Abstract
This evolution of technology gives rise to cybersecurity concerns as criminal risk becomes a reality with hackers, con-artists and fraudsters attack other ICT users. World-wide, the ever-increasing surge in technology has brought with it a myriad of legal problems. Zimbabwe has seen an upsurge in cybercrime and computer-related crime, particularly mobile money-related fraud, card cloning and identity fraud. The government of Zimbabwe has been aware of the risk associated with the technological advancements in the use of ICTs and has been making an effort to establish the parameters upon which these ICTs are to be exploited. The enactment of the Cyber Security and Data Protection Bill seeks to address the risk of cybercrime in an evolving ICT world. Cybercrime is an unavoidable risk as more people exploit e-commerce. Thus taking legislative measures wherein the law is reviewed, and the legislature enacts laws in order to address cybersecurity issues is welcome.
World-wide, the ever-increasing surge in technology has brought with it a myriad of legal problems.[1] The statistics that the Ministry of Information Communication Technology, Postal and Couriers gathered when they drafted the Zimbabwe National Policy on Information and Communication Technology shows that the number of ICT users is escalating as technology continues to evolve. According to the Ministry, as at 31 December 2015, mobile users had risen to 95.4% and internet use had risen to 45%.[2] Needless to say by now the usage of the internet has doubled as more transactions are being done electronically, from mobile money transfers to online banking platforms adopted by every bank in the country.
This evolution of technology gives rise to cybersecurity concerns as criminal risk becomes a reality with hackers, con-artists and fraudsters attack other ICT users. Consequentially, this compels development of progressive cybersecurity upgrade in order to enhance perpetual protection and maintenance of data security and information security. The implementation of a progressive upgrade of cybersecurity law reform in order to reinforce the protection of consumer rights is commendable as evidenced by the gazetting of the Cybersecurity and Data Protection Bill[3] on the 15th of May 2020.
Van der Merwe et al (2016) aptly acknowledged that cybersecurity has become increasingly important because of the especially innate characteristics of cybercrime and/or computer-related crimes.[4] In Zimbabwe the increase in the use of ICTs, mobile money, online banking and online shopping, more particularly during the lockdown as a result of the effects of COVID19, comes with a greater need for cybersecurity. Zimbabwe has seen an upsurge in cybercrime and computer-related crime, particularly mobile money-related fraud, card cloning and identity fraud.
According to Van der Merwe et al (above), cybersecurity must be viewed ultimately as a careful evaluation of the cybersecurity risks that an ICT userโs assets, resources and activities are exposed to and includes the formulation, quantification of countermeasures and the prediction of the effectiveness of such countermeasures.[5] These countermeasures include, but are not limited to law reform and legislative redress. Hence according to this writer, taking legislative measures wherein the law is reviewed, and the legislature drafts and enacts Bills in order to promulgate regulations and laws that address cybersecurity issues is imperative.
Brief History of the Cyber Security in Zimbabwe
The government of Zimbabwe has been aware of the risk associated with the technological advancements in the use of ICTs and has been making an effort to establish the parameters upon which these ICTs are to be exploited. The government finalized the first ICT policy as early as the year 2005. In order to establish the objectives of the ICT Policy, the Ministry of ICT incorporated, among others, a Legal and Regulatory framework in which the government promotes the cyber-law legislative initiatives and development. It is important to note that this conscious effort to enact legal provisions that address cybercrimes or cyber-related crimes is evident in the enactment of the Criminal Law (Codification and Reform) Act 23 of 2004.[6] The legislature in 2004 incorporated sections 162 to 168 in the Codification as Chapter VIII โ Computer-Related Crimes.
The legislative endeavour to promulgate cyber laws is seen manifest even at a regional level. In May 2008, the Ministers of Information and Communication Technology of SADC (SADC ICT Ministers) converged to map a way forward in a bid to harmonize ICT policies and regulations. The SADC ICT Ministers in this May 2008 meeting adopted a reference framework for the harmonization of ICT policies and regulations. Forging ahead, a Harmonization of ICT Policies in Sub-Saharan Africa (HIPSSA) project namely, โSupport to the Harmonization of ICT Policies in Sub-Saharaโ was officially adopted at Addis Ababa in December 2008. In November 2012, the SADC ICT Ministers met in Mauritius and adopted a draft document of the SADC Model Law.[7] It is important to take cognisance of the participation and involvement of our country in these SADC ICT Ministersโ meetings.[8] Our countryโs accession is evidenced by the legislatureโs attempt to ratify the SADC Model Law through the Cybersecurity and Cybercrime Draft Bill, 2017 of the Republic of Zimbabwe. In a bid to uphold the commitment and dedication to law reform and legislative redress, after much drafting, consultations and reviews, the legislature has amalgamated three draft Bills[9] into the gazetted Cybersecurity and Data Protection Bill.
Are there laws already in place to combat cybercrime?
As stated earlier, the legislature enacted the Codification in 2004 with a specific Chapter dedicated to Computer-related crimes, Chapter VIII. In this Chapter hacking has been criminalized under section 163 of the Codification, card cloning under section 167 defined as unauthorised use or possession of a credit or debit card and unauthorised use of oneโs password or pin-number under section 168. This means that during this COVID19 era where e-commerce is fast thriving, the increasing number of victims of card cloning and hackings already have a specific and express legal remedy under Chapter VIII of the Codification. Although Chapter VIII of the Codification was promulgated to cater for cybercrimes, it does not include some of the most common cybercrimes that have become rampant in e-commerce particularly mobile money transaction-related fraud. These cybercrimes that have not been covered by Chapter VIII of the Codification have been addressed under traditional crimes.
However for the positivists, the need to enact specific provisions to formulate an expressly defined charge for the purpose of prosecuting a perpetrator of cybercrimes, demands that the legislature particularly promulgates explicit cybercrime laws. Scholars have contended that the core principle of cybercrime is to punish unauthorised access to a computer system with a specified criminal intent, in order to ultimately prevent damage or alteration to systems and the data on it.[10] This argument brings across the need to enact laws that specifically define cybercrimes expressly, and implores the legislature to be intentional in their provisions without leaving litigants to improvise on appropriate legal remedies upon injury of their rights be it data privacy rights, right to dignity or any other constitutional rights.
Regardless, one can arguably assert that substantive criminal law in Zimbabwe has developed to such an extent that there are laws already in place to combat cybercrime. Victims of these cybercrimes have been and are able to find appropriate legal remedies in our law. These legal remedies are not restricted to those cybercrimes that have already been covered by Chapter VIII of the Codification, but this also includes those legal remedies that we have seen victims of cybercrime implore.
What is the position of future legislation?
The discussion above regarding the current legal position shows that the laws in Zimbabwe have been progressive in order to address cybersecurity issues to the extent of the cybercrime risk. Chapter VIII of the Codification covers the โtraditionallyโ typical computer-related crimes such as hacking and unauthorised manipulation of a computer system because at the time of the enactment of the Codification, offences such as cyberbullying were almost unheard of.
During the early 2000s whenever one would mention cybercrime, it was confined to crimes against the computer system or computer network with deliberate introduction of computer viruses into the computer or computer network being the most rampant cybercrime. Hence one would not have expected the legislature to contemplate the need to expressly provide for the criminalization of an offence such as card cloning or mobile money transaction-related fraud.
The first Bill aimed at the protection of consumers in the on-line environment was drafted in the year 2013 and marked as the first draft of the Electronic Transactions and Electronic Commerce Bill of 2013 on the 11th of June 2013. This Bill was intended to govern e-commerce in Zimbabwe. The E-Transactions and E-Commerce Bill, 2013 only provided for the enforceability and legal certainty of electronic transactions and e-commerce, whilst a separate Bill addressing cybersecurity and cybercrime was drafted in the year 2017[11]. The progression of the laws reflects on the evolution of technology in Zimbabwe.
As we await the outcome of the debate in Parliament when the Cyber Security and Data Protection Bill will be placed before Parliament, we hope that all consultations are carefully considered.
Conclusion
Although we are looking forward to the enactment of the Cyber security and Data Protection Bill, 2019, any victim of cybercrime has a legal remedy at law. The question of jurisdiction, admissibility of evidence and identity of a perpetrator becomes a discussion for another day. These challenges require adequate address in a separate paper. In the meantime it is imperative to highlight to the reader that whether one finds their card cloned, pin-number manipulated or receives a fake notification from a buyer with the intention to defraud them, they can make a police report and the perpetrators will be charged in terms of relevant sections of the Codification articulated above.
[1] Van der Merwe, D.P. (et al) (2016) Information and Communications Technology Law. 2nd edn. South Africa: LexisNexis. pp. 1
[2] Ministry of Information Communication Technology, Postal and Courier Services, 2016, Zimbabwe National Policy For Information and Communication Technology (ICT) 2016-2020, Ministry of Information Communication Technology, Postal and Courier Services, available at www.ictministry.gov.zw. Downloaded on 01 August 2018.
[3] HB18/2019
[4] Van der Merwe, D.P. et al above at pp. 66
[5] Van der Merwe, D.P. et al above at pp. 67
[6] Criminal Law (Codification and Reform) Act [Chapter 09:23] (hereinafter referred to in text as the Codification).
[7] International Telecommunication Union (ITU), 2013, Computer Crime and Cybercrime: Southern African Development Community (SADC) Model Law, 2013, ITU, Available at: www.itu.int. (Downloaded: 30 October 2018)
[8] Cross reference the National ICT Policy of 2016-2020 above.
[9] Data Protection Bill, 2013; Electronic Transactions and Electronic Commerce Bill, 2013; and the Cybercrime and Cybersecurity Bill, 2017 of the Republic of Zimbabwe
[10] Private International, (2018) โUnderstanding the Difference between Cyber Security and Cyber Crimeโ, Available at: https://privacyinternatiional.org (Accessed: 21 May 2020)
[11] Cybercrime and Cybersecurity Bill, 2017 of the Republic of Zimbabwe

this is so insightful