Data Protection in Zimbabwe

Data protection officers in Zimbabwe

Data Protection Officers Data controllers are required to appoint a data protection officer ("DPO") and notify the Authority in writing using Form DP2. The Authority must also be notified of any changes to the DPO's contact information, dismissal, or resignation. DPOs must have the following qualifications:

  • Skill, qualifications, or experience in data science, data analytics, information security systems, information systems audit, law, audit, or any other relevant qualification;
  • Knowledge of national data protection laws and practices;
  • Understanding of the data controller’s business operations and processing activities;
  • Certification through a course approved by the Authority DPOs have the following duties:
    • Monitoring compliance with the Act, the Regulations, and organizational data protection policies;
    • Managing internal data protection activities;
    • Raising awareness of data protection;
    • Training staff on data protection;
    • Conducting internal data protection compliance audits;
    • Dealing with requests from the Authority and data subjects;
    • Advising employees on their data protection obligations;
    • Advising on and monitoring data protection impact assessments;
    • Working with the Authority; and
    • Acting as the contact point for data subjects.

Continue reading

  • no results

Previous topic
Back to top