Construction Industry Pension Fund
(CIPF)
Website & Data Privacy Notice
- Official Website:
www.cit.co.zw
- Last Reviewed Date :
05/08/2026
1. Welcome & Introduction
At the Construction Industry Pension
Fund (“CIPF”, “we”, “us”, or “our”),
we care about your privacy as much as we care about securing your financial
future. Established under the Pensions and Provident Funds Act [Chapter
24:09] and Statutory Instrument 323 of 1991, we manage pension,
retirement, ill-health, and death benefits for workers across Zimbabwe’s
construction sector.
Whether you are a fund member,
beneficiary, employer, job applicant, or just visiting our website, this notice
explains how we collect, use, store, and protect your personal information.
We handle all your data in line with
Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] (“CDPA”) and
the Cyber and Data Protection Regulations, 2024 (“SI 155”).
2. Who We Are & How to Reach Us
Under data protection law, CIPF acts as
the Data Controller. We are registered (or completing registration) with
POTRAZ and have appointed a Data Protection Officer (DPO) to oversee our
compliance and assist you.
Contact Information
- Physical Address:
9th Floor Construction House, 108–110 Leopold Takawira, Harare, Zimbabwe
- General Enquiries Email:
queries@cit.co.zw
- Phone Numbers:
+263 4 792101-1 | +263 4 8677004633
Data Protection Officer (DPO)
- Name: Zviedzo
Gervas Sandinga
- Email:
gsandinga@cit.co.zw
- Phone / Mobile:
+263 4 8677004633 | +263 773669508
Regulatory Authority
- Data Protection Authority:
Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
3. What Personal Information We Collect
The details we collect depend on how
you interact with us:
- Identity & Contact Details: Your full name, date of birth, national ID/passport
number, gender, marital status, physical/email address, phone numbers, and
next-of-kin/dependants’ details.
- Employment & Membership Data: Employer name, job title, start date, employee
ID/payroll number, membership number, contribution history, and salary
details.
- Financial Information:
Bank details for benefit payments/refunds, and tax reference numbers.
- Sensitive Information:
Medical records (for ill-health or disability claims) and death
certificates or beneficiary nominations (for death benefits).
- Technical & Website Data: IP address, browser type, device information, pages
visited, cookies, and any details submitted through website
contact/download forms.
4. How We Collect Your Information
We gather personal information through
three main avenues:
- Directly from You:
When you fill out membership forms, claim benefits, visit our offices,
call us, or submit queries on our website.
- From Your Employer:
Through regular payroll updates and statutory contribution submissions.
- From Third-Party Service Providers: Such as actuaries, auditors, IT vendors, or medical
experts reviewing benefit claims.
5. Why We Process Your Data
We only use your personal information
for clear, legitimate pension administration purposes:
- Registering and managing your Fund membership.
- Calculating, collecting, and reconciling pension
contributions.
- Assessing and paying out pension, retirement,
ill-health, and death benefits.
- Verifying identity and preventing fraud.
- Communicating important updates regarding your account
or the Fund.
- Complying with regulatory obligations (including IPEC,
ZIMRA/tax authorities, and POTRAZ).
- Securing and optimizing our website functionality.
6. Our Legal Basis for Using Your Data
We process your information using one
or more of these legal grounds:
- Your Consent:
When you voluntarily submit forms (you can withdraw consent at any time).
- Performance of Scheme Rules: To manage your membership and fulfill statutory
pension payouts.
- Legal Obligations:
To comply with national laws like the Pensions and Provident Funds Act or
tax laws.
- Legitimate Interests:
To prevent fraud and maintain website security.
Note on Sensitive Data: For sensitive medical or biometric data, we will always
request your explicit written consent, unless a direct legal obligation
overrides it.
7. Sharing Your Data
We never sell your personal
information. However, we may share relevant data with trusted entities on a
strict need-to-know basis:
- Participating Employers
(for contribution reconciliation).
- Professional Advisers
(actuaries, lawyers, auditors, medical examiners).
- Banks & Payment Providers (to issue payouts).
- IT & Systems Hosting Vendors (bound by legal confidentiality agreements).
- Regulators & Law Enforcement (such as IPEC or POTRAZ, where legally mandated).
8. International Data Transfers
If we ever need to transfer data
outside Zimbabwe (for example, to secure cloud servers in other countries), we
guarantee that the receiving region meets equivalent legal standards, or that
explicit legal safeguards such as your informed consent are fully in place.
9. Keeping Your Data Safe & How
Long We Retain It
Data Retention
According to the Insurance and
Pensions Commission (IPEC) Guideline on Record-Keeping Standards (issued
via Circular 40 of 2022) and the Pensions and Provident Funds Act [Chapter
24:32], data retention periods for pension funds are structured around the
lifespan of fund members and their beneficiaries, rather than standard
corporate multi-year windows.
Member & Policyholder Data
Retention Periods
Under IPEC guidelines, pension
funds and administrators must retain member and policyholder records for whichever
period is the greatest among the following:
·
100
years
from the member’s date of birth.
·
100
years
from the date of birth of any designated beneficiary who receives benefits.
·
15
years
after the member’s full pension/provident benefits have been paid out.
·
15
years
after the death of the member or policyholder.
·
Security:
We use strict physical and electronic security controls, including restricted
access, encrypted files, and staff confidentiality agreements to keep your data
safe. In the unlikely event of a security breach, we will notify both POTRAZ
and you as required by law.
10. Cookies & Website Analytics
Our website uses cookies to improve
browsing experience and analyze site traffic. You can adjust or turn off
cookies through your browser settings, though some site functions may become
limited.
(Note: Review your browser settings or
Cookie Policy to manage specific analytics preferences like Google Analytics).
11. Protect Working with Children’s
Information
When processing minor dependents’ or
child beneficiaries’ details (such as survivor benefits), we apply strict extra
safeguards. Information is handled strictly through parents, legal guardians,
or legal representatives, with Data Protection Impact Assessments conducted
whenever required.
12. Knowing Your Data Rights
Under the CDPA, you hold the right to:
- Access the
personal information we hold about you.
- Request Corrections
to incomplete or wrong details.
- Request Erasure
of your data when it is no longer legally needed.
- Object to or Restrict
certain data processing operations.
- Withdraw Consent
at any time where processing was consent-based.
- Lodge a Complaint
with our DPO or directly with POTRAZ.
To exercise any of these rights, please
contact our Data Protection Officer. We will verify your identity and respond
within statutory timelines.
13. Complaints & Dispute Resolution
If you feel your personal data has been
handled improperly, please reach out to our DPO first. If you remain
unsatisfied, you have full legal right to escalate the issue to the regulator:
- Regulator: Postal
and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
- Toll-Free Phone:
08004303
- Website: www.potraz.gov.zw
14. Changes to This Notice
We may update this notice from time to
time to align with system upgrades or legal updates. Revised notices will
always be posted on our website alongside an updated “Last Reviewed”
date.
Annex A: CIPF Legal Compliance
Checklist
|
Requirement |
Statutory Basis (CDPA / SI 155) |
Addressed In |
|
Lawfulness, Fairness, &
Transparency |
CDPA Principles |
Sections 6–7 |
|
Purpose Limitation |
CDPA Principles |
Section 5 |
|
Data Controller Registration |
SI 155 |
Section 2, 14 |
|
Appointment of DPO |
SI 155 |
Section 2, 14 |
|
Sensitive/Special Safeguards |
CDPA / SI 155 |
Section 3, 6 |
|
Children’s Data Safeguards |
CDPA / SI 155 |
Section 11 |
|
Cross-Border Transfer Rules |
CDPA |
Section 8 |
|
Data Subject Rights |
CDPA |
Section 12 |
|
Breach Notification Protocol |
CDPA / SI 155 |
Section 9 |
|
Right to Complain to POTRAZ |
CDPA / SI 155 |
Section 13 |