SlideShare a Scribd company logo
A practical approach to data 
protection 
Protection of Personal Information Act Workshop 
2014-09-18
Share your thoughts 
You can find me on Twitter as @pauljacobson 
2014-07-24 
#POPIready
Useful links at http://j.mp/popiready
Key principles and themes
Lawful processing conditions 
✤ Accountability! 
✤ Purpose limitation! 
✤ Purpose specification! 
✤ Further processing limitation! 
✤ Information quality! 
✤ Openness! 
✤ Security safeguards! 
✤ Data subject participation
Conditions for lawful processing of 
personal information * 
* Subject to exceptions
Consent and data collection
Privacy in a digital world is complicated
“The very practice of privacy is all about control in a world in which we 
fully know that we never have control. Our friends might betray us, our 
spaces might be surveilled, our expectations might be shattered. But this 
is why achieving privacy is desirable. People want to be *in* public, but 
that doesn’t necessarily mean that they want to *be* public. There’s a 
huge difference between the two. As a result of the destabilization of 
social spaces, what’s shocking is how frequently teens have shifted from 
trying to restrict access to content to trying to restrict access to meaning. 
They get, at a gut level, that they can’t have control over who sees 
what’s said, but they hope to instead have control over how that 
information is interpreted. And thus, we see our collective imagination 
of what’s private colliding smack into the notion of public. They are less 
of a continuum and more of an entwined hairball, reshaping and 
influencing each other in significant ways.” 
– danah boyd writing in her article “What is Privacy?”
Consent, justification and objection 
01
“… it seems to be a sensible approach to say that the scope of 
a person’s privacy extends a fortiori only to those aspects in 
regard to which a legitimate expectation of privacy can be 
harboured.” 
– Bernstein and Others v Bester NO and Others
Options 
Consent 
Legitimate interests 
Contractual conclusion or performance
‘‘consent’’ means any voluntary, specific and informed 
expression of will in terms of which permission is given for 
the processing of personal information
Example
Only where consent is required may a data 
subject withdraw permission
“Legitimate interests” is vague, undefined 
and, yet, a very interesting justification
“The processing is necessary for the purposes of legitimate 
interests pursued by the data controller or by the third party 
or parties to whom the data are disclosed, except where the 
processing is unwarranted in any particular case by reason of 
prejudice to the rights and freedoms or legitimate interests of 
the data subject.” 
– Section 6, Schedule 2, UK Data Protection Act
Still, the “Lawful processing of personal information 
conditions” provide broad parameters and context for 
“legitimate interests” arguments …
01 
Special personal information
✤ Children’s personal information! 
✤ Religious or philosophical beliefs*! 
✤ Race or ethnic origin! 
✤ Trade union membership*! 
✤ Political persuasion! 
✤ Health or sex life! 
✤ Criminal behaviour or biometric information
Example
‘‘child’’ means a natural person under the age of 18 years who is not 
legally competent, without the assistance of a competent person, to 
take any action or decision in respect of any matter concerning him-or 
herself;
How transparent are you?
Write clear privacy statements
Examples
Privacy statement essentials 
✤ What personal information do you collect?! 
✤ What do you do with that personal information?! 
✤ When may the personal information be disclosed and to 
whom?! 
✤ How long do you retain personal information, where do you 
retain it and what are your safeguards?! 
✤ How may a data subject interrogate your databases?
Example
“A responsible party must take reasonably practicable steps 
to ensure that the personal information is complete, accurate, 
not misleading and updated where necessary.” 
– Section 16, the Protection of Personal Information Act
Do you facilitate meaningful access to 
personal information you hold?
Example
Data processing
“Personal information may only be processed if, given the 
purpose for which it is processed, it is adequate, relevant 
and not excessive.” 
– Section 10, the Protection of Personal Information Act
Purpose specification 
“Personal information must be collected for a specific, explicitly 
defined and lawful purpose related to a function or activity of 
the responsible party” 
Be transparent about the purpose
Examples
Further processing must align with the original purpose* 
* There are exceptions too
Data integrity and retention
“… records of personal information must not be retained any 
longer than is necessary for achieving the purpose for which 
the information was collected or subsequently processed …” 
– Section 13, Protection of Personal Information Act
Don’t lose sight of the bigger data 
retention compliance picture 
Electronic Communications 
and Transactions Act 
Protection of Personal 
Information Act 
Everything else
POPI places special emphasis on 
security safeguards
“A responsible party must secure the integrity and 
confidentiality of personal information in its possession or 
under its control by taking appropriate, reasonable 
technical and organisational measures …” 
– Section 19, Protection of Personal Information Act
Examples
“A responsible party must, in terms of a written contract 
between the responsible party and the operator, ensure that 
the operator which processes personal information for the 
responsible party establishes and maintains the security 
measures referred to in section 19 …” 
– Section 21, Protection of Personal Information Act
Identifying key risk areas
Helpful questions 
How do you process personal information? 
Are you the responsible party or the operator? 
Is your reputation at risk and what could go wrong?
Do you engage in direct marketing?
Do you process personal information on your responsible 
party customers’ behalf?
Be responsible, reduce reputational harm risk in the process
Transparent dealings with 
stakeholders 
2014 Heartbleed Bug 
OpenSSL exploit came to light 
Providers proactively contacted users 
and recommended password changes
“The way to gain good reputation is to endeavor to be what 
you desire to appear” 
– Socrates
Implementation
What does your policy framework say you do? 
What should your people be doing? 
What are your people actually doing?
Communicate effectively 
01 
with your teams
01 
Document your processes and monitor compliance
Paul Jacobson 083 444 8260 
webtechlaw.com/contact 
Thank you for your time. 
Please feel free to contact me if we can assist you or answer questions.

More Related Content

What's hot

Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
Sabrina Kirrane
 
Personal Data Protection Law
Personal Data Protection LawPersonal Data Protection Law
Personal Data Protection Law
Hatice Zümbül, LL.M.
 
POPI Update 2013
POPI Update 2013POPI Update 2013
Search engine privacy
Search engine privacySearch engine privacy
Search engine privacy
Per Koch
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
Russell_Kennedy
 
Data and software privacy
Data and software privacyData and software privacy
Data and software privacy
Integral university, India
 
Webinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPRWebinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPR
panagenda
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
Exove
 
Data Privacy
Data PrivacyData Privacy
Data Privacy
Home
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
Trish McGinity, CCSK
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
Myron Duncan Burton Betshanger
 
Privacy 101
Privacy 101Privacy 101
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?
MediaPost
 
Sovereignty: the state of data
Sovereignty: the state of dataSovereignty: the state of data
Sovereignty: the state of data
dan hyde
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
Elizabeth Baker, JD, CRCMP
 
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
OvationsGroup
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
Home
 

What's hot (19)

Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
 
Personal Data Protection Law
Personal Data Protection LawPersonal Data Protection Law
Personal Data Protection Law
 
POPI Update 2013
POPI Update 2013POPI Update 2013
POPI Update 2013
 
Search engine privacy
Search engine privacySearch engine privacy
Search engine privacy
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
Data and software privacy
Data and software privacyData and software privacy
Data and software privacy
 
Webinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPRWebinar: An EU regulation affecting companies worldwide - GDPR
Webinar: An EU regulation affecting companies worldwide - GDPR
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR for developers
GDPR for developersGDPR for developers
GDPR for developers
 
Data Privacy
Data PrivacyData Privacy
Data Privacy
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
 
Privacy 101
Privacy 101Privacy 101
Privacy 101
 
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?
 
Sovereignty: the state of data
Sovereignty: the state of dataSovereignty: the state of data
Sovereignty: the state of data
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
Werksmans presentations on popi
Werksmans presentations on popiWerksmans presentations on popi
Werksmans presentations on popi
 
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
Ovations Group - Introducing the Protection of Personal Information (PoPI) ac...
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
 

Viewers also liked

StartupBisnis.com Indonesia General Profile for Public
StartupBisnis.com Indonesia General Profile for PublicStartupBisnis.com Indonesia General Profile for Public
StartupBisnis.com Indonesia General Profile for Public
ReinҲ Rein
 
china is beautiful
china is beautifulchina is beautiful
china is beautiful
sokoban
 
too pretty
too prettytoo pretty
too pretty
sokoban
 
Complementarios- Marioly
Complementarios- MariolyComplementarios- Marioly
Complementarios- MariolyAster
 
Lovemewithallyourheart
LovemewithallyourheartLovemewithallyourheart
Lovemewithallyourheartsokoban
 
Personalitatile colegilor de birou
Personalitatile colegilor de birouPersonalitatile colegilor de birou
Personalitatile colegilor de birou
sokoban
 
Bruxelles
BruxellesBruxelles
Bruxelles
sokoban
 
cel mai periculos loc turistic din lume
cel mai periculos loc turistic din lumecel mai periculos loc turistic din lume
cel mai periculos loc turistic din lume
sokoban
 
Want themost angelhack jakarta 2013
Want themost angelhack jakarta 2013Want themost angelhack jakarta 2013
Want themost angelhack jakarta 2013ReinҲ Rein
 
Els caràcters biològics i el material genètic
Els caràcters biològics i el material genèticEls caràcters biològics i el material genètic
Els caràcters biològics i el material genètic
PatryDavid
 
Videoarte
VideoarteVideoarte
Videoarte
juan paez
 
GWT Extreme!
GWT Extreme!GWT Extreme!
GWT Extreme!
cromwellian
 
Japan
JapanJapan
Japan
sokoban
 
: Novenyszobraszat
: Novenyszobraszat: Novenyszobraszat
: Novenyszobraszat
sokoban
 

Viewers also liked (20)

StartupBisnis.com Indonesia General Profile for Public
StartupBisnis.com Indonesia General Profile for PublicStartupBisnis.com Indonesia General Profile for Public
StartupBisnis.com Indonesia General Profile for Public
 
china is beautiful
china is beautifulchina is beautiful
china is beautiful
 
too pretty
too prettytoo pretty
too pretty
 
Complementarios- Marioly
Complementarios- MariolyComplementarios- Marioly
Complementarios- Marioly
 
Lovemewithallyourheart
LovemewithallyourheartLovemewithallyourheart
Lovemewithallyourheart
 
Cyprus
CyprusCyprus
Cyprus
 
Merry Christmas
Merry ChristmasMerry Christmas
Merry Christmas
 
8marzo
8marzo8marzo
8marzo
 
Personalitatile colegilor de birou
Personalitatile colegilor de birouPersonalitatile colegilor de birou
Personalitatile colegilor de birou
 
Bruxelles
BruxellesBruxelles
Bruxelles
 
cel mai periculos loc turistic din lume
cel mai periculos loc turistic din lumecel mai periculos loc turistic din lume
cel mai periculos loc turistic din lume
 
Want themost angelhack jakarta 2013
Want themost angelhack jakarta 2013Want themost angelhack jakarta 2013
Want themost angelhack jakarta 2013
 
Els caràcters biològics i el material genètic
Els caràcters biològics i el material genèticEls caràcters biològics i el material genètic
Els caràcters biològics i el material genètic
 
Mt Everest Pp
Mt Everest PpMt Everest Pp
Mt Everest Pp
 
Here Comes The Sun
Here Comes The SunHere Comes The Sun
Here Comes The Sun
 
Videoarte
VideoarteVideoarte
Videoarte
 
Diigo
DiigoDiigo
Diigo
 
GWT Extreme!
GWT Extreme!GWT Extreme!
GWT Extreme!
 
Japan
JapanJapan
Japan
 
: Novenyszobraszat
: Novenyszobraszat: Novenyszobraszat
: Novenyszobraszat
 

Similar to 2014-09-18 Protection of Personal Information Act readiness workshop

2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
Paul Jacobson
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
- Mark - Fullbright
 
data privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliancedata privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliance
DesmondMontgomery2
 
4514611.ppt
4514611.ppt4514611.ppt
4514611.ppt
ssusera4419c
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
Olivier Vandeputte
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
Premier EPOS
 
data-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdfdata-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdf
kiruthigajawahar6
 
So You Want to Protect Privacy: Now What?
So You Want to Protect Privacy: Now What?So You Want to Protect Privacy: Now What?
So You Want to Protect Privacy: Now What?
Stuart Bailey
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
David Erdos
 
Intro to information governance booklet
Intro to information governance bookletIntro to information governance booklet
Intro to information governance booklet
Gerardo Medina
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
JakeAldrinDegala1
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
Harrison Clark Rickerbys
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Diana Maier
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
Tushar Rajput
 
Introduction to FOI law (the law of information)
Introduction to FOI law (the law of information)Introduction to FOI law (the law of information)
Introduction to FOI law (the law of information)
Dan Michaluk
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
N N
 

Similar to 2014-09-18 Protection of Personal Information Act readiness workshop (20)

2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
data privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliancedata privacy handbook: A starter guide to data privacy compliance
data privacy handbook: A starter guide to data privacy compliance
 
4514611.ppt
4514611.ppt4514611.ppt
4514611.ppt
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
data-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdfdata-privacy-egypt-what-you-need-know-en.pdf
data-privacy-egypt-what-you-need-know-en.pdf
 
Privacy Access Letter I Feb 5 07
Privacy Access Letter I   Feb 5 07Privacy Access Letter I   Feb 5 07
Privacy Access Letter I Feb 5 07
 
So You Want to Protect Privacy: Now What?
So You Want to Protect Privacy: Now What?So You Want to Protect Privacy: Now What?
So You Want to Protect Privacy: Now What?
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
Intro to information governance booklet
Intro to information governance bookletIntro to information governance booklet
Intro to information governance booklet
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
 
Introduction to FOI law (the law of information)
Introduction to FOI law (the law of information)Introduction to FOI law (the law of information)
Introduction to FOI law (the law of information)
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 

More from Paul Jacobson

2014-04-04 PaperFree Web•Tech•Law presentation
2014-04-04 PaperFree Web•Tech•Law presentation2014-04-04 PaperFree Web•Tech•Law presentation
2014-04-04 PaperFree Web•Tech•Law presentation
Paul Jacobson
 
Why transparency is so important - my presentation at the 2014 SA Privacy Man...
Why transparency is so important - my presentation at the 2014 SA Privacy Man...Why transparency is so important - my presentation at the 2014 SA Privacy Man...
Why transparency is so important - my presentation at the 2014 SA Privacy Man...
Paul Jacobson
 
Web•Tech•Law – Taking risk out of digital
Web•Tech•Law – Taking risk out of digitalWeb•Tech•Law – Taking risk out of digital
Web•Tech•Law – Taking risk out of digital
Paul Jacobson
 
2014 Photo and Film Expo presentation
2014 Photo and Film Expo presentation2014 Photo and Film Expo presentation
2014 Photo and Film Expo presentation
Paul Jacobson
 
2013 05-29 Advertising and Marketing Law Presentation
2013 05-29 Advertising and Marketing Law Presentation2013 05-29 Advertising and Marketing Law Presentation
2013 05-29 Advertising and Marketing Law Presentation
Paul Jacobson
 
2013 03-06 ITWeb GRC presentation on reputation management
2013 03-06 ITWeb GRC presentation on reputation management2013 03-06 ITWeb GRC presentation on reputation management
2013 03-06 ITWeb GRC presentation on reputation management
Paul Jacobson
 
Popi becomes law briefing slides
Popi becomes law briefing slidesPopi becomes law briefing slides
Popi becomes law briefing slides
Paul Jacobson
 
Presentation – Mobile Show Africa 2012
Presentation – Mobile Show Africa 2012Presentation – Mobile Show Africa 2012
Presentation – Mobile Show Africa 2012
Paul Jacobson
 
Changing markets (2012 VOASA Conference)
Changing markets (2012 VOASA Conference)Changing markets (2012 VOASA Conference)
Changing markets (2012 VOASA Conference)Paul Jacobson
 
Social media marketing and the legal stuff presentation slides
Social media marketing and the legal stuff presentation slidesSocial media marketing and the legal stuff presentation slides
Social media marketing and the legal stuff presentation slides
Paul Jacobson
 
Social media: Legal and business challenges
Social media: Legal and business challengesSocial media: Legal and business challenges
Social media: Legal and business challenges
Paul Jacobson
 
Marketing on the social Web - Marketing Legislation Conference
Marketing on the social Web - Marketing Legislation ConferenceMarketing on the social Web - Marketing Legislation Conference
Marketing on the social Web - Marketing Legislation Conference
Paul Jacobson
 
Corporate Social Media Management Conference October 2008
Corporate Social Media Management Conference   October 2008Corporate Social Media Management Conference   October 2008
Corporate Social Media Management Conference October 2008
Paul Jacobson
 
Legal Aspects Of New Media Quirk 2008
Legal Aspects Of New Media   Quirk   2008Legal Aspects Of New Media   Quirk   2008
Legal Aspects Of New Media Quirk 2008
Paul Jacobson
 
Copyright Review Workshop Uct April 2008
Copyright Review Workshop   Uct April 2008Copyright Review Workshop   Uct April 2008
Copyright Review Workshop Uct April 2008
Paul Jacobson
 
Legal Aspects Of New Media 2008
Legal Aspects Of New Media   2008Legal Aspects Of New Media   2008
Legal Aspects Of New Media 2008
Paul Jacobson
 
Copyright Review Workshop
Copyright Review WorkshopCopyright Review Workshop
Copyright Review Workshop
Paul Jacobson
 
Legal Aspects Of New Media 2nd Annual New Media
Legal Aspects Of New Media   2nd Annual New MediaLegal Aspects Of New Media   2nd Annual New Media
Legal Aspects Of New Media 2nd Annual New Media
Paul Jacobson
 
Open Law Project Presentation
Open Law Project PresentationOpen Law Project Presentation
Open Law Project Presentation
Paul Jacobson
 
Document Format Presentation
Document Format PresentationDocument Format Presentation
Document Format Presentation
Paul Jacobson
 

More from Paul Jacobson (20)

2014-04-04 PaperFree Web•Tech•Law presentation
2014-04-04 PaperFree Web•Tech•Law presentation2014-04-04 PaperFree Web•Tech•Law presentation
2014-04-04 PaperFree Web•Tech•Law presentation
 
Why transparency is so important - my presentation at the 2014 SA Privacy Man...
Why transparency is so important - my presentation at the 2014 SA Privacy Man...Why transparency is so important - my presentation at the 2014 SA Privacy Man...
Why transparency is so important - my presentation at the 2014 SA Privacy Man...
 
Web•Tech•Law – Taking risk out of digital
Web•Tech•Law – Taking risk out of digitalWeb•Tech•Law – Taking risk out of digital
Web•Tech•Law – Taking risk out of digital
 
2014 Photo and Film Expo presentation
2014 Photo and Film Expo presentation2014 Photo and Film Expo presentation
2014 Photo and Film Expo presentation
 
2013 05-29 Advertising and Marketing Law Presentation
2013 05-29 Advertising and Marketing Law Presentation2013 05-29 Advertising and Marketing Law Presentation
2013 05-29 Advertising and Marketing Law Presentation
 
2013 03-06 ITWeb GRC presentation on reputation management
2013 03-06 ITWeb GRC presentation on reputation management2013 03-06 ITWeb GRC presentation on reputation management
2013 03-06 ITWeb GRC presentation on reputation management
 
Popi becomes law briefing slides
Popi becomes law briefing slidesPopi becomes law briefing slides
Popi becomes law briefing slides
 
Presentation – Mobile Show Africa 2012
Presentation – Mobile Show Africa 2012Presentation – Mobile Show Africa 2012
Presentation – Mobile Show Africa 2012
 
Changing markets (2012 VOASA Conference)
Changing markets (2012 VOASA Conference)Changing markets (2012 VOASA Conference)
Changing markets (2012 VOASA Conference)
 
Social media marketing and the legal stuff presentation slides
Social media marketing and the legal stuff presentation slidesSocial media marketing and the legal stuff presentation slides
Social media marketing and the legal stuff presentation slides
 
Social media: Legal and business challenges
Social media: Legal and business challengesSocial media: Legal and business challenges
Social media: Legal and business challenges
 
Marketing on the social Web - Marketing Legislation Conference
Marketing on the social Web - Marketing Legislation ConferenceMarketing on the social Web - Marketing Legislation Conference
Marketing on the social Web - Marketing Legislation Conference
 
Corporate Social Media Management Conference October 2008
Corporate Social Media Management Conference   October 2008Corporate Social Media Management Conference   October 2008
Corporate Social Media Management Conference October 2008
 
Legal Aspects Of New Media Quirk 2008
Legal Aspects Of New Media   Quirk   2008Legal Aspects Of New Media   Quirk   2008
Legal Aspects Of New Media Quirk 2008
 
Copyright Review Workshop Uct April 2008
Copyright Review Workshop   Uct April 2008Copyright Review Workshop   Uct April 2008
Copyright Review Workshop Uct April 2008
 
Legal Aspects Of New Media 2008
Legal Aspects Of New Media   2008Legal Aspects Of New Media   2008
Legal Aspects Of New Media 2008
 
Copyright Review Workshop
Copyright Review WorkshopCopyright Review Workshop
Copyright Review Workshop
 
Legal Aspects Of New Media 2nd Annual New Media
Legal Aspects Of New Media   2nd Annual New MediaLegal Aspects Of New Media   2nd Annual New Media
Legal Aspects Of New Media 2nd Annual New Media
 
Open Law Project Presentation
Open Law Project PresentationOpen Law Project Presentation
Open Law Project Presentation
 
Document Format Presentation
Document Format PresentationDocument Format Presentation
Document Format Presentation
 

Recently uploaded

Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
Trademark Quick
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
9ib5wiwt
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
MwaiMapemba
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
anvithaav
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
Wendy Couture
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
9ib5wiwt
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
Daffodil International University
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
9ib5wiwt
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
FernandoSimesBlanco1
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
johncavitthouston
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
Dr. Oliver Massmann
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
BridgeWest.eu
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
ssuser0576e4
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
o6ov5dqmf
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
anjalidixit21
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
akbarrasyid3
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Thomas (Tom) Jasper
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
Abdul-Hakim Shabazz
 

Recently uploaded (20)

Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
 
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW  AN OVERVIEW in Malawi.pptxEMPLOYMENT LAW  AN OVERVIEW in Malawi.pptx
EMPLOYMENT LAW AN OVERVIEW in Malawi.pptx
 
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptxNATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
NATURE, ORIGIN AND DEVELOPMENT OF INTERNATIONAL LAW.pptx
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
 
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
定制(nus毕业证书)新加坡国立大学毕业证学位证书实拍图原版一模一样
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
 
VAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act PresentationVAWA - Violence Against Women Act Presentation
VAWA - Violence Against Women Act Presentation
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
一比一原版麻省理工学院毕业证(MIT毕业证)成绩单如何办理
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
Rokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal OpinionRokita Releases Soccer Stadium Legal Opinion
Rokita Releases Soccer Stadium Legal Opinion
 

2014-09-18 Protection of Personal Information Act readiness workshop

  • 1. A practical approach to data protection Protection of Personal Information Act Workshop 2014-09-18
  • 2. Share your thoughts You can find me on Twitter as @pauljacobson 2014-07-24 #POPIready
  • 3. Useful links at http://j.mp/popiready
  • 5. Lawful processing conditions ✤ Accountability! ✤ Purpose limitation! ✤ Purpose specification! ✤ Further processing limitation! ✤ Information quality! ✤ Openness! ✤ Security safeguards! ✤ Data subject participation
  • 6. Conditions for lawful processing of personal information * * Subject to exceptions
  • 7. Consent and data collection
  • 8. Privacy in a digital world is complicated
  • 9. “The very practice of privacy is all about control in a world in which we fully know that we never have control. Our friends might betray us, our spaces might be surveilled, our expectations might be shattered. But this is why achieving privacy is desirable. People want to be *in* public, but that doesn’t necessarily mean that they want to *be* public. There’s a huge difference between the two. As a result of the destabilization of social spaces, what’s shocking is how frequently teens have shifted from trying to restrict access to content to trying to restrict access to meaning. They get, at a gut level, that they can’t have control over who sees what’s said, but they hope to instead have control over how that information is interpreted. And thus, we see our collective imagination of what’s private colliding smack into the notion of public. They are less of a continuum and more of an entwined hairball, reshaping and influencing each other in significant ways.” – danah boyd writing in her article “What is Privacy?”
  • 11. “… it seems to be a sensible approach to say that the scope of a person’s privacy extends a fortiori only to those aspects in regard to which a legitimate expectation of privacy can be harboured.” – Bernstein and Others v Bester NO and Others
  • 12. Options Consent Legitimate interests Contractual conclusion or performance
  • 13. ‘‘consent’’ means any voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information
  • 15.
  • 16. Only where consent is required may a data subject withdraw permission
  • 17. “Legitimate interests” is vague, undefined and, yet, a very interesting justification
  • 18. “The processing is necessary for the purposes of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject.” – Section 6, Schedule 2, UK Data Protection Act
  • 19. Still, the “Lawful processing of personal information conditions” provide broad parameters and context for “legitimate interests” arguments …
  • 20. 01 Special personal information
  • 21. ✤ Children’s personal information! ✤ Religious or philosophical beliefs*! ✤ Race or ethnic origin! ✤ Trade union membership*! ✤ Political persuasion! ✤ Health or sex life! ✤ Criminal behaviour or biometric information
  • 23. ‘‘child’’ means a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take any action or decision in respect of any matter concerning him-or herself;
  • 25. Write clear privacy statements
  • 27.
  • 28.
  • 29.
  • 30. Privacy statement essentials ✤ What personal information do you collect?! ✤ What do you do with that personal information?! ✤ When may the personal information be disclosed and to whom?! ✤ How long do you retain personal information, where do you retain it and what are your safeguards?! ✤ How may a data subject interrogate your databases?
  • 32.
  • 33. “A responsible party must take reasonably practicable steps to ensure that the personal information is complete, accurate, not misleading and updated where necessary.” – Section 16, the Protection of Personal Information Act
  • 34. Do you facilitate meaningful access to personal information you hold?
  • 36.
  • 38. “Personal information may only be processed if, given the purpose for which it is processed, it is adequate, relevant and not excessive.” – Section 10, the Protection of Personal Information Act
  • 39. Purpose specification “Personal information must be collected for a specific, explicitly defined and lawful purpose related to a function or activity of the responsible party” Be transparent about the purpose
  • 41.
  • 42.
  • 43.
  • 44. Further processing must align with the original purpose* * There are exceptions too
  • 45. Data integrity and retention
  • 46. “… records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed …” – Section 13, Protection of Personal Information Act
  • 47. Don’t lose sight of the bigger data retention compliance picture Electronic Communications and Transactions Act Protection of Personal Information Act Everything else
  • 48. POPI places special emphasis on security safeguards
  • 49. “A responsible party must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures …” – Section 19, Protection of Personal Information Act
  • 51.
  • 52. “A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19 …” – Section 21, Protection of Personal Information Act
  • 54. Helpful questions How do you process personal information? Are you the responsible party or the operator? Is your reputation at risk and what could go wrong?
  • 55. Do you engage in direct marketing?
  • 56. Do you process personal information on your responsible party customers’ behalf?
  • 57. Be responsible, reduce reputational harm risk in the process
  • 58. Transparent dealings with stakeholders 2014 Heartbleed Bug OpenSSL exploit came to light Providers proactively contacted users and recommended password changes
  • 59. “The way to gain good reputation is to endeavor to be what you desire to appear” – Socrates
  • 61. What does your policy framework say you do? What should your people be doing? What are your people actually doing?
  • 62. Communicate effectively 01 with your teams
  • 63. 01 Document your processes and monitor compliance
  • 64. Paul Jacobson 083 444 8260 webtechlaw.com/contact Thank you for your time. Please feel free to contact me if we can assist you or answer questions.