Transparency Report

EMPOWERBANK LIMITED

ANNUAL PRIVACY TRANSPARENCY REPORT

Reporting period: 1 August 2025 to 31 July 2026

.

1. Purpose and Scope

This Annual Privacy Transparency Report explains how EmpowerBank Limited handled personal information during the completed reporting period. It promotes transparency, accountability and public confidence by reporting the categories of personal information processed, the purposes of processing, sharing and transfers, safeguards applied, data subject requests, complaints, incidents, training, audits and regulatory engagements.

The report covers personal information processed through EmpowerBank products, services, branches, websites, mobile applications, online forms, customer contact channels and internal business processes. It provides aggregated information and does not disclose confidential information or identify individual data subjects.

2. Report at a Glance

Transparency measure

Verified result for the period

Data subject rights requests received

0

Privacy complaints received

0

Personal data breaches or privacy incidents recorded

0

Requests from law enforcement or regulators

0

Cross-border transfer arrangements recorded

0

Privacy and data protection awareness activities

0

Staff training completion rate

85%

Data protection audits or compliance reviews

1

Regulatory notifications or formal engagements

1 for the Core Banking System

3. Categories of Personal Information Processed

During the reporting period, EmpowerBank processed the following categories of personal information where required for authorised banking and business activities:

  • Identification and verification information.
  • Contact and communication details.
  • Financial, account and transaction information.
  • Loan application, credit assessment, affordability and repayment information.
  • Employment or income information supplied for a lawful purpose.
  • Customer service, complaint and data subject request records.
  • Online, device, system access and technical information.
  • CCTV, call recordings and other security-related records where applicable.
  • Other information required for legal, regulatory, audit, risk, security or customer support purposes.

4. Purposes for Processing Personal Information

  • Customer onboarding, account opening and account administration.
  • Loan application processing, credit assessment, affordability checks and facility management.
  • Transaction processing, payment services, statements and execution of customer instructions.
  • Identity verification, Know Your Customer checks, fraud prevention, anti-money laundering and financial crime monitoring.
  • Compliance with legal, regulatory, tax, audit, reporting and governance obligations.
  • Customer support, complaint handling and management of data subject rights requests.
  • Website and digital service operation, cybersecurity monitoring, service improvement and business continuity.

5. Third-Party Sharing and Requests for Personal Information

EmpowerBank shared personal information only where there was an authorised and necessary purpose. Recipient categories may include regulators and public authorities, credit reference bureaus, financial institutions, payment and settlement partners, correspondent institutions, approved technology and hosting providers, cybersecurity providers, communication service providers, auditors, legal advisers, insurers and other contracted service providers.

Measure

Received

Completed/responded

Pending

Notes

Law-enforcement requests

  1

1

1

One lawful request was received and responded to in accordance with applicable legal and regulatory requirements.

Regulatory requests for personal information

  1

1

1

No regulatory requests for personal information were received during the reporting period.

Other authorised third-party disclosures requiring tracking

  0

0

0

No authorised third-party disclosures requiring tracking were recorded during the

6. Cookies, Website Trackers and Digital Tools

During the reporting period, EmpowerBank used [insert verified digital tools or state none] to operate and secure its online services, improve functionality and understand service performance. The Bank maintained, or is completing, a record of each provider, purpose, type of data collected, cookie use and whether data was transferred to a third party or outside Zimbabwe.

Tool/provider

Purpose

Data or cookie activity

Third-party/cross-border status

Website Session Cookies

Maintain user sessions and website functionality

Session identifiers and authentication cookie

No additional third-party sharing

  

 

7. Cross-Border Transfers

During the reporting period, EmpowerBank recorded the following transfers of personal information outside Zimbabwe. Each transfer must be supported by a lawful purpose, an approved recipient, appropriate contractual or other safeguards, and any required assessment or authorisation.

Purpose

Recipient category

Destination

Data category

Safeguards applied

Provision of core banking services through the Mambu Core Banking System

Core Banking System Provider (Mambu)

EU

Customer identification information, account information, transaction records, loan and credit information, and system user access records

Contractual data protection obligations, access controls, encryption, vendor due diligence and security assessments

Provision of email, collaboration, document management and productivity services through Microsoft 365

Cloud Service Provider (Microsoft)

      EU                             

Employee and customer communications, documents, contact information, user account information and audit logs

Data Processing Agreements, encryption in transit and at rest, role-based access controls, multifactor authentication and Microsoft security controls

8. Data Subject Rights Requests

EmpowerBank records and monitors privacy rights requests, including requests for access, correction, erasure, restriction, objection, withdrawal of consent, data portability and concerns relating to automated decision-making or profiling. Results below must be reconciled to the Data Subject Access Request Register.

Request type

Received

Completed

Partially granted

Refused lawfully

Pending

Average response time

Access

0

0

0

0

0

0

Correction

0

0

0

0

0

0

Erasure

0

0

0

0

0

0

Restriction or objection

0

0

0

0

0

0

Withdrawal of consent

0

0

0

0

0

0

Data portability

0

0

0

0

0

0

Automated decision-making or profiling concern

0

0

0

0

0

0

Any refusal, limitation, extension or delay must be legally justified and documented. This report presents aggregated outcomes only.

9. Privacy Complaints, Incidents and Breach Management

EmpowerBank recorded, assessed and managed privacy complaints, concerns and incidents during the reporting period in accordance with approved incident response and breach notification procedures. Confidential details and personal identifiers are excluded from this public-facing report.

Measure

Result

General outcome or corrective action

Privacy complaints received

0

No privacy complaints were received during the reporting period.

Privacy incidents recorded

0

No privacy incidents involving personal information were recorded during the reporting period.

Personal data breaches confirmed

0

No personal data breaches were identified or confirmed during the reporting period

Affected individuals notified where appropriate

0

No personal data breaches occurred that would have required notification to affected individuals.

POTRAZ/Data Protection Authority notifications

0

No privacy incidents or personal data breaches occurred that required notification to the Data Protection Authority.

RBZ or other competent authority notifications

0

No privacy incidents or personal data breaches occurred that required notification to the Reserve Bank of Zimbabwe or any other competent authority.

10. Security Measures and Control Improvements

Key technical and organisational measures used to protect personal information during the period included secure storage, role-based access controls, authentication, secure transmission, monitoring, staff awareness, incident response, backup and recovery controls, and secure disposal. The following material improvements should be reported from approved change, audit and risk records:

  • Review and enhancement of the EmpowerBank Data Protection Policy to strengthen data subject rights, cross-border transfer controls, data protection impact assessment requirements, privacy risk management provisions, and regulatory breach notification obligations. 
  • Development and update of supporting privacy governance documents, including the Data Subject Access Request Procedure, Data Breach Notification Procedure, Incident Response Procedure, Privacy Transparency Report, and Retention and Disposal of Records Policy. 
  • Strengthening of records management controls through the introduction of defined retention periods, approved destruction methods, disposal registers, secure disposal procedures, and requirements for certificates of destruction where third-party service providers are used.
  • Continued delivery of privacy and cybersecurity awareness activities, together with ongoing review and improvement of incident management, breach response, compliance monitoring, and information security governance processes. 
  • Enhancement of privacy accountability measures through the establishment and maintenance of privacy-related registers, including data subject rights request tracking, privacy incident records, and compliance monitoring mechanisms. 
  • Review of technical and organisational safeguards to support the protection of personal information processed through EmpowerBank systems, digital banking platforms, websites, cloud services, and third-party service provider arrangements.

11. Training and Awareness Activities

EmpowerBank conducted privacy and data protection awareness activities during the reporting period. Monthly activities and other formal sessions should be reconciled to attendance records and awareness communications before publication.

Measure

Verified result

Awareness activities delivered

12

Staff assigned training

12

Staff completing training

12

Completion rate

85%

Key topics covered

Safe handling of personal information and social media awareness

12. Data Protection Audits and Compliance Reviews

Review/audit

Scope

Key outcome

Corrective action status

Data Protection and Privacy Compliance Review

Review of personal information processing, security controls, access management, retention practices and regulatory compliance relating to the Core Banking System

The review confirmed that appropriate privacy and security controls were in place. Opportunities for improvement were identified in documentation, data governance and privacy compliance monitoring.

In progress

    

Only approved and non-confidential summary findings should be included in the published report.

13. Regulatory Notifications and Engagements

Authority or engagement type

Number

Purpose

Outcome/status

Reserve Bank of Zimbabwe (RBZ)

1

Regulatory engagement relating to the Core Banking System and ongoing regulatory compliance requirements

Engagement completed. Information submitted and no material adverse findings requiring immediate regulatory action were reported.

14. Data Minimisation, Retention and Secure Disposal

EmpowerBank applied data minimisation by limiting collection and use to information necessary for authorised purposes. Retention periods should be defined and documented, and records that reach approved disposal dates should be securely destroyed, anonymised or archived in accordance with applicable legal, regulatory, contractual, audit and operational requirements.

Measure

Verified position for the period

Data inventories or records of processing reviewed

Yes

Retention schedules reviewed or updated

Yes.

Authorised disposal activities completed

Yes

Third-party certificates of destruction retained

Yes

Exceptions or legal holds

Yes

15. Governance, Assurance and Publication

The Data Protection Officer and relevant governance structures shall verify the accuracy and completeness of this report before approval, publication or authorised circulation. Evidence supporting each reported figure must be retained in the relevant register, audit record, training record, incident record or regulatory correspondence file.

This report will be prepared annually for a completed reporting period. Where full publication would disclose confidential, security-sensitive or personal information, EmpowerBank may publish an appropriately aggregated summary while retaining the detailed evidence for authorised review.

16. Approval

Prepared by

Reviewed by

Approved by

Name: ____________________

Title: Data Protection Officer

 


Date: _____________________

Name: ____________________

Title: _____________________


Date: _____________________

Name: ____________________

Title: _____________________

 


Date: _____________________