SlideShare a Scribd company logo
1 of 10
Download to read offline
Presented by Leishen Pillay
Protection of Personal Information
Act, 2013
Protection of
Personal Information
Act, 2013 ("POPIA")
| 3Hogan Lovells
• Expected implementation date
• Sanctions for non-compliance
Agenda
Hogan Lovells | 4
• On 11 April 2014, the President proclaimed the commencement of the
following sections in the POPI Act, 2013:
– Section 1 (Definitions)
– Part A of Chapter 5 (Information Regulator) - provides for the establishment of the
Information Regulator
– Section 112 (Regulations) - The Minister may issue regulations in terms of the POPI Act,
2013
– Section 113 (Procedure for making regulations) - Process of engagement in respect of
regulations
Transitional period
Hogan Lovells | 5
• On 29 May 2017, Hogan Lovells hosted the Information Regulator who
indicated that POPIA is likely to come into effect in 2018
• The Information Regulator is also in the process of drafting regulations,
which should be tabled in Parliament before the end of the year
• The Information Regulator is benchmarking the data protection practices
of European countries as well as the United Kingdom
Expected implementation date
Hogan Lovells | 6
• Currently, the POPI Act provides that the "processing of personal
information, must within one year after the commencement date ... be
made to conform to this Act"
Time for compliance
Hogan Lovells | 7
• Interference with protection of personal information of a data subject
– Section 73 – "For the purposes of this Chapter, interference with the protection of
personal information of a data subject consists, in relation to that data subject, of -
– (a) any breach of the conditions for the lawful processing of personal information as
referred to in Chapter 3; …"
• Civil remedies
– Section 99(1) – "A data subject or, at the request of the data subject, the Regulator, may
institute a civil action for damages in a court having jurisdiction against a responsible
party for breach of any provision of the POPI Act as referred to in section 73, whether
or not there is intent or negligence on the part of the responsible party."
Sanctions for non-compliance
Hogan Lovells | 8
• In the event of a breach the responsible party may only raise any of the
following defences against an action for damages:
– Vis major
– Consent of the plaintiff
– Fault on the part of the plaintiff
– Compliance was not reasonably practical in the circumstances of the particular case
– The Regulator has granted an exemption
Legal defences
Hogan Lovells | 9
• Section 107 – A person convicted of an offence in terms of POPIA, 2013,
is liable if he/she …
– obstructed the Information Regulator, disclosed the account number of a customer or
failed to comply with a compliance notice, such person may be subject to a fine and/or
imprisonment not exceeding 10 years, or
– if a person committed certain other offences in terms of the POPI Act, such person may
be subject to a fine and/or imprisonment not exceeding 12 months
An administrative fine not exceeding R 10 million may also be imposed on such a person
Sanctions of non-compliance continued
"Hogan Lovells" or the "firm" is an international legal practice that includes Hogan Lovells International LLP, Hogan Lovells
US LLP and their affiliated businesses.
The word “partner” is used to describe a partner or member of Hogan Lovells International LLP, Hogan Lovells US LLP or
any of their affiliated entities or any employee or consultant with equivalent standing.. Certain individuals, who are
designated as partners, but who are not members of Hogan Lovells International LLP, do not hold qualifications equivalent
to members.
For more information about Hogan Lovells, the partners and their qualifications, see www.hoganlovells.com.
Where case studies are included, results achieved do not guarantee similar outcomes for other clients. Attorney
advertising. Images of people may feature current or former lawyers and employees at Hogan Lovells or models not
connected with the firm.
© Hogan Lovells 2017. All rights reserved
www.hoganlovells.com

More Related Content

What's hot

Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
Yizi
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
David Erdos
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Ppt
guestbc7697
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
Kinfe Micheal Yilma
 
Francesca Fanucci, Ppt
Francesca Fanucci, PptFrancesca Fanucci, Ppt
Francesca Fanucci, Ppt
guestbc7697
 

What's hot (20)

Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
Brexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveBrexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK Perspective
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the Philippines
 
RTI ACT 2005 PART-III
RTI ACT 2005 PART-IIIRTI ACT 2005 PART-III
RTI ACT 2005 PART-III
 
Freedom of information
Freedom of informationFreedom of information
Freedom of information
 
Box 9
Box 9Box 9
Box 9
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacy
 
Box 11
Box 11Box 11
Box 11
 
Maeve Mc Donagh
Maeve Mc DonaghMaeve Mc Donagh
Maeve Mc Donagh
 
POPI Update 2013
POPI Update 2013POPI Update 2013
POPI Update 2013
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Ppt
 
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
The Right to Be Forgotten: Remarks on Its Impact on Free Speech and Right of ...
 
Right to good governance
Right to good governanceRight to good governance
Right to good governance
 
Francesca Fanucci, Ppt
Francesca Fanucci, PptFrancesca Fanucci, Ppt
Francesca Fanucci, Ppt
 
Introduction privacy and drones130902.pptx (alleen lezen)
Introduction privacy and drones130902.pptx (alleen lezen)Introduction privacy and drones130902.pptx (alleen lezen)
Introduction privacy and drones130902.pptx (alleen lezen)
 
Radhika bhave 122
Radhika bhave 122Radhika bhave 122
Radhika bhave 122
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 

Similar to Protection of personal information act, 2013

Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
Barbara Richman, SPHR
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
N N
 
ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP Alignment
Mohammed J. Khan
 

Similar to Protection of personal information act, 2013 (20)

The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
The Whistleblowers’ Act
The Whistleblowers’ ActThe Whistleblowers’ Act
The Whistleblowers’ Act
 
Whistleblowing, the Law - Scrase Employment Solicitors
Whistleblowing, the Law - Scrase Employment SolicitorsWhistleblowing, the Law - Scrase Employment Solicitors
Whistleblowing, the Law - Scrase Employment Solicitors
 
Regulatory compliance 2018
Regulatory compliance 2018Regulatory compliance 2018
Regulatory compliance 2018
 
Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
Memphis Business Journal.Eeoc Issues Guidance On Using Arrests, Convictions I...
 
1307 Privacy Act
1307 Privacy Act1307 Privacy Act
1307 Privacy Act
 
Uchi data local presentation 2020
Uchi data local presentation 2020Uchi data local presentation 2020
Uchi data local presentation 2020
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Transatlantic Personal Data Processing: Complying with the new EU-US Privacy ...
Transatlantic Personal Data Processing: Complying with the new EU-US Privacy ...Transatlantic Personal Data Processing: Complying with the new EU-US Privacy ...
Transatlantic Personal Data Processing: Complying with the new EU-US Privacy ...
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP Alignment
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
Whistleblowing Policy
Whistleblowing PolicyWhistleblowing Policy
Whistleblowing Policy
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
The changing face of privacy laws
The changing face of privacy lawsThe changing face of privacy laws
The changing face of privacy laws
 
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
 

Recently uploaded

一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
Airst S
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
bd2c5966a56d
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
Airst S
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
Airst S
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
PoojaGadiya1
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 

Recently uploaded (20)

一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptxPresentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理一比一原版曼彻斯特城市大学毕业证如何办理
一比一原版曼彻斯特城市大学毕业证如何办理
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptxAnalysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
 
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 

Protection of personal information act, 2013

  • 1. Presented by Leishen Pillay Protection of Personal Information Act, 2013
  • 3. | 3Hogan Lovells • Expected implementation date • Sanctions for non-compliance Agenda
  • 4. Hogan Lovells | 4 • On 11 April 2014, the President proclaimed the commencement of the following sections in the POPI Act, 2013: – Section 1 (Definitions) – Part A of Chapter 5 (Information Regulator) - provides for the establishment of the Information Regulator – Section 112 (Regulations) - The Minister may issue regulations in terms of the POPI Act, 2013 – Section 113 (Procedure for making regulations) - Process of engagement in respect of regulations Transitional period
  • 5. Hogan Lovells | 5 • On 29 May 2017, Hogan Lovells hosted the Information Regulator who indicated that POPIA is likely to come into effect in 2018 • The Information Regulator is also in the process of drafting regulations, which should be tabled in Parliament before the end of the year • The Information Regulator is benchmarking the data protection practices of European countries as well as the United Kingdom Expected implementation date
  • 6. Hogan Lovells | 6 • Currently, the POPI Act provides that the "processing of personal information, must within one year after the commencement date ... be made to conform to this Act" Time for compliance
  • 7. Hogan Lovells | 7 • Interference with protection of personal information of a data subject – Section 73 – "For the purposes of this Chapter, interference with the protection of personal information of a data subject consists, in relation to that data subject, of - – (a) any breach of the conditions for the lawful processing of personal information as referred to in Chapter 3; …" • Civil remedies – Section 99(1) – "A data subject or, at the request of the data subject, the Regulator, may institute a civil action for damages in a court having jurisdiction against a responsible party for breach of any provision of the POPI Act as referred to in section 73, whether or not there is intent or negligence on the part of the responsible party." Sanctions for non-compliance
  • 8. Hogan Lovells | 8 • In the event of a breach the responsible party may only raise any of the following defences against an action for damages: – Vis major – Consent of the plaintiff – Fault on the part of the plaintiff – Compliance was not reasonably practical in the circumstances of the particular case – The Regulator has granted an exemption Legal defences
  • 9. Hogan Lovells | 9 • Section 107 – A person convicted of an offence in terms of POPIA, 2013, is liable if he/she … – obstructed the Information Regulator, disclosed the account number of a customer or failed to comply with a compliance notice, such person may be subject to a fine and/or imprisonment not exceeding 10 years, or – if a person committed certain other offences in terms of the POPI Act, such person may be subject to a fine and/or imprisonment not exceeding 12 months An administrative fine not exceeding R 10 million may also be imposed on such a person Sanctions of non-compliance continued
  • 10. "Hogan Lovells" or the "firm" is an international legal practice that includes Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses. The word “partner” is used to describe a partner or member of Hogan Lovells International LLP, Hogan Lovells US LLP or any of their affiliated entities or any employee or consultant with equivalent standing.. Certain individuals, who are designated as partners, but who are not members of Hogan Lovells International LLP, do not hold qualifications equivalent to members. For more information about Hogan Lovells, the partners and their qualifications, see www.hoganlovells.com. Where case studies are included, results achieved do not guarantee similar outcomes for other clients. Attorney advertising. Images of people may feature current or former lawyers and employees at Hogan Lovells or models not connected with the firm. © Hogan Lovells 2017. All rights reserved www.hoganlovells.com