Cyber Security and Data Protection
(3) The register shall be available for inspection by members of the public, in
the manner determined by the Authority.
5
(4) In case of the processing of data exempted from notification by this Act, the
Authority may, either by virtue of its office or at the data subject’s request, impose upon
the controller the obligation to disclose to the data subject all or part of the information
mentioned in section 16(1).
24
Accountability
(1) The data controller shall—
(a) take all the necessary measures to comply with the principles and
obligations set out in this Act; and
(b) have the necessary internal mechanisms in place for demonstrating such
compliance to both the data subjects and the Authority in the exercise of
its powers.
10
PART VII
Data Subject
15
25
Decision taken on basis of Automatic Data Processing
(1) The data subject shall have the right not to be subject to a decision based
solely on automated processing, including profiling, which produces legal effects
concerning him or her or similarly significantly affects him or her.
20
(2) The right referred to in subsection (1) shall not be applicable if the decision
based solely on automated processing is taken on the basis of the data subject having
consented to such decision or is based on a provision established by law.
26
25
Where the data subject is a child, his or her rights pursuant to this law may be
exercised by his or her parents or legal guardian.
27
30
Representation of data subject who is a child
Representation of physically, mentally or legally incapacitated data
subjects
(1) A data subject who is physically, mentally or legally incapable of exercising
the rights given under this Act and who is not subject to the provisions of section 27,
may exercise such rights through a parent or guardian or as provided for by law or as
designated by a Court of competent jurisdiction.
(2) Incapacity as referred to in subsection (1) shall be proven by a physician
or a person legally competent to do so.
PART VIII
35
Transborder Flow
28 Transfer of personal information outside Zimbabwe
40
(1) Subject to the provisions of this Act, a data controller may not transfer
personal information about a data subject to a third party who is in a foreign country
unless an adequate level of protection is ensured in the country of the recipient or within
the recipient international organisation and the data is transferred solely to allow tasks
covered by the competence of the controller to be carried out.
15