POPI Compliance is an ongoing journey Copy

POPI Compliance is an ongoing journey

Once POPI has been implemented in a business, it is important to ensure that compliance is effectively monitored and reviewed on a regular basis and any new or additional issues are resolved.

The compliance journey does not end with becoming POPI compliant, you also have to maintain your compliance on an ongoing basis.

Ongoing compliance measures that a business will need to consider include:

– Monitoring the compliance of Operators and third party suppliers

All Operators and third party suppliers who have access to Personal Information that the business Processes will need to be monitored and audited regularly to ensure that these organisations are and remain POPI compliant.

– Annual health checks for your business

All controls, processes and policies put in place for POPI should be reviewed at least annually to ensure that they are being implemented effectively, and in order to maintain compliance.

– Regulatory updates

Amendments to POPI, regulations and any industry specific codes of conduct will need to be considered and implemented to the extent necessary.

As a newly enacted piece of legislation, the Information Regulator is like to still issue a number of guidance documents and industry codes of conduct too, to guide you on their expectations and recommendations for POPI compliance.

– Regular training and awareness

Ensure that all new employees are trained on POPI, and that all employees take part in POPI training and awareness on a regular basis (at least annually).

Human error is a large POPI risk for most businesses, and ongoing training and awareness is therefore vital to reduce this businesses risk.

– Privacy Impact Assessments

A privacy impact assessment should be conducted on all new projects undertaken by a business, to ensure that privacy is adequately assessed and implemented in the project.