Data Protection in Zimbabwe

Security in Zimbabwe

Section 13 of the Act states that Data controllers are responsible for processing personal information lawfully, fairly, and transparently, and for taking all necessary measures to comply with the Act and Regulations.

Data controllers must take appropriate technical and organizational measures to protect personal data from negligent or unauthorized destruction, loss, alteration, access, or processing.

Security measures must ensure an appropriate level of security considering technological development, implementation costs, the nature of the data, and potential risks to the data subject.

The Authority may issue information security standards for processing activities.

Data controllers must appoint data processors who provide sufficient guarantees regarding technical and organizational security measures and must enter into a written contract or legal instrument with the processor ensuring security measures are maintained.

Data controllers must take all appropriate technical and organizational measures to safeguard data security, integrity, and confidentiality, ensuring an appropriate level of security.

Technical and organizational security measures include:

  • Conducting risk assessments;
  • Developing and implementing organizational policies;
  • Implementing appropriate physical and technical measures for all data phases;
  • Data controllers and processors may implement additional security measures depending on the circumstances and risks associated with the processing.

Continue reading

  • no results

Previous topic
Back to top