Popia has commenced

The much anticipated commencement date for the Protection of Personal Information Act (POPIA) has arrived.

Most of the provisions of POPIA commenced on 01 July 2020, and businesses now have 1 year (until 01 July 2021) to become fully compliant with the provisions of the Act, after which the Act will be fully enforceable.

  What is the Protection of Personal Information Act (“POPIA”) and how does it apply to your business?

Every time you use a service, buy a product online, go to your doctor, pay your taxes, or enter into any contract or service request, you are required hand over some of your Personal Information. Even without your knowledge, information about you is being generated and processed by companies that you may have never interacted with. To empower us to control our Personal Information and protect us from abuses, it is essential that data protection laws are put in place to protect how our Personal Information is used and handled, and it is for this reason that the Protection of Personal Information Act, 4 of 2013 (the “POPI Act” or “POPIA”) is relevant and so important.

Information privacy laws have been implemented in most parts of the world, with it becoming a core focus internationally given the rate at which Personal Information is stored, processed and accessed through technological advances.

In South Africa, the right to Privacy is a constitutional right that is protected in our Bill of Rights. The POPI Act is one of the legislative measures that aims to protect our right to Privacy. The POPI Act brings South Africa in line with international data protection laws and is based on many of the core principles of data protection that are found in data protection laws around the world.

  What is POPIA?

POPIA applies to all processing of personal Information, for whatever reason. It seeks to regulate every step of how Personal Information must be handled from the moment it is collected until the moment it is destroyed.

The definitions of Personal Information and Processing are key to POPIA.

 The definition of Personal Information is very broad and includes all information that identifies or is about a person. This includes information about a person’s:

  • race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person;
  • the education or the medical, financial, criminal or employment history of the person;
  • any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person;
  • the biometric information of the person;
  • the personal opinions, views or preferences of the person and the views or opinions of another individual about the person;
  • correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original private or confidential correspondence; and
  • the name of the person if it appears with other Personal Information relating to the person or if the disclosure of the name itself would reveal information about the person.

The definition of Processing is equally as broad and covers everything that is done with that Personal Information from the moment it is collected until the moment it is destroyed. Processing includes any operation or activity concerning Personal Information, whether or not by automatic means (so it applies to both hard copy and electronic information), including:

  • the collection, receipt, Recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use;
  • dissemination by means of transmission, distribution or making available in any other form; or
  • merging, linking, as well as restriction, degradation, erasure or destruction of information.

  Does the POPI Act apply to your business?

Do you have employees in your business? Do you collect Personal Information (as defined above) from your clients or customers? Do you collect Personal Information from your suppliers or contractors? Do you receive, collect or Process (as defined above) Personal Information for or on behalf of your clients? If so, then it is more than likely that your business uses or “Processes” Personal Information, and that POPIA applies. You therefore need to start taking steps towards becoming POPIA Compliant and protecting the Personal Information that your business Processes.

  What do you need to do to start your POPIA Compliance Journey?

If POPIA applies to your business, you will need to start looking at what steps need to be taken to start your compliance journey. The extent of work needed to become POPIA compliant, and the length of time needed to do so, will vary from business to business, and really depends on the size of the business and the amount of Personal Information that a business Processes.

One of the first steps is training and awareness. Not only will training guide you through what POPIA is about and what it requires of you to protect the Personal Information that your business processes, but it will also make you and your employees privacy aware at the outset, as you process Personal Information in your day to day business operations.

Once you have covered the basics of POPIA and have an understanding of what POPIA and Data Privacy is all about, you will then be in a position to start conducting a POPIA gap assessment of your business. A gap assessment will enable you to assess how the Act will truly affect your business and where your main POPIA compliance gaps lie. Once you have identified your businesses main compliance gaps, you can then start identifying what needs to be done in your business to start becoming compliant and begin with compliance implementation.

Don’t Delay. Start Now.

The commencement date for the material provisions of POPIA has been declared as 01 July 2020. Businesses now have 1 year, until 01 July 2021 to become fully POPIA compliant before the provisions of the Act become enforceable.

Depending on the nature of your business and the volume of Personal Information your business processes, it is recommended that you start your POPIA compliance journey sooner rather than later. In some instances, a 1-year period to become fully POPIA compliant will be insufficient.

The fines that the Information Regulator may impose (once POPIA is enforceable from 01 July 2021) and the potential business interruption and reputational damage to your business can be far reaching in the event of a Data Breach and your business can only benefit from putting the required data privacy measures in place to protect the privacy of the Personal Information that your business is entrusted with and responsible for protecting.

Contact us at info@popicompli.co.za to see how we can assist you with your POPI compliance journey.