Skip to legal document
Back to portal
University of ZimbabweeGate

Privacy Policy

How the University of Zimbabwe collects, uses, shares, retains, and protects information in eGate.

Effective 6 September 2026
Data controllerUniversity of Zimbabwe
ServiceeGate student administration
Institutional scopeUZ affiliate colleges
On this page
Scope and data controllerInformation we collectWhere information comes fromWhy we use informationWhen information is requiredWho receives informationProcessing outside ZimbabweHow long information is keptHow information is protectedYour data-protection rightsCookies and local storageContact and complaintsChanges to this policy

1. Scope and data controller

This policy applies to eGate, the student administration system used by the University of Zimbabwe and its affiliate colleges for admissions, student records, registration, teaching administration, assessment, results, finance, graduation, reporting, and related support services.

University of Zimbabwe is the data controller for personal information processed through eGate. It determines why and how that information is processed. Affiliate colleges use the system as authorised participating institutions and may collect, review, or update information within their approved college scope. Service providers process information only for authorised purposes and under the University's instructions.

This document applies across the University of Zimbabwe affiliate-college network served by eGate.

2. Information we collect

The information collected depends on your relationship with the University or an affiliate college and the services you use.

  • Identity and contact details, including names, date of birth, nationality, national identification or passport details, addresses, telephone numbers, email addresses, photographs, and account identifiers.
  • Admissions information, including applications, programme choices, qualifications, grades, work experience, references, declarations, interview information, decisions, and supporting documents.
  • Student and academic records, including student numbers, programme and Module registrations, attendance, placements, assessments, marks, results, progression, disciplinary or academic-integrity records, graduation, and official documents.
  • Financial and sponsorship records, including fees, invoices, payments, allocations, receipts, balances, refunds, scholarships, sponsor details, and financial-clearance information. Payment-card or mobile-wallet credentials are handled by the relevant payment provider where applicable and should not be stored in eGate.
  • Sensitive information where required and lawfully permitted, including health, disability or accessibility information, demographic information, and information about a minor supplied by a parent or legal guardian.
  • Technical and security information, including sign-in events, device and browser details, network addresses, timestamps, audit trails, security events, and records of changes or downloads.
  • Communications, enquiries, complaints, consent choices, and support records submitted through or about the system.

3. Where information comes from

We obtain information directly from you, from an authorised parent or guardian, from staff acting within their duties, and from records held by the University or your affiliate college. Where necessary, we may also receive information from examining bodies, previous institutions, sponsors, employers or placement providers, referees, payment providers, government bodies, regulators, identity providers, and other lawful sources. When information is obtained from another source, the University will provide the disclosures required by applicable law unless a lawful exception applies.

4. Why we use information

We process personal information only where it is necessary, fair, and lawful. Depending on the activity, processing may be based on your consent, performance of an educational or related agreement, compliance with a legal or regulatory obligation, a task carried out in the public interest or under official authority, protection of vital interests, or a legitimate institutional interest that does not override your rights.

  • Create and secure accounts, verify identity, manage roles, and provide the correct affiliate-college workspace.
  • Administer applications, admission, registration, Modules, assessment, results, progression, graduation, student support, and alumni or statutory recordkeeping.
  • Administer fees, payments, sponsorships, refunds, receipts, financial reporting, and clearance decisions.
  • Generate official documents and reports, conduct audits, support quality assurance and accreditation, and meet regulatory or public-body reporting duties.
  • Communicate deadlines, decisions, notices, service messages, and information needed to participate in academic and administrative processes.
  • Protect users and systems, investigate misuse or incidents, maintain audit evidence, improve service reliability, and plan institutional services using appropriately limited or aggregated information.

5. When information is required

Fields marked as required are needed to complete the stated academic or administrative process. If you do not provide required information, the University or affiliate college may be unable to create your record, assess an application, register you, process a payment, issue a document, provide support, or meet a legal or regulatory duty. Optional fields are identified as such where appropriate.

6. Who receives information

Access is limited by role and affiliate-college scope. We do not sell personal information or use student-administration records for third-party advertising.

  • Authorised University and affiliate-college staff who need the information for admissions, registry, teaching, examinations, student support, finance, audit, reporting, security, or governance.
  • Identity, hosting, object-storage, communications, document-generation, support, and other service providers bound by appropriate confidentiality, security, and data-processing obligations.
  • Banks, payment service providers, sponsors, and insurers where needed to complete or reconcile an authorised transaction or benefit.
  • Examining bodies, professional bodies, placement providers, prior institutions, and verification services where validation is necessary and lawful.
  • ZIMCHE, ministries, auditors, the Data Protection Authority, courts, law-enforcement bodies, and other recipients where disclosure is required or authorised by law.

7. Processing outside Zimbabwe

If an approved provider or recipient processes information outside Zimbabwe, the University will assess the transfer, apply appropriate contractual and security safeguards, and make any notification or obtain any approval required by Zimbabwean law. Information will not be transferred merely for convenience where the necessary safeguards are absent.

8. How long information is kept

Information is kept only for as long as needed for the purpose for which it was collected and for applicable academic-record, accreditation, audit, finance, tax, dispute, safeguarding, security, and legal requirements. Permanent academic records may be retained as part of the University record. Draft, rejected, withdrawn, support, technical, and audit records follow approved retention schedules and are deleted, anonymised, or archived when no longer required. You may ask the Data Protection Officer for the schedule that applies to a particular record.

9. How information is protected

The University uses appropriate technical and organisational measures designed to protect confidentiality, integrity, and availability. These include role-based access, affiliate-college isolation, secure authentication, encrypted connections, private document storage, controlled downloads, logging, audit history, backups, monitoring, and incident-response procedures. No online system can eliminate every risk, so users must also protect their credentials and report suspected compromise promptly.

Where a personal-data breach occurs, the University will investigate, preserve evidence, notify the Data Protection Authority within the period required by law, and notify affected people when the risk and applicable requirements call for it.

10. Your data-protection rights

Subject to the Cyber and Data Protection Act [Chapter 12:07] and lawful limits needed to preserve official records or meet legal obligations, you may ask to be informed about the use of your information, access information held about you, object to all or part of its processing, correct false or misleading information, and request deletion of false or misleading information. Where processing relies on consent, you may withdraw that consent without charge. A parent or legal guardian may exercise applicable rights for a child.

You may also request human review where a decision with legal or similarly significant effects was made solely by automated processing, unless that processing is authorised by law or based on valid consent. eGate may assist staff with validation or calculations, but final high-impact academic and administrative decisions remain subject to authorised institutional processes.

11. Cookies and local storage

eGate uses cookies or browser storage that are necessary for secure sign-in, session continuity, portal context, user preferences, and protection against misuse. The system is not designed to use student-administration data for behavioural advertising. The admin, applicant and student portals use Microsoft Clarity for usage analytics, heatmaps and session recordings to help identify navigation and usability problems. Page text is masked in recordings. Clarity may use cookies and process usage information through Microsoft; see the Microsoft Privacy Statement at https://privacy.microsoft.com/privacystatement for details.

12. Contact and complaints

Send privacy questions or requests to the Data Protection Officer, University of Zimbabwe, P.O. Box MP 167, Mount Pleasant, Harare, Zimbabwe, or email dpo@admin.uz.ac.zw. Please describe the record or processing activity concerned. The University may need to verify your identity before releasing or changing personal information and aims to respond within 30 days.

If you are not satisfied with the response, you may lodge a complaint with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), acting as the Data Protection Authority.

13. Changes to this policy

The University may update this policy when the system, law, or institutional practices change. The effective date will be revised, and material changes will be communicated through an appropriate portal notice, email, or institutional channel before they take effect where required.

Contact the University

Data Protection Officer, University of Zimbabwe
P.O. Box MP 167, Mount Pleasant, Harare, Zimbabwe

dpo@admin.uz.ac.zw

Legal references

Cyber and Data Protection Act [Chapter 12:07] Data Controller and Data Protection Officer Regulations, 2024
© 2026 University of Zimbabwe
Terms of Service