Cyber and Data Protection Regulations 2024, children's information and automated decisions
Statutory Instrument 155 of 2024, regulation 10 (children's information and automated decisions)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 September 2024.
A sensitive categories rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Obtain the consent of a parent or legal guardian before processing a child's personal information, and do not subject a child's data to automated decision-making that affects the child's rights.
- Make reasonable efforts to verify that the consent to process a child's personal information was given or authorised by the parent or legal guardian, taking available technology into account.
- Conduct regular data protection impact assessments to identify and mitigate privacy risks to children, and ensure data protection by design and by default when processing children's data.
- Do not subject any data subject to a decision based solely on automated processing which produces legal effects concerning them, without their consent or a provision established by law.
What it reaches
Obligation class
Consent, Age verification, DPIA, Prohibition
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Regulation 10(5)(a) bars a data controller from processing a child's personal information without the consent of the child's parent or legal guardian, and regulation 10(5)(b) requires reasonable efforts to verify that the consent was given or authorised by that parent or guardian, taking available technology into account.
Regulation 10(5)(d) requires regular data protection impact assessments to identify and mitigate privacy risks to children, regulation 10(5)(e) requires data protection by design and by default when processing children's data, and regulation 10(5)(f) bars subjecting children's data to automated decision making that has the effect of affecting the children's rights.
Regulation 10(3) separately bars subjecting any data subject to a decision based solely on automated processing which produces legal effects concerning them, without that data subject's consent or a provision established by law. Regulation 10(6) makes contravening the regulation an offence carrying a fine up to level 11 or up to seven years' imprisonment, or both.
The Regulations were made by the Minister of Information Communications Technology, Postal and Courier Services in consultation with the Authority under section 32 of the Cyber and Data Protection Act, and took effect on their publication on 13 September 2024.
When LexLint raises it
crawls_webtrains_modelsserves_minorshigh_risk_decisionsprocesses_biometrics
Read the law
Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations
2024, Statutory Instrument 155 of 2024, official text reproduced by Veritas Zimbabwe
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.