Standards Association of Zimbabwe (“we”, “us”, “our”) is the national standardization body responsible for developing and promoting the use of standards in Zimbabwe. We are a Data Controller under the Cyber and Data Protection Act [Chapter 12:07] (“CDPA”).
2. Personal Data We Collect
Contact & identifiers: Name, address, phone, email, national ID, passport
Demographics: Age, gender
Sensitive categories: Health/medical, biometric data (e.g., fingerprints), professional qualifications
Technical/log data: IP addresses, device/browser metadata
3. How We Use Your Data (Purposes & Legal Basis)
Service delivery (e.g., standards purchases, training, certification) – Contractual necessity
Communications and marketing (with consent where required) – Consent
Compliance with legal/regulatory obligations – Legal obligation
Security, fraud prevention, and IT management – Legitimate interests
Personalized service improvements – Legitimate interests
4. Recipients of Your Data
Service providers
Regulators
Legal advisors or law enforcement, if required by law
5. International Transfers
If data is transferred outside Zimbabwe, we ensure adequate safeguards, including standard contractual clauses and encryption, in compliance with CDPA requirements.
6. Data Retention
Your data is retained only as long as necessary for contractual and legal obligations.
After that, it will be securely deleted or anonymized.
7. Your Rights
Right to be informed
Right of access
Right to rectification
Right to erasure
Right to object
Right to data portability
Right to review automated decisions
8. Special Conditions for Sensitive or Children’s Data
We treat health, biometric, and other sensitive data with enhanced safeguards.
Where processing involves children (under 18), we ensure parental/guardian consent or legal authorizations.
9. Security of Your Data
We implement technical, organizational, and physical measures (aligned with ISO 27001), such as encryption, access controls, and regular security audits.
10. Data Breaches
If SAZ becomes aware of a breach, we will notify the Data Protection Authority (POTRAZ) within 24 hours and affected individuals if there’s high risk.
Our processors are required to report breaches to us within 24 hours of discovery.
11. Complaints & Dispute Resolution
If you’re dissatisfied with our handling of your data: Contact our Data Protection Officer