COLUMN | Is there a ‘WhatsApp group’ law? Demystifying Data Controller Licencing

Common Law with Mike Murenzvi

“Relying on the government to protect your privacy is like asking a peeping tom to install your window blinds.”– John Perry Barlow

The Minister of Information Communication Technology, Postal and Courier Services, Tatenda Mavetera, recently generated a lot of noise regarding the topic of Data Controller licencing and how far the regulations reach.

The Minister posted on her social media that administrators of certain WhatsApp groups would need to register as data controllers, and that the licence fee ranges from US$50 to US$2,500. Naturally, this news was met with a lot of consternation and ridicule as it was interpreted in different ways. To make matters worse, she later posted another statement alleging misinterpretation and misinformation from certain quarters. This just added fuel to the fire.

Because of this, we need to look at the basics of the regulations that the Minister was referring to and get down to the true position of it all.

In an age where more and more of our interactions and personal information are online or in some electronic form, it has become increasingly necessary to have safeguards and rules for those who handle our information. While identity theft isn’t a big thing yet in Zimbabwe, no one really wants their personal information freely accessible to all and sundry. Those entities that collect it for one reason or another must keep it safe and use it only for agreed upon purposes.

The regulations

SI 155 of 2024, the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024, is a set of rules expanding on the requirements of the Cyber and Data Protection Act [Chapter 12:07].

The rules govern how entities and persons who process personal information to:

  1. decide the means, purpose, or outcome of the processing;
  2. decide what personal data should be collected;
  3. decide which individuals to collect personal data from;
  4. obtain a commercial gain or other benefit from the processing of personal data.

When you see those uses of personal information, you automatically think of government institutions, financial institutions, medical facilities and personnel, connectivity service providers, schools, employers, etc. But think of all the places where you’ve been asked for your personal information in the last month, like gaining entry into a building (government or private), or joining a competition, or joining that accommodation agent’s WhatsApp group. We very easily, and freely, give our name, phone number and ID number to anyone and everyone who asks these of us without much of a second thought of what it will be used for.

For the purposes of the regulations, personal information includes:

  1. racial or ethnic origin
  2. political opinions
  3. membership of a political association
  4. religious beliefs or affiliations
  5. philosophical beliefs
  6. membership of a professional or trade association
  7. membership of a trade union
  8. sex life
  9. criminal, educational, financial, or employment history
  10. gender, age, marital status, or family status
  11. health or other biometric data

Some of this information is required when you apply for a job, join a church, or even give blood.

Licencing categories and annual fees

Licencing is broken down into 4 tiers based on the number of data subjects whose information is being processed. The minimum number of data subjects is 50 to exclude small employers from the requirements of the Act and regulations. The full list of tiers and associated annual licencing fees are as follows:

Tier 1 (50-1,000 data subjects) – USD 50

Tier 2 (1,001-100,000 data subjects) – USD 300

Tier 3 (100,001 – 500,000 data subjects) – USD 500

Tier 4 (more than 500,000 data subjects) – USD 2,500

Who is exempt from licensing

There are three major exemption categories: personal, family or household affairs; law enforcement; and journalistic, historical, or archival purposes. Of these, only personal and family purposes don’t have to register with the Data Protection Authority. The other two categories must still comply with the rest of the requirements of the regulations.

The myths

Does your WhatsApp group need to be registered as a data controller? Most likely not. Unless your WhatsApp group is also your client database and you are monetising those contacts, like accommodation agents, there is, generally, no need to register as a data controller on the basis of your WhatsApp group.

The Minister should have clear information and ideas before making announcements, or perhaps speak in broader terms that allude to big corporations to whom many of these measures are targeted. The statement on WhatsApp group and the subsequent denials and clarifications shows a lack of clarity and disorder and brought unnecessary ridicule to the ministry. The Ministry of ICT has so many critical issues in its purview that are bedevilling it and data protection isn’t one of them. The Postal and Telecommunication Regulatory Authority of Zimbabwe (POTRAZ) also doubles as the Data Protection Authority. They are the ones who should speak on data protection and all the detail around it, not the Minister.

In the second instalment I will venture into the obligations of data controllers and another big elephant in the room, data processing officers.

_______________________

Mike Murenzvi writes in his personal capacity and his views are not associated with any organisation he is, or may be, affiliated with.