Data Privacy Policy
This Policy was last reviewed and updated on 24 August 2026
This Privacy Policy explains how Africa Clinical Research Network (ACRN) (“we”, “us”, “our”) at www.acrnhealth.com collects, uses, shares and safeguards personal data when you interact with our services. We are committed to the principles and obligations under Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] (“CDPA”) and Statutory Instrument 155 of 2024 (“SI 155”), including lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability.
1. Purpose and Scope
This Policy applies to all personal data processed by ACRN through any means, including clinical trial operations, research collaborations, site network management, policy advocacy, workforce training, employment relationships, community engagement, and website interactions. It covers data from:
- Clinical trial participants and patients
- Employees, consultants, and contractors
- Site investigators, coordinators, and research staff across 14 countries
- Community members and Community Advisory Board (CAB) members
- Policymakers, regulators, and advocacy stakeholders
- Suppliers, vendors, and business partners
- Website visitors and job applicants
2. What We Collect
- Personal and demographic data: name, national ID, address, age, gender, phone number, next of kin
- Clinical and research data: medical records, biometrics, consent forms, laboratory results, treatment responses, genetic data
- Site network data: investigator CVs, medical licences, GCP certificates, delegation logs, performance metrics
- Employment data: bank details, tax records, payroll information, qualifications, employment history, biometric templates
- Training data: LMS profiles, course completions, certification records, competency assessments
- Community data: CAB member details, attendance registers, socio-behavioural research data, event photographs
- Advocacy data: stakeholder contact details, institutional affiliations, engagement history
- Supplier data: contact details, banking information for invoicing
- Website data: IP address, browser type, geographic location, cookies
3. Lawful Bases Under the CDPA
- Consent: informed, specific, freely given consent, which may be withdrawn at any time without prejudice (Sections 10(1), 11(1)-11(2), CDPA)
- Contractual necessity: to perform employment contracts, clinical trial agreements, and supplier contracts
- Legal obligation: compliance with MCAZ, MRCZ, POTRAZ, ZIMRA, Labour Act, Income Tax Act, and other statutory requirements
- Vital interests: to protect the life or health of the data subject (Section 10(3)(c))
- Public interest: scientific and public health research subject to ethical approvals (Section 10(3)(d))
- Legitimate interest: operational management where not overridden by data subject rights (Section 10(3)(e))
4. How We Use Personal Data
- Clinical research: conducting and managing Phase I-IV trials across 59 sites in 14 African countries
- Site network management: qualification, onboarding, performance monitoring, and regulatory submissions for network sites
- Policy and advocacy: regulatory dialogues, fiscal policy reform, data protection law engagement
- Training and workforce development: LMS administration, ACRP certification, competency tracking
- HR and payroll: employment administration, salary processing, statutory deductions
- Regulatory compliance: submissions to MCAZ, MRCZ, POTRAZ, ZIMRA, and equivalent national authorities
- Community engagement: CAB administration, socio-behavioural research, participant recruitment
- Financial management: procurement, invoicing, grant financial reporting
- Premises security: biometric access control and CCTV surveillance
5. Sensitive Personal Data
ACRN processes the following sensitive data categories under Sections 11 and 12 of the CDPA, with written consent and/or under applicable exceptions (scientific research, public health, vital interests):
- Race and ethnic origin (equitable clinical trial recruitment and health equity research)
- Genetic and biometric information (clinical research samples; employee premises access control)
- Health status and medical records (trial eligibility, safety monitoring, clinical care)
- Social origin (assessing barriers to clinical trial access)
Children’s data: ACRN does not knowingly collect children’s data without parental/guardian consent. Where clinical trials involve minors, processing is per MRCZ-approved protocols with parental consent (Section 26, CDPA; SI 155, s.10(5)).
6. Data Sharing and Disclosure
- Regulatory authorities (MCAZ, MRCZ, POTRAZ, ZIMRA, and equivalent national regulators) as required by law
- Ethics committees for ongoing study oversight
- Study sponsors and their contracted CROs under Data Processing Agreements
- Collaborating research institutions and network sites under binding agreements
- Data processors acting under our instruction (see Section 8)
We do not sell personal data. All third parties receiving personal data must sign a Data Processing Agreement (DPA) including confidentiality, prohibition on secondary use, audit rights, breach notification, and return-or-destroy clauses (Section 18(5), CDPA; SI 155, s.10(4)(f)).
7. International Data Transfers
Transfers are conducted in accordance with Sections 28 and 29 of the CDPA, on the basis of: unambiguous consent; contractual necessity; public interest; vital interests; or binding Data Processing Agreements incorporating appropriate safeguards. Transfers to jurisdictions lacking adequate protection are subject to prior DPO and Ethics Committee approval.
All processors are contractually required to maintain appropriate security, process only as instructed, and return or destroy data upon contract termination.
8. Data Security
ACRN implements appropriate technical and organisational measures to safeguard personal data (Section 18, CDPA; SI 155, s.16), including:
- Role-based access control (RBAC) and multi-factor authentication (MFA)
- AES-256 encryption at rest; SSL/TLS encryption in transit
- Mobile device management (Microsoft Intune) with remote wipe capability
- 24/7 physical security, CCTV, biometric access control, perimeter fencing
- Secure document storage in fire-resistant, locked cabinets
- Secure biospecimen storage with chain-of-custody protocols
- Comprehensive audit trails and data loss prevention (DLP) systems
- Mandatory security awareness training for all personnel
- Periodic security audits, phishing simulations, and vulnerability assessments
A data breach response plan is in place. Breaches are reported to POTRAZ within 24 hours (SI 155, s.17(1)) and affected data subjects notified within 72 hours where high risk exists (SI 155, s.17(3)).
9. Data Retention
Personal data is retained only as long as necessary, per our Data Retention Policy (POL-DPO-002) and the storage limitation principle (Section 7(1)(c), CDPA):
- Clinical trial master file: 25 years from study close-out
- Employee records: 6 years from termination
- Financial/tax records: 6 years from end of tax year
- Community/CAB data: 5 years from end of membership or study close-out
- Supplier records: 6 years from end of contract
- Biometric data: deleted upon separation from employment
- CCTV footage: 30 days (auto-overwrite)
- Job applications/EOIs: 24 months unless consent for longer retention
These periods may be extended under a legal hold. Upon expiry, data is securely destroyed (cross-cut shredding; cryptographic erasure; autoclaving for biospecimens). Destruction logs are maintained as permanent audit evidence.
10. Exercise Your Rights
Under the CDPA, you have the right to:
- Be informed about the collection and use of your personal data
- Access your personal data held by ACRN
- Correct inaccurate or incomplete personal data
- Request deletion of data that is no longer necessary or is false/misleading
- Object to processing based on legitimate interests or direct marketing
- Restrict processing in specific circumstances
- Withdraw consent at any time, without explanation and free of charge
- Receive your data in a portable, machine-readable format
- Not be subject to solely automated decisions producing legal effects
- Deactivate, block, anonymise, or delete your data as appropriate
To exercise any of these rights, contact our Data Protection Officer at dpo@acrnhealth.com or +263783507641. We will acknowledge requests within 7 days and respond substantively within 30 days.
11. How to Contact Us
For privacy questions, concerns, or data subject requests:
Data Protection Officer: Tatenda Magetsi (DPO 000754)
- Email: dpo@acrnhealth.com
- Phone: +263783507641
- Mail: 52 Alpes Road, Vainona, Harare, Zimbabwe
General Enquiries: info@acrnhealth.com | +263 77 746 3012
12. Updates to This Policy
We may update this Policy periodically. Material changes will be communicated via our website or directly to affected individuals. The date above indicates when this Policy was last reviewed. This Policy is reviewed at least annually or upon changes to the CDPA, SI 155, POTRAZ guidance, or our processing activities.
13. Governing Law
This Policy is governed by the laws of Zimbabwe, principally the Constitution (Section 57), the Cyber and Data Protection Act [Chapter 12:07], SI 155 of 2024, POTRAZ Guidelines. POPIA and GDPR serves as regional and international comparators.