Law / Zimbabwe

Cyber and Data Protection Act, sensitive, genetic, biometric and health data

Cyber and Data Protection Act, No. 5 of 2021, ss. 11-12 (sensitive information and genetic, biometric and health data)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 11 March 2022.

A sensitive categories rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's written consent, withdrawable at any time, before processing sensitive data such as race, political opinion, religion, trade union membership, sex life, health or criminal history.
  • Do not process genetic data, biometric data or health data at all unless the data subject has given written consent.
  • Let a data subject withdraw consent to sensitive data processing at any time, without explanation and free of charge, and stop relying on it once they do.
  • Where you rely on the not-for-profit ground in section 11(5), confine the processing to the organisation's members or regular contacts and do not disclose the data to a third party without the data subjects' consent.

What it reaches

Obligation class

Prohibition, Consent, Biometric

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 11(1) bars a data controller from processing sensitive data unless the data subject has given consent in writing, and section 11(2) lets the data subject withdraw that consent at any time, without explanation and free of charge. Section 11(3) lets the Authority determine the circumstances in which the prohibition cannot be lifted even with consent.

Section 11(5) disapplies the consent requirement where the processing is necessary to carry out the controller's obligations and specific rights in employment law, to protect vital interests where the data subject cannot consent, in the legitimate activities of a not-for-profit body confined to its members, to comply with national security laws, for legal claims with appropriate guarantees, where the data subject has made the data public, for scientific research on the Authority's conditions, or where a law authorises it for a substantial public interest.

Section 12 bars the processing of genetic data, biometric sensitive data and health data altogether unless the data subject has given written consent. The Act was gazetted on 11 March 2022, the day it came into operation, so these provisions have bound since then.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice
  • handles_health_records

Read the law

Cyber and Data Protection Act
No. 5 of 2021, official text as gazetted with the correct title and chapter number on 11 March 2022, reproduced by Veritas Zimbabwe

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app