Close Menu
  • Homepage
  • News
  • Cloud
  • ECommerce
  • Entertainment
  • Finance
  • Security
  • Podcast
  • Contact

Subscribe to Updates

Get the latest technology news from TechFinancials News about FinTech, Tech, Business, Telecoms and Connected Life.

What's Hot

Enjoying Online Games Responsibly

2025-05-12

Supreme Court Of Appeal Hears Zimbabwean Permit Case

2025-05-12

SA Women Break Barriers In Construction With PMI & CIDB Training

2025-05-12
Facebook X (Twitter) Instagram
Trending
  • Enjoying Online Games Responsibly
Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp RSS
TechFinancials
  • Homepage
  • News
  • Cloud
  • ECommerce
  • Entertainment
  • Finance
  • Security
  • Podcast
  • Contact
TechFinancials
Home»Opinion»One Year Of POPIA: Have You Done Enough?
Opinion

One Year Of POPIA: Have You Done Enough?

ContributorBy Contributor2022-07-07No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
PoPIA
Data protection: Image source: Celagenix
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The first of July 2022 marks the one-year anniversary of the compliance deadline of the Protection of Personal Information Act No 4 of 2013 (“POPIA”) for all organisations. While the operational provisions of this Act became effective on 1 July 2020, a one-year grace period was granted to allow businesses to effect the necessary changes. This resulted in a compliance drive to bring various information practices in line.

Compliance with this Act requires ongoing vigilance. At this stage, it is imperative that organisations understand the implications of their personal information practices and put in place systems and measures to manage both their existing and ongoing obligations.

What has happened since POPIA came into effect? 

In order to address compliance with POPIA, your organisation has most likely had to:

  • Undertake exercises in training staff to comply with POPIA across all operations;
  • Conduct personal information impact assessments to address areas of non-compliance;
  • Address issues relating to the consent, transfer and sharing of personal information with third parties (i.e. suppliers, customers etc); and
  • Navigate the intricacies of dealing with incidents of data breaches.

Compliance with POPIA has in certain circumstances necessitated a fundamental shift in the manner in which businesses approach various aspects of their operations. With this shift has come various challenges in accommodating such a transition.

Examples include:

  • There has been a slow uptake in the registration of Information Officers;
  • Many organisations are yet to put in place or update their existing Promotion of Access to Information Manual (“PAIA Manual”) as required; and
  • There are still issues in the interpretation of certain provisions of POPIA which remain uncharted territory and must be navigated through the use of the appropriate processes and legal mechanisms.

Over the past year, developments in case law relating to Data Privacy have aided us in better understanding the compliance requirements set out in POPIA. However, this understanding must be accompanied by practical guidelines to assist organisations in the development and implementation of compliance programmes that take into account their specific needs and operational parameters.

How to ensure your compliance: 

To address any potential compliance gaps within your business, a number of fundamental steps should be considered and taken. These may include:

  • Conducting a gap analysis to determine your organisation’s readiness for POPIA;
  • Undertaking Data Mapping exercises to understand the type of information processed by your organisation and for what purpose, such information is processed;
  • Considering the relevant data transfer requirements and how they may affect your company’s commercial arrangements with third parties or the sharing of data between companies;
  • Updating the PAIA manual to accord with the relevant requirements set out in PAIA (as amended) and POPIA;
  • Developing a culture of privacy by:
  • Conducting an awareness campaign;
  • Training staff; and
  • Updating the relevant organisational policies.
  • Updating customer and supplier contracts to ensure they accord with the relevant requirements set out in POPIA;
  • Preparing the relevant consent and notification documentation;
  • Implementing a system for Data Subject access management; and
  • Preparing and/or updating a Data Breach Incident Response Plan.

The above-mentioned steps are useful in establishing certain best practices in your organisation’s POPIA compliance journey; however, ongoing obligations necessitate a constant review of your organisational processes to ensure that they do not fall short of the POPIA requirements over time.

How to educate yourself further 

In recognition of the one-year anniversary of POPIA, CMS will be publishing a series of articles to take stock of the relevant developments since the enactment of POPIA, which will broadly deal with:

  1. The Role of Employees in Data Protection Compliance Programmes;
  2. Understanding Personal Information Impact Assessments;
  3. The Management of Data Transfers;
  4. Notifications and disclosures of Processing Activities;
  5. Understanding the various types of Cyber Risk; and
  6. A broad account of Data Breaches.

Understanding the intricacies and implications of the requirements set out in POPIA will require your active engagement and consultation to test your operations against the prescripts of the Act. It is not sufficient to deal with your obligations on a theoretical basis alone, as the requirements relating to various organisations may differ on a case-by-case basis. Compliance with the present and ongoing obligations of POPIA must be accompanied by a practical process that allows your organisation to meaningfully measure compliance and address the deficiencies identified.

  • Zaakir Mohamed, Director: Head of Corporate Investigations and Forensics; Savanna Stephens, Senior Associate: Corporate and Commercial; and Mawande Ntontela, Associate: Corporate Investigations and Forensics, at CMS South Africa

POPIA POPIA Compliance Protection of Personal Information Act
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Contributor

Related Posts

How Tech Taxation Policy Is Key To Improving Africa’s Usage Gap

2025-05-12

How Tech Is Reshaping Africa’s Development Trajectory

2025-05-12

How To Tell If A Photo’s Fake? You Probably Can’t. That’s Why New Rules Are Needed

2025-05-09

AI Could Be A Game Changer For Africa’s Youth

2025-05-09

Degrees Alone Won’t Save South Africa’s Economy — Skills Will

2025-05-07

Information Regulator’s Bold Plan: Tackling Data Breaches & PAIA Compliance

2025-05-07

SAA Hit By Major Cyberattack, Systems Disrupted Since May 3

2025-05-06

South Africa’s ICT Sector Needs A New Path

2025-05-02

ISPA Demands Urgent Action Against Rogue Call Centres Breaking The Law

2025-05-02
Leave A Reply Cancel Reply

DON'T MISS
Breaking News

Cassava & Zindi Partner To Boost African AI Innovation

Cassava Technologies, a global tech leader of African heritage, has signed a Memorandum of Understanding…

Daybreak Chair Quits After R625K Payout Amid Chicken Crisis

2025-05-11

TV Licences Are Outdated, But Is A Streaming Levy The Right Fix?

2025-03-17

US-China Trade Wars: Their Impact On Africa

2025-03-07
Stay In Touch
  • Facebook
  • Twitter
  • YouTube
  • LinkedIn
OUR PICKS

Why Cybersecurity Must Support South Africa’s Local By-Elections

2025-05-12

SA Post Office Can Digitally Transform Rural Communities

2025-05-11

Phygital Shopping Rises In SA: Blending Online & In-Store

2025-04-18

Foreigner Nabbed With 554 Cellphones Worth R2.5m In Bloemfontein

2025-04-18

Subscribe to Updates

Get the latest tech news from TechFinancials about telecoms, fintech and connected life.

About Us

TechFinancials delivers in-depth analysis of tech, digital revolution, fintech, e-commerce, digital banking and breaking tech news.

Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp Reddit RSS
Our Picks

Enjoying Online Games Responsibly

2025-05-12

Supreme Court Of Appeal Hears Zimbabwean Permit Case

2025-05-12

SA Women Break Barriers In Construction With PMI & CIDB Training

2025-05-12
Recent Posts
  • Enjoying Online Games Responsibly
  • Supreme Court Of Appeal Hears Zimbabwean Permit Case
  • SA Women Break Barriers In Construction With PMI & CIDB Training
  • How Tech Taxation Policy Is Key To Improving Africa’s Usage Gap
  • No Deposit Casinos SA: How To Win Real Money Without A Deposit
TechFinancials
RSS Facebook X (Twitter) LinkedIn YouTube WhatsApp
  • Homepage
  • Newsletter
  • Contact
  • Advertise
  • About
© 2025 TechFinancials. Designed by TFS Media.

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.