Cyber Security and Data Protection
2
Object
The object of this Act is to increase cyber security in order to build confidence
and trust in the secure use of information and communication technologies by data
controllers, their representatives and data subjects.
3
Interpretation
5
In this Act—
“child” means any person under the age of eighteen years;
“code of conduct” refers to the Data Use Charters drafted by the data controller
in order to institute the rightful use of IT resources, the Internet, and
electronic communications of the structure concerned, and which have
been approved by the Data Protection Authority;
“consent” refers to any manifestation of specific unequivocal, freely given,
informed expression of will by which the data subject or his or her legal,
judicial or legally appointed representative accepts that his or her data
be processed;
“critical database” means a computer data storage medium or any part thereof
which contains critical data;
“data” means any representation of facts, concepts, information, whether in text,
audio, video, images, machine-readable code or instructions, in a form
suitable for communications, interpretation or processing in a computer
device, computer system, database, electronic communications network
or related devices and includes a computer programme and traffic data;
“data controller or controller” refers to any natural person or legal person who
is licensible by the Authority;
“data controller’s representative or controller’s representative” refers to any
natural person or legal person who performs the functions of the data
controller in compliance with obligations set forth in this Act;
“data processor” refers to a natural person or legal person, who processes data
for and on behalf of the controller and under the controller’s instruction,
except for the persons who, under the direct employment or similar
authority of the controller, are authorised to process the data;
“data protection authority or authority” refers to Postal and Telecommunications
Regulatory Authority of Zimbabwe established in terms of section 5 of
the Postal and Telecommunications Act [Chapter 12:05];
“data protection officer or DPO” refers to any individual appointed by the
data controller and is charged with ensuring, in an independent manner,
compliance with the obligations provided for in this Act;
“data subject” refers to an individual who is an identifiable person and the
subject of data;
“disproportionate effort” means effort that is so labour intensive as to consume
a lot of time, money and manpower resources;
“electronic communications network” means any electronic communications
infrastructures and facilities used for the conveyance of data;
“genetic data: refers to any personal information stemming from a
Deoxyribonucleic acid (DNA) analysis;
“health professional” refers to any individual determined as such by
Zimbabwean law;
“identifiable person” means a person who can be identified directly or indirectly,
in particular by reference to an identification number or to one or more
4
10
15
20
25
30
35
40
45