Cyber and Data Protection Act, 2021 Zimbabwe "processing" refers to any operation or set of operations which are performed upon data, whether or not by automatic means, such as obtaining recording or holding the data or carrying out any operation or set of operations on data, including— (a) organisation, adaptation or alteration of the data; (b) retrieval, consultation or use of the data; or (c) alignment, combination, blocking, erasure or destruction of the data; "recipient" a natural or legal person, agency or any other body to whom personal information is disclosed by a data controller, whether a third party or not; however, persons who receive personal information in the framework of a particular legal inquiry shall not be regarded as recipients; "sensitive data" refers to— (a) information or any opinion about an individual which reveals or contains the following— (i) racial or ethnic origin; (ii) political opinions; (iii) membership of a political association; (iv) religious beliefs or affiliations; (v) philosophical beliefs; (vi) membership of a professional or trade association; (vii) membership of a trade union; (viii) sex life; (ix) criminal educational, financial or employment history; (x) gender, age, marital status or family status; (b) health information about an individual; (c) genetic information about an individual; or (d) any information which may be considered as presenting a major risk to the rights of the data subject; "third party" refers to any natural or legal person or organisation other than the data subject, the controller, the processor and anyone who, under the direct authority of the controller or the processor, is authorised to process the data; "transborder flow" refers to international flows of data by the means of transmission including data transmission electronically or by satellite; "whistleblowing" refers to legal provisions permitting individuals to report the behaviour of a member of their organisation which, they consider contrary to a law or regulation or fundamental rules established by their organisation. 4. Application (1) This Act shall apply to matters relating to access to information, protection of privacy of information and processing and storage of data wholly or partly by automated means: and shall be interpreted as being in addition to and not in conflict or inconsistent with the Protection of Personal Information Act [Chapter 10:27]. By Laws.Africa and contributors. Licensed under CC-BY. Share widely and freely. 3

Select target paragraph3