The global outbreak of the Coronavirus (“COVID-19”) has irrefutably led to a paradigm shift in the way in which enterprises are operating both internationally and locally. Businesses have increasingly evolved to e-commerce, a modern activity of entering into contracts with consumers through use of the internet. Such a shift has had an impact on how personal data is processed, stored and transferred triggering concern as to whether contracting parties, particularly the consumers, are adequately protected on the cyber environment.
Data privacy regulates all stages of the processing of personal data. However, it is important to note from the outset that cybersecurity threats and vulnerabilities have predated COVID-19 given the vast technological advancements pervading trade markets. This pandemic merely magnifies the potential risk of infringement of personal data and privacy rights in countries where protective legislative frameworks have not been developed for enforcement.
Privacy and Data protection have become major issues in the global economy. The Constitution of Zimbabwe in section 57 provides for the right to privacy. This Constitutional right, one could argue, could be used as the basis for transforming the law on privacy and data protection to include all institutions not presently covered by the present legal provisions. On the 15th of May 2020 the Parliament of Zimbabwe published the Cyber Security and Data Protection Bill of Zimbabwe. The Cyber Security Bill is an important and commendable milestone in realizing privacy rights and the protection of personal data in Zimbabwe. However, the prospects of this Bill are dependent on implementation of its statutory provisions.
The law should deal with principles on data privacy such as collection limitation, use limitation and security safeguards. The current law results in a lot of legal uncertainty and risk between the consumers and the business enterprises. Any law enacted to deal with protection of information should seek to increase data security compliance obligations and consequences, including significant fines for organisations, that fail to adhere to same. While some institutions may adopt international best practice on collecting and processing confidential information there remains a need for specific law on data collection, handling and disclosure.
Privacy and Data Protection in Zimbabwe: Zimbabwe Gazettes Cyber Security and Data Protection Bill
Let us know if you liked the post. That’s the only way we can improve.

0 Comments