Cyber Security and Data Protection
“third party” refers to any natural or legal person or organisation other than
the data subject, the controller, the processor and anyone who, under the
direct authority of the controller or the processor, is authorised to process
the data;
“transborder flow” refers to international flows of data by the means of
transmission including data transmission electronically or by satellite;
“whistleblowing” refers to legal provisions permitting individuals to report
the behaviour of a member of their organisation which, they consider
contrary to a law or regulation or fundamental rules established by their
organisation.
4
5
10
Application
(1) This Act shall apply to matters relating to access to information, protection
of privacy of information and processing of data wholly or partly by automated means:
and shall be interpreted as being in addition to and not in conflict or inconsistent with
the Protection of Personal Information Act [Chapter........].
(2) Subject to subsection (1) this Act shall be applicable—
(a) to the processing of data carried out in the context of the effective and
actual activities of any data controller;
(b) to the processing of data by a controller who is not permanently established
in Zimbabwe, if the means used, whether electronic or otherwise is located
in Zimbabwe, and such processing is not for the purposes of the mere
transit of data through Zimbabwe.
(3) In the circumstances referred to in subsection (2)(b), the controller shall
designate a representative established in Zimbabwe, without prejudice to legal
proceedings that may be brought against the controller.
15
20
25
PART II
Establishment of Cyber Security Centre
5
Designation of Postal and Telecommunications Regulatory Authority
as Cyber Security Centre
The Postal and Telecommunications Regulatory Authority established in terms
of the Postal and Telecommunications Act [Chapter 12:05] is hereby designated as the
Cyber Security Centre.
6
30
Functions of Cyber security Centre
The functions of the Cyber Security Centre shall be to—
(a) advise Government and implement Government policy on cyber crime
and cyber security;
(b) identify areas for intervention to prevent cyber crime;
(c) coordinate cyber security and establish a national contact point available
daily around-the-clock;
(d) establish and operate a protection-assured whistle-blower system that will
enable members of the public to confidentially report to the Committee
cases of alleged cyber crime;
(e) promote and coordinate activities focused on improving cyber security
and preventing cyber crime by all interested parties in the public and
private sectors;
6
35
40
45