After more than seven years in the making, President Ramaphosa announced earlier last year an effective date of 1 July 2020 for the Protection of Personal Information Act (POPI), Act 4 of 2013.
Even though the Protection Of Personal Information Act is welcomed by most, it has been long overdue and will require business owners (a “Responsible Party” in terms of the Act) to process personal information according to the requirements set out in the Act.
Responsible Parties only have approximately 8 months left until 30 June 2021 to become compliant in full. The duration of a typical POPI compliance project will differ from one business to another depending on the nature and size of the business, as well as the personal information processed by a Responsible Party. Business owners are therefore advised to, without delay, embark on a compliance project to meet the deadline.
The purpose of the Protection of Personal Information Act is in essence found in the title of the Act; to protect the personal information of Data Subjects. The Act gives effect to ones right to privacy as enshrined in the Constitution but also provides balance in terms of the right to privacy weighed up against the right to access of information.
POPIA regulates the way information must be processed and provides protection and recourse to those whose rights are infringed. Further to this, the Act makes provision for the establishment of an Information Regulator. Advocate, Pansy Tlakula has already been appointed as the Information Regulator a couple of years ago and has done a great deal of work in establishing her office.
Before I get into more detail about the eight processing conditions, it is important to note that the Act is “definitions driven”. It is therefore of utmost importance to first highlight some of the definitions found in the Act for readers to better understand the eight processing conditions.
The first definition is that of “personal information”. Personal information is widely defined in the Act and includes, but is not limited to, information relating to an identifiable living natural person or a juristic person (Data Subjects), such as:
- Race, gender, sex, pregnancy, marital status, nationality, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, believe, culture, language, birth
- History – education, medical, financial, criminal, employment
- Identifiers – number, symbols, e-mail address, physical address, telephone numbers, location, online ID or other assignment to a person such as a unique identifier (in example a student or patient number)
- Biometric information – physical or psychological behavioural characterization, blood type, fingerprints, DNA analysis, retinal scanning, voice recognition
- Personal opinion views or preferences
- Correspondence implicitly or explicitly of a private and confidential nature
- Views or opinions of another individual
- The name of the person with other information or the name alone
The second definition of importance is that of “processing”. The processing of personal information includes but is not limited to any operation/activity or any set of operations, whether automated or not, concerning personal information. It includes:
- Collection / receipt / recording / organizing / collation / storage / updating / modification / retrieval / alteration of personal information
- Dissemination by means of transmission distribution or making available to others.
- Merging / linking / restricting / degradation / erasure / destruction of personal information.
A Responsible Party can either be a public body, private body or any other person or persons, domiciled in South Africa and that determines the purpose and means for processing of personal information.
Throughout the entire lifecycle of personal information in any business, eight processing conditions must be adhered to. The eight processing conditions are summarized below:
Condition 1 – Accountability. The Responsible Party must always ensure that the conditions set out in Chapter 3 of the Act and all the associated measures are complied with.
Condition 2 – Personal information must be collected and processed lawfully in a reasonable manner that does not infringe the privacy of a Data Subject. The personal information may only be processed if it is adequate, relevant, and not excessive.
Personal information may only be processed if the Data Subject consented thereto. Alternatively, where it is necessary to do so for the conclusion or performance of a contract, an obligation in terms of law, to protect the legitimate interest of the Data Subject, or to pursue a legitimate interest of the Responsible Party.
A further requirement is that the personal information must be collected directly from the Data Subject.
Condition 3 requires that personal information must be collected for a specific explicitly defined and lawful purpose related to a function or activity of the responsible party. Such personal information may not be retained any longer than necessary for achieving the purposes for which the information was collected and/or subsequently processed.
Condition 4 prohibits the further processing of personal information unless such processing is compatible with the initial purpose of collecting the information.
Condition 5 – Requires that Responsible Parties must take reasonable, practical steps to ensure that personal information is complete, accurate, and not misleading. Such personal information must also be kept up to date, taking into consideration the purpose of the personal information.
The nature and purpose of the personal information will dictate as to how often such personal information must be updated.
Condition 6 addresses some of the rights of Data Subjects, such as the right to be informed by the Responsible Party before information is collected. The purpose of collecting and from where personal information will be collected must be disclosed to the Data Subject.
A Data Subject is entitled to the details of the Responsible Party and to be made aware of the consequences of not making personal information available to the Responsible Party.
Should it be required that personal information be collected and processed in terms of legislation, the Data Subject must be made aware accordingly.
As per Section 72 of the Act, the Data Subject must be advised if personal information will be transferred across the borders of South Africa. Under such circumstances the Data Subject is entitled to first be made aware of legislation in other countries that provides adequate protection of the personal information. In the absence of legislation, whether there are any binding corporate rules in place, alternatively a written agreement that offers adequate protection for the Data Subject, concluded between the Responsible Party and he third party.
Condition 7 requires that Responsible Parties must secure the integrity and confidentiality of personal information by taking appropriate reasonable, technical and organisational measures, to prevent loss or unlawful access of personal information under the control of a Responsible Party.
In this regard the Responsible Party is required to identify all reasonable and foreseeable internal and external risks, and to establish and maintain appropriate safeguards. Compliance with such safeguards must be regularly audited and measures updated if so required.
Condition 8 deals with the rights of Data Subjects and participation. In terms of condition 8, Data Subjects have the right to establish whether personal information is held by a Responsible Party and to have it corrected or destroyed if it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or have been obtained unlawfully.
Responsible Parties are also further required to introduce Data Subject rights and participation in their PAIA (Promotion of Access to Information Act) manuals.
Responsible Parties are also not permitted to send direct marketing material to Data Subjects without their written consent as per from 4 four of the regulations of the Act.
Other important considerations in terms of the Act are that a responsible party may be issued with an administrative fine of up to R10 million for its non-compliance with the Act. Additionally, Data Subjects have the right to sue Responsible Parties and under specific circumstances, the Information Officer of the Responsible Party may be imprisoned.
Each Responsible Party must register an Information Officer (the head of the organization or a person acting in such capacity) with the Information Regulator. The Information Officer may appoint deputies to assist with ensuring compliance within the business.
From the above, it is evident that a POPIA compliance project is not something that should be undertaken without a solid understanding of the Act.
Written by: Jan du Toit