An effective date of Protection of Personal Information Act (POPIA) is still unknown and will not be announced until the Information Regulator is operational and effective in its role of monitoring and being able to enforce compliance.

The importance of the effective date

The effective date will signal the start of the 12-month grace period, following which compliance will be enforced and with it some heavy consequences, including a ten-year prison sentence or up to R10 million fines for breaches to the act.

Recently appointed Information Regulator have defined their mandate

The Information Regulator, who were appointed on 1 December 2016, issued their three year strategic and performance plan in May 2017. Their mandate being “to ensure respect for and to promote, enforce and fulfil the right to privacy and the right of access to information”.

Banking and insurance industries are keeping the regulator busy

The regulator are receiving a large number of complaints from the public which they are already dealing with, majority of which are from the banking and insurance sectors.

What is personal information

‘‘Personal information’’ means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person. For example; Email addresses; age; birth dates; medical history; employment details; blood type etc. There is special provision for special personal information given the increased sensitivity of this information, for example; information concerning a child, race or ethic origin and trade union membership.

A few key changes as a result of POPIA

1. Information can only be used for what it was agreed to be used for.

Customers and employees need to know exactly what information employers have about them and precisely what they’re using it for, and once complete they are required to destroy the information as soon as the purpose has been completed. The days of buying mailing lists from other companies is come and gone.

2. Direct marketers will require your consent prior to communicating with you.

Direct marketers will require your consent prior to processing personal information for the purposes of direct marketing by means of electronic communication, unless the individual has specifically consented to the processing; or is a customer of the responsible party doing the marketing.
Therefore organizations need to need to implement opt-in and opt-out processes.

3. Personal information can only be retained for as long as necessary

Organizations will be required to determine how long is necessary.

As an organization what will we be obligated to do

  1. Ensure the information remains relevant and up to date
  2. Apply reasonable security measures to protect it
  3. Only collect information that you need for a specific purpose
  4. Only hold as much as you need, and only for as long as you need it

Why should our organization comply?

  1. Your customer confidence will increase given that POPI promotes transparency regarding information that is collected and how it is to be processed.
  2. It will improve the overall reliability of information available given the core principle of capturing the minimum required data, ensuring accuracy, and removing data that is no longer required.
  3. It will reduce the risk of data breaches and the associated reputational and legal implications due to implementing measures to protect the information.

The POPI Act continues to be drafted

Certain sections of the Protection of Personal Information Act (POPIA) have already commenced (under proclamation No. R. 25, 2014), but these are limited to; definitions; the establishment of and the role of the Information Regulator and procedures for making regulations.

Draft regulations have yet to be published for comment with Detailed regulations will be published during July / August 2017. The finalisation of the regulations will be done in consultation with many of the industry bodies as well as directly with the industries.

POPIA is still a fair way off from being effective however given the level of complexity and impact on most organisations business processes there is plenty of work to be done to ensure compliance and credibility in a trust hungry market.