Zimbabwe Data Protection Act (2021)
Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per Zimbabwe Data Protection Act (2021): Breach and Enforcement. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for ZIMBABWE-5
- see authoritative source for detailed gap analysis
Governance
Per Zimbabwe Data Protection Act (2021): DPO and Governance. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for ZIMBABWE-4
- see authoritative source for detailed gap analysis
Rights
Per Zimbabwe Data Protection Act (2021): Rights and Notice. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for ZIMBABWE-2
- see authoritative source for detailed gap analysis
Scope
Per Zimbabwe Data Protection Act (2021): Scope and Lawful Basis. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for ZIMBABWE-1
- see authoritative source for detailed gap analysis
Security
Per Zimbabwe Data Protection Act (2021): Security and Cross-Border. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for ZIMBABWE-3
- see authoritative source for detailed gap analysis
Zimbabwe DPA: Data Subject Rights
Provide data subjects with mechanisms to access, rectify, erase, restrict, object to processing and obtain copies of their personal information, fulfilling requests without undue delay and within statutory timeframes set by POTRAZ.
- Data subject rights request intake form and tracker
- Identity verification procedure for requestors
- Response templates covering each right with citation to the Act
- Monthly metrics on volume, type and turnaround of requests
- No verified channel beyond a generic info inbox
- Inconsistent response timelines across business units
- Missing audit trail of what was disclosed to each requester
Provide data subjects with the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, and offer meaningful human review where such processing occurs.
- Inventory of automated decision systems and their effect on data subjects
- Human review procedure for adverse automated decisions
- Transparency notice describing the logic involved
- Audit log of override decisions taken by human reviewers
- Credit or fraud models with no documented human review path
- Vague transparency wording that does not describe model inputs
- No re-training governance to prevent drift and discrimination
Apply additional safeguards when processing personal information of children and other vulnerable persons, including age appropriate consent flows, parental authorisation where required and limits on profiling and advertising.
- Age gating implementation evidence
- Parental consent capture and verification logs
- Marketing exclusion controls for minors
- DPIA covering services likely to be accessed by children
- Self declaration with no verification of parental authority
- No separate consent flow for under sixteens
- Behavioural advertising defaults on for all users
Zimbabwe DPA: Governance and Accountability
Appoint a Data Protection Officer where the entity is a public body, processes sensitive information at scale or carries out regular and systematic monitoring, with the DPO position resourced, independent and reachable by data subjects and POTRAZ.
- DPO appointment letter with reporting line to senior management
- DPO job description listing statutory tasks under the Act
- Published DPO contact email and physical address
- Annual DPO activity report submitted to the board
- DPO role bolted onto the head of IT creating conflict of interest
- No published contact channel for data subjects
- DPO without sufficient budget or training
Maintain written records of all processing activities, including categories of data subjects, categories of personal information, purposes, recipients, retention periods and security measures, available for inspection by POTRAZ on request.
- Records of processing activities register in tooling or spreadsheet
- Quarterly review attestation by business process owners
- Mapping between RoPA entries and supporting contracts
- RoPA stale and decoupled from actual system inventory
- No retention period specified per processing activity
- Missing entries for HR and contractor data flows
Carry out a Data Protection Impact Assessment for processing operations that are likely to result in a high risk to the rights and freedoms of data subjects, including large scale processing, profiling and processing of sensitive categories.
- DPIA template aligned to the Act and POTRAZ expectations
- Completed DPIA records for high risk processing
- Sign off by DPO and project sponsor
- Consultation evidence with POTRAZ where residual risk remains
- DPIA started after go-live rather than at design stage
- Risk treatment actions without owners or dates
- No threshold rules to decide when a DPIA is required
Provide internal and external channels for staff and contractors to report suspected breaches of the Act without fear of reprisal, with protection against retaliation and a documented investigation procedure.
- Whistleblowing policy covering data protection concerns
- Anonymous reporting channel evidence
- Investigation procedure with DPO involvement
- Annual report to the board on reports received and outcomes
- Channel exists for fraud but not for privacy issues
- No separation between whistleblowing investigations and HR cases
- Lack of training on how to raise concerns
Train all personnel who handle personal information on their obligations under the Act, with role specific modules for high risk functions such as customer service, HR, marketing and engineering, and refresh the training at least annually.
- Training curriculum with module mapping to the Act
- Completion records for the past twelve months
- Phishing and social engineering simulation results
- New starter induction checklist including privacy module
- Training generic and not tailored to Zimbabwean context
- Completion rates not tracked for contractors
- Refresher cadence longer than twelve months
Zimbabwe DPA: Lawful Basis and Registration
Establish and document a lawful basis for every processing activity involving personal information of data subjects in Zimbabwe, with valid, specific, informed and freely given consent where consent is the chosen basis, recorded in a manner that can be demonstrated to POTRAZ on request.
- Lawful basis register mapping each processing activity to a section of the Act
- Consent capture screenshots and timestamps from all customer-facing channels
- Consent withdrawal workflow documentation and audit trail
- Privacy notice text shown to data subjects at the point of collection
- Standard operating procedure for re-papering historical consents
- Pre-ticked consent boxes that fail the freely given standard
- No granularity between marketing, analytics and core service consents
- Inability to evidence consent for legacy records collected before 2021
Register the entity as a data controller with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) in its capacity as Data Protection Authority, declaring categories of personal information, purposes of processing and security measures applied, and keep the registration current.
- Submitted POTRAZ controller registration form and acknowledgment
- Annual renewal correspondence and proof of fee payment
- Internal change log triggering re-registration when scope shifts
- Designated controller representative appointment letter
- Operating in Zimbabwe through a local branch without separate registration
- Stale registration that does not reflect new product lines
- No accountable owner for monitoring POTRAZ updates
Apply heightened safeguards when processing sensitive information including health, genetic, biometric, racial, political, religious, trade union, sexual life and criminal data, including explicit consent or another specific statutory ground and a documented necessity test.
- Sensitive data inventory with justification per category
- Explicit consent forms or statutory ground citations
- Necessity and proportionality assessment for each sensitive use case
- Additional access control matrix for sensitive data stores
- Treating biometric authentication data as ordinary credentials
- No separate consent for sensitive categories embedded in T&Cs
- Missing necessity test for health data collection by non-health entities
Zimbabwe DPA: Marketing, Complaints and Enforcement
Send unsolicited electronic communications for direct marketing purposes only with the prior consent of the recipient or under a tightly scoped soft opt in, with clear sender identification and a working unsubscribe mechanism in every message.
- Marketing consent capture screenshots and timestamp logs
- Suppression list management procedure and tooling export
- Sample of recent marketing emails showing identification and unsubscribe link
- Unsubscribe processing audit trail
- Reusing scraped contact lists with no consent provenance
- Unsubscribe processed manually with delays of several days
- No separation between transactional and marketing streams
Provide data subjects with a clear complaints channel that escalates to POTRAZ if unresolved, and cooperate fully with the Authority during investigations, audits and information requests, including providing access to records and systems.
- Complaints handling procedure with stage gates and timelines
- Complaints register and root cause analysis
- POTRAZ correspondence file for active and closed matters
- Audit cooperation protocol approved by legal
- Complaints absorbed into general customer service queues
- No defined escalation when a complainant mentions POTRAZ
- Limited record retention for closed complaints
Maintain readiness for enforcement action by POTRAZ including production of records, ability to demonstrate accountability and a managed response to compliance orders, fines and potential criminal liability for officers under the Act.
- Enforcement response playbook with legal and communications steps
- Mock audit results and remediation tracking
- Director and officer briefing pack on personal liability
- Insurance evidence covering regulatory defence costs
- No single owner for regulator correspondence
- Limited evidence library that cannot be produced quickly
- Officers unaware of personal liability exposure
Zimbabwe DPA: Security and Breach Notification
Implement appropriate technical and organisational measures proportionate to the risk of processing, including access control, encryption in transit and at rest, logging, secure development, vulnerability management and physical security of facilities holding personal information.
- Information security policy aligned to ISO 27001 control set
- Encryption key management procedure and KMS configuration export
- Vulnerability scan and penetration test reports for the last twelve months
- Access review evidence for systems holding personal information
- Encryption claimed in policy but not enforced at the database tier
- No formal patch cadence for non-production environments
- Penetration testing limited to the perimeter
Detect, assess and notify POTRAZ and affected data subjects of personal information breaches that pose a risk of harm, within the timeframe specified by the Authority, providing details of the nature of the breach, the data involved and mitigation steps.
- Breach response runbook with POTRAZ notification template
- Breach register covering the last twenty four months
- Tabletop exercise minutes and after action review
- Customer notification samples and dispatch logs
- Reliance on the cloud provider to detect breaches without independent monitoring
- No risk scoring criteria to decide notification thresholds
- Notification template missing statutory content elements
Where designated as critical information infrastructure, comply with additional cybersecurity duties under the Act including incident reporting to the relevant authority, regular risk assessment and adoption of recognised security standards.
- Designation letter and scope of critical infrastructure
- Incident notifications to the cybersecurity authority
- Annual cybersecurity risk assessment and treatment plan
- Alignment statement to recognised standards such as ISO 27001 or NIST CSF
- Critical infrastructure status unknown across the entity
- Cyber incident reporting confused with personal data breach reporting
- Standards alignment claimed without supporting gap analysis
Zimbabwe DPA: Transfers, Processors and Retention
Only transfer personal information outside Zimbabwe to jurisdictions providing an adequate level of protection or under approved safeguards such as contractual clauses, with prior authorisation from POTRAZ where required by the Act and supporting regulations.
- Transfer impact assessment for each non-Zimbabwe destination
- Executed data transfer agreements with overseas processors
- POTRAZ authorisation letters where applicable
- Map of personal data flows showing source, destination and legal basis
- Cloud workloads in regions with no documented adequacy assessment
- Sub-processor onward transfers not contractually controlled
- No periodic refresh of transfer impact assessments
Engage processors only under written contracts that bind them to process personal information solely on documented instructions, apply security measures, assist with data subject requests and notify breaches without delay.
- Data processing addenda for all in scope vendors
- Vendor risk assessment questionnaires and scoring
- Sub-processor approval workflow and current register
- Annual processor assurance reports such as SOC 2 or ISO 27001
- Master service agreements without a data processing schedule
- No record of sub-processor changes communicated to the controller
- Vendor inventory missing the small SaaS tools used by marketing
Retain personal information only for as long as necessary for the declared purposes, applying documented retention schedules and secure disposal techniques including cryptographic erasure, secure wipe and physical destruction of media.
- Retention schedule mapped to system tables and document stores
- Disposal certificates from media destruction vendors
- Quarterly proof of automated deletion jobs
- Backup expiry configuration and verification
- Backups retained indefinitely overriding production deletions
- No defined schedule for unstructured shared drives
- Disposal evidence not collected from contract printers
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.