Construction Industry Pension Fund (CIPF)

Website & Data Privacy Notice

  • Official Website: www.cit.co.zw
  • Last Reviewed Date : 05/08/2026

1. Welcome & Introduction

At the Construction Industry Pension Fund (“CIPF”, “we”, “us”, or “our”), we care about your privacy as much as we care about securing your financial future. Established under the Pensions and Provident Funds Act [Chapter 24:09] and Statutory Instrument 323 of 1991, we manage pension, retirement, ill-health, and death benefits for workers across Zimbabwe’s construction sector.

Whether you are a fund member, beneficiary, employer, job applicant, or just visiting our website, this notice explains how we collect, use, store, and protect your personal information.

We handle all your data in line with Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] (“CDPA”) and the Cyber and Data Protection Regulations, 2024 (“SI 155”).

2. Who We Are & How to Reach Us

Under data protection law, CIPF acts as the Data Controller. We are registered (or completing registration) with POTRAZ and have appointed a Data Protection Officer (DPO) to oversee our compliance and assist you.

Contact Information

  • Physical Address: 9th Floor Construction House, 108–110 Leopold Takawira, Harare, Zimbabwe
  • General Enquiries Email: queries@cit.co.zw
  • Phone Numbers: +263 4 792101-1 | +263 4 8677004633

Data Protection Officer (DPO)

  • Name: Zviedzo Gervas Sandinga
  • Email: gsandinga@cit.co.zw
  • Phone / Mobile: +263 4 8677004633 | +263 773669508

 

Regulatory Authority

  • Data Protection Authority: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)

 

3. What Personal Information We Collect

The details we collect depend on how you interact with us:

  • Identity & Contact Details: Your full name, date of birth, national ID/passport number, gender, marital status, physical/email address, phone numbers, and next-of-kin/dependants’ details.
  • Employment & Membership Data: Employer name, job title, start date, employee ID/payroll number, membership number, contribution history, and salary details.
  • Financial Information: Bank details for benefit payments/refunds, and tax reference numbers.
  • Sensitive Information: Medical records (for ill-health or disability claims) and death certificates or beneficiary nominations (for death benefits).
  • Technical & Website Data: IP address, browser type, device information, pages visited, cookies, and any details submitted through website contact/download forms.

4. How We Collect Your Information

We gather personal information through three main avenues:

  1. Directly from You: When you fill out membership forms, claim benefits, visit our offices, call us, or submit queries on our website.
  2. From Your Employer: Through regular payroll updates and statutory contribution submissions.
  3. From Third-Party Service Providers: Such as actuaries, auditors, IT vendors, or medical experts reviewing benefit claims.

5. Why We Process Your Data

We only use your personal information for clear, legitimate pension administration purposes:

  • Registering and managing your Fund membership.
  • Calculating, collecting, and reconciling pension contributions.
  • Assessing and paying out pension, retirement, ill-health, and death benefits.
  • Verifying identity and preventing fraud.
  • Communicating important updates regarding your account or the Fund.
  • Complying with regulatory obligations (including IPEC, ZIMRA/tax authorities, and POTRAZ).
  • Securing and optimizing our website functionality.

6. Our Legal Basis for Using Your Data

We process your information using one or more of these legal grounds:

  • Your Consent: When you voluntarily submit forms (you can withdraw consent at any time).
  • Performance of Scheme Rules: To manage your membership and fulfill statutory pension payouts.
  • Legal Obligations: To comply with national laws like the Pensions and Provident Funds Act or tax laws.
  • Legitimate Interests: To prevent fraud and maintain website security.

Note on Sensitive Data: For sensitive medical or biometric data, we will always request your explicit written consent, unless a direct legal obligation overrides it.

7. Sharing Your Data

We never sell your personal information. However, we may share relevant data with trusted entities on a strict need-to-know basis:

  • Participating Employers (for contribution reconciliation).
  • Professional Advisers (actuaries, lawyers, auditors, medical examiners).
  • Banks & Payment Providers (to issue payouts).
  • IT & Systems Hosting Vendors (bound by legal confidentiality agreements).
  • Regulators & Law Enforcement (such as IPEC or POTRAZ, where legally mandated).

 

8. International Data Transfers

If we ever need to transfer data outside Zimbabwe (for example, to secure cloud servers in other countries), we guarantee that the receiving region meets equivalent legal standards, or that explicit legal safeguards such as your informed consent are fully in place.

9. Keeping Your Data Safe & How Long We Retain It

Data Retention

According to the Insurance and Pensions Commission (IPEC) Guideline on Record-Keeping Standards (issued via Circular 40 of 2022) and the Pensions and Provident Funds Act [Chapter 24:32], data retention periods for pension funds are structured around the lifespan of fund members and their beneficiaries, rather than standard corporate multi-year windows.

Member & Policyholder Data Retention Periods

Under IPEC guidelines, pension funds and administrators must retain member and policyholder records for whichever period is the greatest among the following:

·       100 years from the member’s date of birth.

·       100 years from the date of birth of any designated beneficiary who receives benefits.

·       15 years after the member’s full pension/provident benefits have been paid out.

·       15 years after the death of the member or policyholder.

 

·        Security: We use strict physical and electronic security controls, including restricted access, encrypted files, and staff confidentiality agreements to keep your data safe. In the unlikely event of a security breach, we will notify both POTRAZ and you as required by law.

10. Cookies & Website Analytics

Our website uses cookies to improve browsing experience and analyze site traffic. You can adjust or turn off cookies through your browser settings, though some site functions may become limited.

(Note: Review your browser settings or Cookie Policy to manage specific analytics preferences like Google Analytics).

 

 

11. Protect Working with Children’s Information

When processing minor dependents’ or child beneficiaries’ details (such as survivor benefits), we apply strict extra safeguards. Information is handled strictly through parents, legal guardians, or legal representatives, with Data Protection Impact Assessments conducted whenever required.

12. Knowing Your Data Rights

Under the CDPA, you hold the right to:

  • Access the personal information we hold about you.
  • Request Corrections to incomplete or wrong details.
  • Request Erasure of your data when it is no longer legally needed.
  • Object to or Restrict certain data processing operations.
  • Withdraw Consent at any time where processing was consent-based.
  • Lodge a Complaint with our DPO or directly with POTRAZ.

To exercise any of these rights, please contact our Data Protection Officer. We will verify your identity and respond within statutory timelines.

13. Complaints & Dispute Resolution

If you feel your personal data has been handled improperly, please reach out to our DPO first. If you remain unsatisfied, you have full legal right to escalate the issue to the regulator:

  • Regulator: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
  • Toll-Free Phone: 08004303
  • Website: www.potraz.gov.zw

14. Changes to This Notice

We may update this notice from time to time to align with system upgrades or legal updates. Revised notices will always be posted on our website alongside an updated “Last Reviewed” date.

 

 

Annex A: CIPF Legal Compliance Checklist

Requirement

Statutory Basis (CDPA / SI 155)

Addressed In

Lawfulness, Fairness, & Transparency

CDPA Principles

Sections 6–7

Purpose Limitation

CDPA Principles

Section 5

Data Controller Registration

SI 155

Section 2, 14

Appointment of DPO

SI 155

Section 2, 14

Sensitive/Special Safeguards

CDPA / SI 155

Section 3, 6

Children’s Data Safeguards

CDPA / SI 155

Section 11

Cross-Border Transfer Rules

CDPA

Section 8

Data Subject Rights

CDPA

Section 12

Breach Notification Protocol

CDPA / SI 155

Section 9

Right to Complain to POTRAZ

CDPA / SI 155

Section 13

 

Reach us on WhatsApp
1