Law / Zimbabwe

Cyber and Data Protection Regulations 2024, children's information and automated decisions

Statutory Instrument 155 of 2024, regulation 10 (children's information and automated decisions)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 September 2024.

A sensitive categories rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the consent of a parent or legal guardian before processing a child's personal information, and do not subject a child's data to automated decision-making that affects the child's rights.
  • Make reasonable efforts to verify that the consent to process a child's personal information was given or authorised by the parent or legal guardian, taking available technology into account.
  • Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data.
  • Do not subject any data subject to a decision based solely on automated processing which produces legal effects concerning them, without their consent or a provision established by law.

What it reaches

Obligation class

Consent, Age verification, DPIA, Prohibition

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Regulation 10(5)(a) bars a data controller from processing a child's personal information without the consent of the child's parent or legal guardian, and regulation 10(5)(b) requires reasonable efforts to verify that the consent was given or authorised by that parent or guardian, taking available technology into account.

Regulation 10(5)(d) requires regular data protection impact assessments to identify and mitigate privacy risks to children, regulation 10(5)(e) requires data protection by design and by default when processing children's data, and regulation 10(5)(f) bars subjecting children's data to automated decision making that has the effect of affecting the children's rights.

Regulation 10(3) separately bars subjecting any data subject to a decision based solely on automated processing which produces legal effects concerning them, without that data subject's consent or a provision established by law. Regulation 10(6) makes contravening the regulation an offence carrying a fine up to level 11 or up to seven years' imprisonment, or both.

The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.

When LexLint raises it

  • crawls_web
  • trains_models
  • serves_minors
  • high_risk_decisions
  • processes_biometrics

Read the law

Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations
2024, Statutory Instrument 155 of 2024, official text reproduced by Veritas Zimbabwe

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app