Cyber Security and Data Protection (3) The register shall be available for inspection by members of the public, in the manner determined by the Authority. 5 (4) In case of the processing of data exempted from notification by this Act, the Authority may, either by virtue of its office or at the data subject’s request, impose upon the controller the obligation to disclose to the data subject all or part of the information mentioned in section 16(1). 24 Accountability (1) The data controller shall— (a) take all the necessary measures to comply with the principles and obligations set out in this Act; and (b) have the necessary internal mechanisms in place for demonstrating such compliance to both the data subjects and the Authority in the exercise of its powers. 10 PART VII Data Subject 15 25 Decision taken on basis of Automatic Data Processing (1) The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. 20 (2) The right referred to in subsection (1) shall not be applicable if the decision based solely on automated processing is taken on the basis of the data subject having consented to such decision or is based on a provision established by law. 26 25 Where the data subject is a child, his or her rights pursuant to this law may be exercised by his or her parents or legal guardian. 27 30 Representation of data subject who is a child Representation of physically, mentally or legally incapacitated data subjects (1) A data subject who is physically, mentally or legally incapable of exercising the rights given under this Act and who is not subject to the provisions of section 27, may exercise such rights through a parent or guardian or as provided for by law or as designated by a Court of competent jurisdiction. (2) Incapacity as referred to in subsection (1) shall be proven by a physician or a person legally competent to do so. PART VIII 35 Transborder Flow 28 Transfer of personal information outside Zimbabwe 40 (1) Subject to the provisions of this Act, a data controller may not transfer personal information about a data subject to a third party who is in a foreign country unless an adequate level of protection is ensured in the country of the recipient or within the recipient international organisation and the data is transferred solely to allow tasks covered by the competence of the controller to be carried out. 15

Select target paragraph3