Cyber Security and Data Protection
(2) The adequacy of the level of protection afforded by the third country
or international organisation in question shall be assessed in the light of all the
circumstances surrounding a data transfer operation or set of data transfer operations;
with particular consideration being given to the nature of the data, the purpose and
duration of the proposed processing operation or operations, the recipient third country
or recipient international organisation, the laws relating to data protection in force in
the third country or international organisation in question and the professional rules
and security measures which are complied with in that third country or international
organisation.
(3) The Authority shall lay down the categories of processing operations for
which and the circumstances in which the transfer of data to countries outside the
Republic of Zimbabwe is not authorised.
29
10
Transfer to a country outside the Republic of Zimbabwe which does
not assure an adequate level of protection
(1) A transfer or a set of transfers of data to a country outside the Zimbabwe
which does not assure an adequate level of protection may take place in one of the
following cases—
(a) the data subject has unambiguously given his or her consent to the
proposed transfer;
(b) the transfer is necessary for the performance of a contract between the
data subject and the controller or the implementation of pre-contractual
measures taken in response to the data subject’s request;
(c) the transfer is necessary for the conclusion or performance of a contract
concluded or to be concluded between the controller and a third party in
the interest of the data subject;
(d) the transfer is necessary or legally required on important public interest
grounds, or for the establishment, exercise or defense of legal claims;
(e) the transfer is necessary in order to protect the vital interests of the data
subject;
(f) the transfer is made from a register which, according to acts or regulations,
is intended to provide information to the public and which is open to
consultation either by the public in general or by any person who can
demonstrate a legitimate interest, to the extent that the conditions laid
down in law for consultation are fulfilled in the case at hand.
PART IX
Code of Conduct
30
5
15
20
25
30
35
Code of Conduct
(1) The Authority shall provide guidelines and approve codes of conduct and
ethics governing the rules of conduct to be observed by data controllers and categories
of data controllers.
40
(2) In effecting (1) above, the Authority shall consider trade associations and
other bodies representing other categories of controllers who have national codes or
have the intention of amending or extending existing national codes and allow them
to submit such codes for the approval of the Authority.
(3) The Authority in considering codes of conduct for approval, shall ascertain,
among other things, whether the Codes submitted comply with the provisions of this
16
45