This policy is not final.
Drafting is with the client. Zimbabwe has its own data protection regime; the South African POPIA policy does not apply here and must not be adapted into this page.
What this policy has to cover
- What personal data is collected, and why — under the Cyber and Data Protection Act (Chapter 12:07).
- The identity of the data controller, and the appointed Data Protection Officer.
- Whether the business is licensed with POTRAZ as a data controller. The general compliance period ended in March 2025, so this is already overdue by default.
- How long data is kept, and who it is shared with.
- How someone exercises their rights over their own data.
- Breach notification: 24 hours to POTRAZ, 72 hours to affected individuals where the risk is high.
Questions in the meantime: besuperior@arthur-ford.co.zw or +263 779 708 539.