Cyber Security and Data Protection (2) The adequacy of the level of protection afforded by the third country or international organisation in question shall be assessed in the light of all the circumstances surrounding a data transfer operation or set of data transfer operations; with particular consideration being given to the nature of the data, the purpose and duration of the proposed processing operation or operations, the recipient third country or recipient international organisation, the laws relating to data protection in force in the third country or international organisation in question and the professional rules and security measures which are complied with in that third country or international organisation. (3) The Authority shall lay down the categories of processing operations for which and the circumstances in which the transfer of data to countries outside the Republic of Zimbabwe is not authorised. 29 10 Transfer to a country outside the Republic of Zimbabwe which does not assure an adequate level of protection (1) A transfer or a set of transfers of data to a country outside the Zimbabwe which does not assure an adequate level of protection may take place in one of the following cases— (a) the data subject has unambiguously given his or her consent to the proposed transfer; (b) the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken in response to the data subject’s request; (c) the transfer is necessary for the conclusion or performance of a contract concluded or to be concluded between the controller and a third party in the interest of the data subject; (d) the transfer is necessary or legally required on important public interest grounds, or for the establishment, exercise or defense of legal claims; (e) the transfer is necessary in order to protect the vital interests of the data subject; (f) the transfer is made from a register which, according to acts or regulations, is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, to the extent that the conditions laid down in law for consultation are fulfilled in the case at hand. PART IX Code of Conduct 30 5 15 20 25 30 35 Code of Conduct (1) The Authority shall provide guidelines and approve codes of conduct and ethics governing the rules of conduct to be observed by data controllers and categories of data controllers. 40 (2) In effecting (1) above, the Authority shall consider trade associations and other bodies representing other categories of controllers who have national codes or have the intention of amending or extending existing national codes and allow them to submit such codes for the approval of the Authority. (3) The Authority in considering codes of conduct for approval, shall ascertain, among other things, whether the Codes submitted comply with the provisions of this 16 45

Sélectionner le paragraphe cible3