Common Law with Mike Murenzvi
“Every right implies a responsibility; Every opportunity, an obligation, Every possession, a duty.” ~ John D. Rockefeller
In the last article we looked at data controllers being persons, or organisations that capture people’s personal information with the intent of processing it in one way or another. Whether it’s employee, membership, occupancy, or any other data, as long as there is a processing element to it, they must be registered. Data controllers are registered to create a fully binding legal obligation between them, the Data Protection Authority (DPA), and the people whose data they process (data subjects) on control and security of that data. Some categories of data processors are exempt from registering. These are mainly people operating for personal, family, or household affairs, and those whose data subjects are less than 50.
In this article we now look at the obligations placed on data controllers, and the rights of data subjects.
Obligations of a data controller
SI 155 of 2024, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 (SI 155/2024) places certain obligations on data controllers as custodians and processors of people’s personal identifiable information.
Providing continuous professional development for the DPO for his/her continued certification: The DPO, as will be more fully explained, needs to keep up with constantly updated principles, methods, and tools of data protection to do their job properly. The onus is, rightly or wrongly, placed on the data controller to ensure that the DPO gets that regular training.
Notifications to DPA; The data controller must notify the DPA of any of the following events or changes:
- All processing activities performed on personal information. This is done at the registration of the data controller. This is more of a generalised statement of what they do with the information they collect. Whether it’s payroll processing, banking, processing of criminal records, or anything else.
- Any modification of personal information collected indirectly from data subjects. This is simply, any changes to information collected from data subjects.
- Any intention to transfer or share information of data subjects outside Zimbabwe. This can be done directly or indirectly, and both must be reported. When you store information on “the cloud” or online, you need to know where the ultimate server hosting that information is. For most generally available systems, those servers are hosted outside Zimbabwe. In some cases, you may require use of specialised software or the assistance of certain organisations to work on the information and make it usable for whatever purpose you use it for and these organisations may be based outside Zimbabwe.
- Any processing which involves biometric and genetic data of data subjects. Think DNA testing, any form of medical lab test, biometric voter registration, getting your fingerprints taken and verified for criminal record verification, or simply getting an ID or passport. Genetic and biometric data is as personal as information can get. There is no way of faking that information or confusing one person with another based on it.
A data controller shall not subject a data subject to a decision based solely on automatic processing which produces legal effects concerning him or her without the consent of that data subject or based on a provision established by law. Automated processes like credit checks or criminal record checks can have legal implications on a person. These processes are either statutory – governed by law – or are part of vetting processes by banks or employers, in which case the person is now supposed to give express written consent for them to happen.
A data controller shall:
- be accountable for his or her representative, agent or assignee, data processor, recipient, data protection officer who contravenes the provisions of these regulations and the Act. Whatever an employee, agent, or representative of the data controller does is in the name of the data controller. If it is outside the law, the data controller gets charged.
- take all the appropriate technical and organisational measures to safeguard the security, integrity and confidentiality of personal information which must ensure an appropriate level of security. It’s the data controller’s responsibility to keep all personal information that they have collected and processed safe and secure.
- be responsible for taking all the necessary measures and controls to comply with the principles and obligations set out in these regulations and the Act. The data controller shall have policies and procedures to ensure that everything they do is above board and within the legal framework.
- put measures in place to facilitate the exercise of rights of data subjects under the Act. Every data subject has rights over the use, security, and continued maintenance of their information by a data controller. It is the data controller’s job to ensure that those rights are not violated.
- process personal information of physically, mentally or legally incapacitated data subjects through a parent or guardian or as provided for by the law or as directed by a court of competent jurisdiction. People who don’t have the legal capacity to consent either have parents, guardians, or other legally appointed people to handle their affairs. A data controller must ensure that there are clear steps to identify these people before collecting and processing the information.
- enter into a written data processing agreement or contract or legal instrument with a data processor which ensures that a data processor maintains all necessary security measures to safeguard personal information of data subjects. A data processor is a person or organisation that processes data at the request of the data controller. An example is a payroll processing company. An employer may not have the skills to process their payroll themselves so, they may engage the services of a payroll processor. This payroll processor is a “data processor” for these regulations. There must be a clear and binding agreement between the data controller and the data processor to ensure that the information is still safe, secure, private, and within the parameters of the agreed processes.
Personal information relating to children requires special attention and procedures that require a parent or legal guardian to consent to collection and processing. Children’s rights supersede most other rights and, therefore, data controllers and processors must implement risk identification and mitigation strategies specifically for children’s information.
In the next article we delve into a special group of people known as Data Processing Officers. They are the registered people on the ground who carry joint accountability to implement all these obligations.
_______________________
Mike Murenzvi writes in his personal capacity and his views are not associated with any organisation he is, or maybe, affiliated with.


























