Data Protection
No. 5/2021
3
Cap. 11:22
Interpretation
In this Act—
“child” means any person under the age of eighteen years;
“code of conduct” refers to the Data Use Charters drafted by the data controller
in order to institute the rightful use of IT resources, the Internet, and
electronic communications of the structure concerned, and which have
been approved by the Data Protection Authority;
“consent” refers to any manifestation of specific unequivocal, freely given,
informed expression of will by which the data subject or his or her legal,
judicial or legally appointed representative accepts that his or her data
be processed;
“critical database” means a computer data storage medium or any part thereof
which contains critical data;
“data” means any representation of facts, concepts, information, whether in text,
audio, video, images, machine-readable code or instructions, in a form
suitable for communications, interpretation or processing in a computer
device, computer system, database, electronic communications network
or related devices and includes a computer programme and traffic data;
“data controller” or “controller”—
(a) refers to any natural person or legal person who is licensable by the
Authority;
(b) includes public bodies and any other person who determines the
purpose and means of processing data;
“data controller’s representative” or “controller’s representative” refers to any
natural person or legal person who performs the functions of the data
controller in compliance with obligations set forth in this Act;
“Data processor” refers to a natural person or legal person, who processes data
for and on behalf of the controller and under the controller’s instruction,
except for the persons who, under the direct employment or similar
authority of the controller, are authorised to process the data;
“Data Protection Authority” or “Authority” refers to Postal and
Telecommunications Regulatory Authority of Zimbabwe established in
terms of section 5 of the Postal and Telecommunications Act [Chapter
12:05];
“data protection officer” or “DPO” refers to any individual appointed by the
data controller and is charged with ensuring, in an independent manner,
compliance with the obligations provided for in this Act;
“data subject” refers to an individual who is an identifiable person and the
subject of data;
“disproportionate effort” means effort that is so labour intensive as to consume
a lot of time, money and manpower resources;
“electronic communications network” means any electronic communication
infrastructure and facilitie used for the conveyance of data;
“genetic data: refers to any personal information stemming from a
Deoxyribonucleic acid (DNA) analysis;
“health professional” refers to any individual determined as such in terms of
the Health Professions Act [Chapter 27:19];
“identifiable person” means a person who can be identified directly or indirectly,
in particular by reference to an identification number or to one or more
44
DISTRIBUTED BY VERITAS
e-mail: veritas@mango.zw; website: www.veritaszim.net
Veritas makes every effort to ensure the provision of reliable information,
but cannot take legal responsibility for information supplied.