Comprehensive regime
Cyber and Data Protection Act [Chapter 12:07]
Cyber and Data Protection Act, No. 5 of 2021 (Zimbabwe)Cyber and Data Protection Act
In force since 11 March 2022. Binds public and private bodies.
What this law does
Every data controller or processor must ensure personal data is processed necessarily, fairly and lawfully (s. 8), collected for specified and legitimate purposes (s. 9), and, for sensitive data (including data revealing race, political opinion, religion, trade union membership, sex life, and health, genetic, or criminal history), only with the data subject's written consent, withdrawable at any time (s. 11).
Genetic data, biometric data and health data may not be processed at all unless the data subject has given written consent (s. 12). A data controller must notify the Authority of a security breach within 24 hours of discovering it (s. 19). A data subject has the right to be informed, to access their data, to object to processing, and to correct or delete false or misleading data (s. 14).
Transferring personal data outside Zimbabwe requires an adequate level of protection in the recipient's country or the transfer to be solely for tasks within the controller's competence (s. 28).
Any data controller, representative, agent or assignee who contravenes sections 11 (sensitive data), 13 (duties of controller), 18(4) (security), 24 (accountability) or 28 (transborder transfer) is guilty of an offence, liable to a fine not exceeding level 11 or imprisonment not exceeding seven years, or both (s. 33(2)); a member of staff of the Authority, or any expert, contractor or sub-contractor who violates the Act is liable to a fine not exceeding level 7 or imprisonment not exceeding two years, or both (s. 33(1)). The Act does not describe a private civil right of action for a data subject in the text reviewed.
What it requires