Data Protection
No. 5/2021
Cap. 11:22
(b) health information about an individual;
(c) genetic information about an individual; or
(d) any information which may be considered as presenting a major
risk to the rights of the data subject;
“third party” refers to any natural or legal person or organisation other than
the data subject, the controller, the processor and anyone who, under the
direct authority of the controller or the processor, is authorised to process
the data;
“transborder flow” refers to international flows of data by the means of
transmission including data transmission electronically or by satellite;
“whistleblowing” refers to legal provisions permitting individuals to report
the behaviour of a member of their organisation which, they consider
contrary to a law or regulation or fundamental rules established by their
organisation.
4
Application
(1) This Act shall apply to matters relating to access to information, protection of privacy of information and processing and storage of data wholly or partly by
automated means: and shall be interpreted as being in addition to and not in conflict
or inconsistent with the Protection of Personal Information Act.
(2) Subject to subsection (1) this Act shall be applicable—
(a) to the processing of data carried out in the context of the effective and
actual activities of any data controller;
(b) to the processing and storage of data by a controller who is not permanently
established in Zimbabwe, if the means used, whether electronic or otherwise
is located in Zimbabwe, and such processing and storage is not for the
purposes of the mere transit of data through Zimbabwe.
(3) In the circumstances referred to in subsection (2)(b), the controller shall
designate a representative established in Zimbabwe, without prejudice to legal
proceedings that may be brought against the controller.
PART II
Data Protection Authority
5
Designation of Postal and Telecommunications Regulatory Authority
as Data Protection Authority
The Postal and Telecommunications Regulatory Authority established in terms
of the Postal and Telecommunications Act [Chapter 12:05] is hereby designated as the
Data Protection Authority.
6
Functions of Data Protection Authority
(1) The Authority shall perform the following functions—
(a) to regulate the manner in which personal information may be processed
through the establishment of conditions for the lawful processing of data;
(b) to promote and enforce fair processing of data in accordance with this
Act;
(c) to issue its opinion either of its own accord, or at the request of any person
with a legitimate interest, on any matter relating to the application of the
46
DISTRIBUTED BY VERITAS
e-mail: veritas@mango.zw; website: www.veritaszim.net
Veritas makes every effort to ensure the provision of reliable information,
but cannot take legal responsibility for information supplied.