party organisation
-How the data can be accessed by data subjects if needed
-Periods they need to keep the data
-How the data is deleted or destroyed

7. RISKS THAT MSMEs SHOULD LOOK OUT FOR IN THE PROCESSING OF PERSONAL DATA

7.1. Unauthorised Access

‘creating a level playing field’

-Storing data manually can be easier to access without proper authorisation, leading to breaches of privacy of sensitive information falling into the wrong hands.
Page 6 of 9

Data Protection Authority Implementation Guidelines on the

Page 53

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

7.2. Human Error

-Manual processes can be prone to human error, including misfiling documents,
-Lack of or no verification of information, and unintentional disclosure of information can lead to inaccurate processing of data.

7.3. Excessive storage

Lack of defined periods of keeping personal data can lead to storage of large volumes of unnecessary personal information, which in turn;

-Create more entry points for cyberattacks/ increased cyber threats
-Makes it harder to secure all data effectively.
-Increase the risk and impact of a breach, especially if sensitive data is involved.

8. INSTANCES OF NON-COMPLIANCE TO WATCH OUT FOR

8.1.Processing personal data without a license.
8.2.Failure to appoint a data protection officer.
8.3.Processing children’s personal information without the authority of their parent or guardian.
8.4.Failure to report a data breach after being aware of such breach to the Authority within 24 hours and within 72 hours to the affected data subjects.

8.5. Providing false information to the Authority

8.6.Failure to renew a data protection licence.

8.7. Processing and transferring personal data outside of Zimbabwe without approval from the

Authority.

9. PENALTIES AND FINES FOR NOT FOLLOWING THE LAW

Failure to follow the law will result in the following;

a)Fines up to level 11,
b)Imprisonment up to 7 years
c)An order to stop the processing of personal data- (Cancellation of Data Protection License.)

10. PRACTICAL RECOMMENDATIONS AND TIPS FOR MSMEs WHEN PROCESSING PERSONAL

INFORMATION

MSMEs should;

-Seek professional guidance and advice from the Authority
-Appoint or train a certified DPO

‘creating a level playing field’

-Establish a clear reason relevant to the business for processing personal data
-Create clear ways to seek consent from data subjects and to
Page 7 of 9

Data Protection Authority Implementation Guidelines on the

Page 54

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

establish a communication framework in a way that respects data subject’s rights, e.g, consent forms, privacy notices, etc

-Use encryption, password protection, and secure cloud services as

part of the technical measures to secure the

integrity and confidentiality of personal data.

-Restrict physical access to records and supervise visitors
-Invest in data protection awareness and capacity building for staff, as part of existing capacity building initiatives
-implement storage mechanisms that ensure that they keep personally identifiable information for no longer than necessary
-Set up clearly defined procedures for secure deletion of personal data.
-Strive to get awareness of stipulated legal retention limits for different data types and sectors (e.g. financial and health data)

‘creating a level playing field’

Page 8 of 9

Data Protection Authority Implementation Guidelines on the

Page 55

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

ANNEXURE 1: COMPLIANCE CHECKLIST FOR MSMEs

Description of requirement YES NO Comments Data controller licence If tier 2 and above- Appointment of a DPO A recognised reason for processing personal data Training and awareness Implementation of Data protection princi- ples Records of all Processing Activities Consent forms/ data subjects access request forms Data Protection Policy/ Privacy policies Periods of keeping data Approval for transfer of Data outside of Zim- babwe Data processing/ sharing agreements in place with processors Data Protection Impact Assessments when necessary (Transfer of data outside Zimba- bwe, integration of new technologies, data processing using digital means, processing sensitive data, children’s data) Measures to ensure the security and confi- dentiality of data Risk assessments and reports Valid consent- processing of children’s data For compliance and further guidance, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at regulator@potraz.zw or call +263 242 333032/48

‘creating a level playing field’

Page 9 of 9

Data Protection Authority Implementation Guidelines on the

Page 56

Cyber and Data Protection Act [Chapter 12:07]

‘creating a level playing field’

1110 Perfomance Close, Mt Pleasant Business Park

P.O Box MP 843, Mt Pleasant, Harare, Zimbabwe Toll Free Number: 0800 4303 Tel: +263 24-2-333032 Fax: +263 24-2-333041

‘creating a level playing field’

Referenced by Privacy Hub
Processing personal data

Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.