HomeAfrica

Legal Discussions with Vengai Madzima: Data Protection Compliance in Zimbabwe

Africa 1 source 1 country 🔦 Under-reported 20m ago

Vengai Madzima, the Senior Partner at Madzima Chidyausiku Museta Legal Practitioners (MCM Legal), to discuss with us legal issues that affect Zimbabweans. The discussions are of a general nature, and those seeking specific legal advice should contact their lawyer. This week we want to discuss compliance with data protection laws: who they apply to and when companies have to comply.

We discussed data protection extensively in one of our previous articles; if I am not mistaken, that was around the period the Statutory Instrument was published. However, I will reiterate that the right to privacy and data protection remains a constitutional right. If we understand this premise, then the compliance requirements will become more palatable.

That being said, all entities that handle personal information relating to customers, suppliers, employees or members of the public, be it government agencies, businesses, universities or financial institutions, are supposed to be compliant with the Cyber and Data Protection Act {Chapter 12:07} and the Cyber and Data Protection {Licensing of Data Controllers and Appointment of Data Protection Officers} Regulations. So, entities that collect personal information, which may include, but is obviously not limited to, identity details, financial information, health status, employment data et cetera must ensure that their compliance position with our laws is in order before 1 September 2026 I say so because POTRAZ, that is the Post and Telecommunications Regulatory Authority of Zimbabwe, announced that from 1 September, 2026 there will be mandatory data protection inspections and assessments on entities that collect such personal data and are not exempt. Reporter: What can an entity which potentially falls within the provisions of a data controller do to ensure compliance?

VM: Once an entity establishes that it is a data controller and does not operate within the exempted data processing activities, it is required to obtain a data controller licence; these licences vary depending on the volume of data handled. However, the data controller licences are renewed annually. Data controllers are also expected to implement systems that ensure that personal data is always protected.

In the event of a breach of this fundamental right to privacy, the …

Summary from source
Read the full story at the source NewZimbabwe.com (Harare, Zimbabwe) · ZW
Get the news on TelegramTop stories & under-reported picks, straight to your feed — free. Join →