0% found this document useful (0 votes)
10 views8 pages

Automated Decision-Making Regulations

The document outlines key issues related to automated decision-making and transborder data transfer under Zimbabwe's Cyber and Data Protection Regulations. It emphasizes the prohibition of solely automated decisions affecting individuals, the need for adequate protection when transferring data internationally, and the rights of data subjects, including the right to be informed, access, and object to processing. Additionally, it details the responsibilities of Data Protection Officers and the mandatory timelines for data breach notifications.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views8 pages

Automated Decision-Making Regulations

The document outlines key issues related to automated decision-making and transborder data transfer under Zimbabwe's Cyber and Data Protection Regulations. It emphasizes the prohibition of solely automated decisions affecting individuals, the need for adequate protection when transferring data internationally, and the rights of data subjects, including the right to be informed, access, and object to processing. Additionally, it details the responsibilities of Data Protection Officers and the mandatory timelines for data breach notifications.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

DATA PROTECTION NOTES

ALL ISSUES RELATED TO AUTOMATED DECISION MAKING?

Drawing on the sources provided, here are the key issues related to automated
decision-making under the Cyber and Data Protection Regulations (S.I. 155 of 2024)
and the Cyber and Data Protection Act [Chapter 12:07]:

 General Prohibition: Generally, a data controller shall not subject a data


subject to a decision based solely on automated processing, including
profiling, which produces legal effects concerning them or similarly
significantly affects them [11, s 10(3), 102, s 25(1)]. This highlights a
fundamental principle that individuals should not be solely subjected to decisions
with significant consequences based purely on automated algorithms.
 Exceptions to the Prohibition: This prohibition on solely automated decision-
making has specific exceptions [103, s 25(2), 11, s 10(3)]:
o If the decision is taken on the basis of the data subject having given
their consent to such decision [103, s 25(2)]. The consent must meet the
requirements for valid consent as defined in the Act [50, s 3].
o If the decision is based on a provision established by law [103, s
25(2), 11, s 10(3)]. This means that if legislation explicitly allows for
certain decisions to be made through automated means, then the
prohibition does not apply.
 Specific Protections for Children: The regulations place a particular emphasis
on protecting children from automated decision-making. No data controller
shall subject children’s data to automated decision making that has the
effect of affecting the children’s rights [15, s 10(5)(f)]. This implies a stricter
stance on automated decision-making concerning children compared to adults,
potentially due to their vulnerability.
 Relationship to Data Processing: Automated decision-making is a specific
form of data processing, which is broadly defined in the Act [57, s 3]. Therefore,
general obligations related to data processing, such as the need for licensing in
certain circumstances [3, s 3], the principles of fair and lawful processing [68, s
8], and the implementation of appropriate security measures [24, s 16, 91, s 18],
would also apply when automated decision-making is involved.
 Notification to the Authority: While the sources don't explicitly state that
automated decision-making processes require separate notification beyond
general processing activities, the obligation to notify the Authority of all
processing activities performed on personal information [11, s 10(2)(a)]
and prior to any wholly or partly automated operation [93, s 20(1)] would
likely encompass automated decision-making systems. The notification would
need to detail the nature and purpose of such processing.
 Data Subject Rights: The right not to be subject to solely automated decision-
making is a key right of data subjects [102, s 25(1)]. This right, along with other
rights such as the right to be informed [84, s 14(a)], the right to access [84, s
14(b)], and the right to object to processing [84, s 14(c)], aims to provide
individuals with control and transparency over how their data is used in decision-
making processes.

In essence, the legal framework in the sources acknowledges the potential impact of
automated decision-making on individuals and seeks to regulate its use, particularly
when it leads to legally significant or similarly impactful outcomes. Consent and legal
basis are key justifications for automated decision-making, and special attention is given
to protecting children from its potential adverse effects on their rights.
ZIMBABWE TRANSBORDER DATA TRANSFER TO PROCESSORS

Drawing on the provided sources and our conversation history, here's a summary of the
regulations concerning transborder data transfer to processors in Zimbabwe:

The Cyber and Data Protection Act [Chapter 12:07] and the Cyber and Data Protection
(Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations,
2024, address the transfer of personal information outside Zimbabwe. While they don't
have a section explicitly titled "transborder data transfer to processors," the general
principles and requirements for transferring data internationally apply regardless of
whether the recipient is another controller or a processor.

Here are the key points:

 General Restriction on Transfers: A data controller may not transfer


personal information about a data subject to a third party who is in a
foreign country unless an adequate level of protection is ensured in the
country of the recipient [105, s 28(1)]. This applies to any third party, which
would include a data processor located outside Zimbabwe. The data must also be
transferred solely to allow tasks covered by the competence of the
controller to be carried out [105, s 28(1)].
 Assessment of Adequate Protection: The adequacy of the level of
protection afforded by the third party or international organisation shall
be assessed in light of all the circumstances surrounding a data transfer
operation [105, s 28(2)]. This assessment considers factors such as the nature of
the data, the purpose and duration of processing, the recipient, the data
protection laws in force in the recipient country, and the professional rules and
security measures complied with there [105, s 28(2)].
 Data Processing Agreements: When a data controller engages a data
processor (whether inside or outside Zimbabwe), they must enter into a written
data processing agreement or contract or legal instrument with the data
processor [13, s 10(4)(f), 93, s 18(4), 93, s 18(5)]. This agreement must ensure
that the data processor maintains all necessary security measures to
safeguard personal information of data subjects [13, s 10(4)(f), 93, s 18(5)]
and provides sufficient guarantees regarding the technical and
organisational security measures employed to protect the data [93, s
18(4)].
 Notification of Intention to Transfer: A data controller is obligated to notify
the Authority of any intention to transfer or share information of a data
subject outside Zimbabwe [11, s 10(2)(c)]. This implies that the Authority
needs to be informed before any such transfer to a processor occurs.
 Transfers to Countries Without Adequate Protection: A transfer of data to a
country outside Zimbabwe that does not ensure an adequate level of protection
can occur only under specific conditions [107, s 29]:
o If the data subject has unambiguously given their consent to the
proposed transfer [107, s 29(a)].
o If the transfer is necessary for the performance of a contract between
the data subject and the controller or for pre-contractual measures at
the data subject's request [107, s 29(b)].
o If the transfer is necessary for the conclusion or performance of a
contract between the controller and a third party in the interest of
the data subject [108, s 29(c)].
o If the transfer is necessary or legally required on important public
interest grounds, or for the establishment, exercise, or defence of legal
claims [108, s 29(d)].
o If the transfer is necessary to protect the vital interests of the data
subject [108, s 29(e)].
o If the transfer is made from a public register under specific legal
conditions [108, s 29(f)].
 Authority's Power to Restrict Transfers: The Authority shall lay down the
categories of processing operations for which and the circumstances in
which the transfer of data to countries outside the Republic of
Zimbabwe is not authorised [106, s 28(3)]. This suggests that the Authority
has the power to further regulate and potentially restrict certain types of
international data transfers, including those to processors.

In summary, when a data controller in Zimbabwe intends to transfer personal data to a


processor located outside the country, they must ensure that the recipient country offers
an adequate level of data protection. If not, the transfer can only proceed if one of the
specific exceptions listed in the Act applies, such as obtaining the data subject's explicit
consent or if the transfer is necessary for contractual obligations in the data subject's
interest. Crucially, the data controller must also have a written agreement with the
foreign processor ensuring data security, and they are obligated to notify the Authority of
their intention to transfer data abroad [11, s 10(2)(c)]. The Authority also retains the
power to specify further restrictions on international data transfers [106, s 28(3)].

SUMMURIZE RIGHTS OF DATA SUBJECTS

Based on the sources and our conversation history, data subjects in Zimbabwe have the
following key rights:

 Right to be Informed: Data subjects have the right to be informed of the use
to which their personal information is to be put [84, s 14(a)]. When data is
collected directly from the data subject, the controller must provide specific
information, including the controller's identity and address, the purposes of
processing, the existence of the right to object to processing for direct marketing,
whether providing the information is compulsory, and other necessary details to
ensure fair processing [85, s 15(1)]. Similar information must be provided when
data is not collected directly from the data subject [87-88, s 16(1)].
 Right to Access: Data subjects have the right to access their personal
information in the custody of a data controller or data processor [84, s
14(b)].
 Right to Object: Data subjects have the right to object to the processing of
all or part of their personal information [84, s 14(c)]. Specifically, they have
the right to object, by request and free of charge, to the intended processing of
data relating to them if it is obtained for direct marketing purposes [86, s 15(1)(c),
88, s 16(1)(d)].
 Right to Correction (Rectification): Data subjects have the right to the
correction of false or misleading personal information [84, s 14(d), 83-84, s
13(f)]. Data controllers must take reasonable steps to ensure data is accurate and
up to date and to rectify inaccuracies without delay.
 Right to Deletion (Erasure): Data subjects have the right to the deletion of
false or misleading data about them [85, s 14(e)].
 Right Not to be Subject to Automated Decision-Making: Data subjects have
the right not to be subject to a decision based solely on automated
processing, including profiling, which produces legal effects concerning
them or similarly significantly affects them [102, s 25(1)]. This right has
exceptions if the decision is based on the data subject's consent or a provision
established by law [103, s 25(2)].

These rights aim to provide individuals with control over their personal data and ensure
that processing is conducted fairly and transparently. Data controllers are obligated to
put measures in place to facilitate the exercise of these rights by data subjects [13, s
10(4)(d)]. When dealing with children's data, their rights may be exercised by their
parents or legal guardians [103, s 26], and similar provisions exist for physically,
mentally, or legally incapacitated data subjects [104, s 27].

KEY TOP PRIORITIES OF A DATA PROTECTION OFFICER?

Drawing on the provided sources, the key top priorities of a Data Protection Officer (DPO)
in Zimbabwe can be summarised as follows:

 Monitoring Compliance: A primary priority of the DPO is monitoring


compliance with the Cyber and Data Protection Act [Chapter 12:07] and
the Cyber and Data Protection (Licensing of Data Controllers and
Appointment of Data Protection Officers) Regulations, 2024, as well as
with the data controller's own organisational data protection policies [20, s 14(a),
95, s 20(6)(a)]. This involves:
o Managing internal data protection activities [20, s 14(a)(i)].
o Raising awareness on data protection issues within the
organisation [20, s 14(a)(ii)].
o Training staff on data protection obligations and best practices
[20, s 14(a)(iii)].
o Conducting internal data protection compliance audits to ensure
adherence to the legal and policy frameworks [20, s 14(a)(iv)].
 Serving as a Point of Contact: The DPO acts as the main point of contact
for both the Data Protection Authority and data subjects regarding all
matters related to data protection [21, s 14(e), 21, s 14(f), 95, s 20(6)(b), 96, s
20(6)(c)]. This includes:
o Dealing with requests made to the data controller by the
Authority [21, s 14(b), 95, s 20(6)(b)].
o Addressing inquiries and requests from data subjects concerning
the processing of their data [21, s 14(f)].
o Working with the Authority in relation to the performance of its
functions concerning the data controller [21, s 14(e), 96, s 20(6)(c)].
 Providing Advice and Guidance: The DPO is responsible for advising the
data controller and its employees about their obligations to comply with
the Act and the regulations [21, s 14(c)]. This includes:
o Advising on and monitoring the implementation of data protection
impact assessments to identify and mitigate privacy risks [21, s
14(d)].
o Providing guidance on the appropriate technical and
organisational measures to safeguard the security, integrity, and
confidentiality of personal information [12, s 10(4)(b)].

In essence, the DPO's role is crucial in fostering a culture of data protection within the
organisation, ensuring adherence to the legal requirements, and facilitating
communication between the organisation, the regulatory authority, and data subjects.
Their priorities revolve around ensuring lawful and ethical data processing practices.

OUTLINE THE MANDATORY DATA BREACH NOTIFICATION TIMELINE.

Drawing on the provided sources, here is an outline of the mandatory data breach
notification timeline in Zimbabwe:

According to the Cyber and Data Protection (Licensing of Data Controllers and
Appointment of Data Protection Officers) Regulations, 2024:

 A data controller shall report personal data breaches to the Authority


within 24 hours of becoming aware of the breach affecting the data being
processed by the concerned data controller or data processor [26, s 17(1), 93, s
19].
 Personal data breaches shall be reported to the Authority by completing and
submitting a data breach notification form DP3 (Data Breach Notification
Form) specified in the Fourth Schedule [26, s 17(2)].
 Where the detected breach is likely to result in a high risk of adversely
affecting individuals’ rights and freedoms, the controller shall also
inform those data subjects within 72 hours [26, s 17(3)].

Additionally, the regulations specify further actions a data controller must take following
a data breach:

 A data controller shall ensure that there are robust breach detection,
investigation, and internal reporting procedures in place [27, s 17(4)(a)].
 A data controller must keep a record of all personal data breaches [27, s
17(4)(b)].
 The data controller is required to cooperate with the Authority in conducting
enquiries or investigations relating to data breaches [27, s 17(5)(a)].
 The data controller must respond to information requests on data breaches
within 14 days [27, s 17(5)(b)].
 The data controller must conclude the data breach investigations and
submit a report within 21 days from the date of notification [27, s 17(5)
(c)].

In summary, the key mandatory timelines are:

 Notification to the Authority: within 24 hours of becoming aware of the


breach.
 Notification to Data Subjects (if high risk): within 72 hours of detecting a
breach likely to highly impact their rights and freedoms.
 Response to Authority's information request: within 14 days.
 Submission of breach investigation report: within 21 days from the date
of initial notification.

GROUNDS FOR PROCESSING PII

Drawing on the provided sources, the grounds for processing personal data in Zimbabwe
are outlined in both the Cyber and Data Protection Act [Chapter 12:07] and the Cyber
and Data Protection (Licensing of Data Controllers and Appointment of Data Protection
Officers) Regulations, 2024.
According to the Cyber and Data Protection Act [Chapter 12:07]:

 Generally, personal information may only be processed if the data subject


or a competent person (for a child) consents to the processing [69, s
10(1)]. This consent, for adult natural persons or those with legal capacity, may
be implied [70, s 10(2)].
 However, the processing of non-sensitive data is permitted without the data
subject's consent under specific circumstances [70, s 10(3)]:
o Where it is material as evidence in proving an offence [70, s 10(3)
(a)].
o For compliance with a legal obligation to which the controller is
subject [70, s 10(3)(b)].
o For protecting the vital interests of the data subject [70, s 10(3)(c)].
o For performing a task carried out in the public interest or in the
exercise of official authority vested in the controller or a third party [70, s
10(3)(d)].
o For promoting the legitimate interests of the controller or a third
party, unless these interests are overridden by the interests or
fundamental rights and freedoms of the data subject [71, s 10(3)(e)]. The
Authority may specify when this condition is met [71, s 10(4)].
 The processing of sensitive data is generally prohibited unless the data subject
has given explicit consent in writing [71, s 11(1)]. This consent can be
withdrawn at any time, freely and without explanation [72, s 11(2)]. The Authority
can determine circumstances where even consent cannot lift this prohibition [72,
s 11(3)].
 There are exceptions to the requirement for written consent for sensitive data
processing [73, s 11(5)]:
o When necessary to carry out obligations and specific rights in
employment law [73, s 11(5)(a)].
o To protect the vital interests of the data subject or another person
when the data subject cannot give consent [73, s 11(5)(b)].
o Carried out by non-profit organisations with a political,
philosophical, religious, health-insurance, or trade-union purpose,
relating solely to their members or regular contacts, and not disclosed to
third parties without consent [73, s 11(5)(c)].
o Necessary to comply with national security laws [74, s 11(5)(d)].
o Necessary, with appropriate guarantees, for the establishment,
exercise, or defence of legal claims [74, s 11(5)(e)].
o Relating to data that has been made public by the data subject [74, s
11(5)(f)].
o Necessary for the purposes of scientific research, subject to conditions
specified by the Authority [74, s 11(5)(g)].
o Authorised by law or regulation for substantial public interest
reasons [75, s 11(5)(h)].
o Processing of data relating to sex life is authorised under specific
conditions involving evaluation, guidance, or treatment by recognised
associations with specific authorisation from a competent public body after
consulting the Authority [75, s 11(6), 76, s 11(7)].
 The processing of genetic data, biometric data, and health data is generally
prohibited unless the data subject has given written consent [77, s 12(1)].
This consent can be withdrawn at any time, freely and without reason [77, s
12(2)].
 Exceptions to the written consent requirement for genetic, biometric, and health
data include [77, s 12(3)]:
o Necessary to carry out specific obligations and rights in employment
law [77, s 12(3)(a)].
o Necessary to comply with national security laws [77, s 12(3)(b)].
o Necessary for the promotion and protection of public health,
including medical examination of the population [78, s 12(3)(c)].
o Required by law or equivalent legislative act for substantial public
interest reasons [78, s 12(3)(d)].
o Necessary to protect the vital interests of the data subject or
another person when the data subject cannot give consent [78, s 12(3)
(e)].
o Necessary for the prevention of imminent danger or the mitigation
of a specific criminal offence [79, s 12(3)(f)].
o Relating to data made public by the data subject [79, s 12(3)(g)].
o Necessary for the establishment, exercise, or defence of legal rights
[79, s 12(3)(h)].
o Required for scientific research [79, s 12(3)(i)].
o Necessary for preventive medicine, medical diagnosis, care or
treatment of the data subject or their relatives, or management of
health-care services in the data subject's interest, under the supervision
of a health professional [79, s 12(3)(j)].
 Health-related data can generally only be processed under the responsibility of
a health professional, unless the data subject has given written consent or it is
necessary for preventing imminent danger or mitigating a specific criminal
offence [80, s 12(4)].
 Health-related data may only be collected from other sources if the data subject
cannot provide it [80, s 12(6)].

The Cyber and Data Protection (Licensing of Data Controllers and Appointment
of Data Protection Officers) Regulations, 2024 also touch upon the processing of
data in relation to licensing requirements:

 No person shall process personal information for the purposes outlined


in subsection (2) of Section 3 unless they are licensed with the Authority
[3, s 3(1)]. These purposes include processing with the intention to:
o Decide the means, purpose, or outcome of the processing [3, s 3(2)
(a)].
o Decide what personal data should be collected [3, s 3(2)(b)].
o Decide which individuals to collect personal data from [3, s 3(2)(c)].
o Obtain a commercial gain or other benefit from the processing of
personal data [4, s 3(2)(d)].
 Exemptions from licensing are provided for data controllers processing
personal data for [9, s 8(1)]:
o Personal, family, or household affairs [9, s 8(1)(a)].
o Law enforcement [9, s 8(1)(b)] (though registration and compliance with
data protection principles are still required [9, s 8(2)]).
o Journalistic, historical, or archival purposes [9, s 8(1)(c)] (again,
registration and compliance are required [9, s 8(2)]).

In summary, the primary grounds for processing personal data are consent and
legitimate interest, with specific, stricter requirements and exceptions for sensitive,
genetic, biometric, and health data. Additionally, for certain commercial or benefit-
driven processing activities, a data controller licence is mandatory unless an
exemption applies.

Regulations are legally binding and require businesses to meet specific obligations.
Standards, while voluntary (unless ruled in a Regulation), often serve as benchmarks for
achieving industry-recognized quality and performance levels.

Guidelines provide recommended practices that businesses can voluntarily adopt.

NOTIFICATION OF DPA

- Within 14 days – on change of contact details of the DPO


- Notify in writing of the appointment of a DPO – DP2 Form
-

You might also like