SlideShare a Scribd company logo
1 of 22
PROTECTION OF PERSONAL INFORMATION
ACT NO. 4 OF 2013 (“POPI”)
OCTOBER 2016
INTRODUCTION
• POPI was signed into law on 19 November 2013
• Commencement date of:
• section 1; Part A of Chapter 5; and
• section 112; and
• section 113
was on 11 April 2014
INTRODUCTION
• Rationale behind POPI:
• Section 14 of the Constitution – right to privacy
• to protect the misuse and abuse of personal information in RSA and cross-
border flow of information
• introducing a minimum set of requirements for the processing of personal
information
• establishing an Information Regulator to perform duties in terms of POPI and
PAIA
• to align legislation with modern society
IMPORTANT DEFINITIONS
• “consent” – is any voluntary, specific and informed expression of will of which
permission is given for the processing of personal information
• “data subject” – is a person to whom personal information relates
• “filing system” – is a structured set of personal information, whether centralised,
decentralised or dispersed geographically
• “operator” – is a person who processes personal information in terms of a
contract or mandate
IMPORTANT DEFINITIONS
• “personal information” – is information relating to an identifiable, living, natural
person, juristic person including, but not limited to:
• Race, gender, pregnancy, marital status, national, ethnic or social origin
• Education, medical, financial, criminal or employment history
• ID, symbol, e-mail address, physical address, telephone number, location,
online identifier or particular assignment to the person
• Correspondence sent by the person that is explicitly or implied to be
confidential or private of nature or any further information that would reveal the
contents of the original correspondence
• about the person
IMPORTANT DEFINITIONS
• Views or opinions of another individual about the person
• Name of a person if it appears with other personal information relating to
the person or if the disclosure itself would reveal the information
IMPORTANT DEFINITIONS
• “processing” – means any operation or activity or set of operations, whether or
not by automatic means, concerning personal information:
• the collection, receipt, recording, organisation, collation, storage, updating or
modification, retrieval, alteration, consultation or use
• dissemination by means of transmission, distribution or making available in any
other form
• merging, linking, as well as restriction, degradation, erasure or destruction of
information
• “responsible party” – is a public or private body or any person which, alone
or in conjunction with others, determines the purpose of and means for
processing personal information
APPLICATION OF THE ACT
• Applies to the processing of personal information where the information is entered
in a record by a responsible party AND
• when it is recorded by non-automated means, it forms part of a filing system or is
intended to form part thereof AND
• where the responsible party is domiciled in RSA
• If not domiciled in RSA, but makes use of automated or non-automated means in
the republic – unless those means are used only to forward personal information
through the republic
CAVEATS
• If any other legislation provides for lawful processing of personal information that
are more extensive, then the extensive conditions will prevail – section 3
• POPI will apply in any other case irrespective of whether other legislation provides
for the lawful processing of information
EXCLUSIONS
• Section 6 determines that POPI does not apply:
• when data is processed for personal or household activities
• when personal information has been de-identified
• if a public body processes personal information for national security, criminal
matters or judicial functions
• when personal information is processed for Journalistic, artistic or literary
expression
• Caveat in section 3 – more extensive protection in other legislation
LAWFUL PROCESSING
• There are 8 principles that has to be followed:
• Accountability
• Processing limitation
• Purpose specification
• Further processing limitation
• Information quality
• Openness
• Security safeguards
• Data subject participation
LAWFUL PROCESSING
• Accountability
• The responsible party must ensure that he/she/it comply with the provisions of
POPI at the time of determination of the purpose and means of the processing
• Processing limitation
• Lawfulness (should not infringe privacy)
• Consent, justification and objection
• Processing is just if there is an obligation, protects a legitimate interest of the
data subject, pursuing legitimate interests of the responsible party
• Consent may be withdrawn at any time
LAWFUL PROCESSING
• Minimalism – purpose for which information is processed has to be:
• Relevant
• Not excessive
• Adequate
• Collection – directly from the data subject
LAWFUL PROCESSING
• Purpose specification
• Collection
• Must be for a specific purpose relating to the function of the responsible party
• The data subject must be informed of the purpose of collection
• Retention and restriction
• Not longer than it is necessary for unless required by law or for the function of
the responsible party
• Personal information must be destroyed, deleted or de-identified as soon as
practicable after it is no longer required to be retained
LAWFUL PROCESSING
• Further processing limitation
• Must be for the purpose for it was collected for
• Further processing is not incompatible with the purpose if further processing is
necessary for compliance with section 1 of the SARS Act, No.34 of 1997
• Information quality
• Openness
• Documentation
• Must maintain documentation of processing operations – section 14 or 51 of
PAIA
• Notification when collecting data
LAWFUL PROCESSING
• Notify of the purpose of collecting the information
• Whether supply is mandatory or voluntary
• Flow of information is cross-border and need to advise on the other countries’
privacy laws
LAWFUL PROCESSING
• Security Safeguards
• Security measures on data integrity and confidentiality
• appropriate and reasonable
• Identify internal and external risks
• Regularly verify, review and update safeguards
• Information processed by operator
• Only with authorisation of the responsible party
• Confidentiality
• Security Compromises
• Need to notify the regulator and the data subject
• Notify as soon as becoming aware of breach
LAWFUL PROCESSING
• Data subject participation
• Access to personal information
• Correction of personal information
• Manner of access – in accordance with PAIA
• Prohibition on processing special personal information
• Beliefs, race, sex, trade union membership and health (act contain more)
• Criminal behaviour – all that is alleged
• Section 27 - 33 list exclusions to special personal information
CROSS BORDER INFORMATION FLOW
• Responsible party may not transfer personal information to a 3rd party in a foreign
country unless:
• The 3rd party has similar privacy laws, corporate rules or a biding agreement to
that effect
• The data subject consents to the transfer
• The transfer is necessary for contractual performance
• Transfer is necessary for the conclusion of agreements in the interest of the
data subject
• Transfer is for the benefit of the data subject
COMPLAINTS
• Any person may submit a complaint with the Regulator
• It must be in writing
• The Regulator may then conduct a pre-investigation
• Act as a conciliator at any time during the investigation
• May decide not to take any action on a complaint
• Conduct a full investigation
• Refer the compliant to the Enforcement Committee
• Take any other action referred to in terms of the Act
OFFENCES AND PENALTIES
• 2 categories
• Serious offences – fine or imprisonment of not more than 10 years
• Less serious offences – fine or imprisonment of not more than 12 months
• Administrative fines – not exceeding R10 million Rand
TRANSITIONAL ARRANGEMENTS
• All processing of personal information must within 1 year conform to the Act
• The 1 year period may be extended by the Minister

More Related Content

What's hot

Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Jason Haislmaier
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the PhilippinesShirley Ingles-Cruz
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson LLP
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Jay Castillo
 
Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Kirk Go
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationEndcode_org
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislationjonbarclay
 
Cloud and security 6 jul2013 v2
Cloud and security 6 jul2013 v2Cloud and security 6 jul2013 v2
Cloud and security 6 jul2013 v2Charles Mok
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
Data Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperativesData Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperativesjo bitonio
 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Werksmans Attorneys
 
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited
 

What's hot (19)

The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
 
Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)
 
CEU DPA
CEU DPACEU DPA
CEU DPA
 
Data privacy act of 2012 presentation
Data privacy act of 2012 presentationData privacy act of 2012 presentation
Data privacy act of 2012 presentation
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the Philippines
 
Privacy in simple
Privacy in simplePrivacy in simple
Privacy in simple
 
Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017Browne Jacobson - Administrative and public law - October 2017
Browne Jacobson - Administrative and public law - October 2017
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
 
Gary Davis
Gary DavisGary Davis
Gary Davis
 
Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)
 
Leg4
Leg4 Leg4
Leg4
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
Data privacy act
Data privacy actData privacy act
Data privacy act
 
Guernsey Data Protection Legislation
Guernsey Data Protection LegislationGuernsey Data Protection Legislation
Guernsey Data Protection Legislation
 
Cloud and security 6 jul2013 v2
Cloud and security 6 jul2013 v2Cloud and security 6 jul2013 v2
Cloud and security 6 jul2013 v2
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
Data Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperativesData Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperatives
 
Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...Saying "I Don't": the requirement of data subject consent for purposes of dat...
Saying "I Don't": the requirement of data subject consent for purposes of dat...
 
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...Lorson Resources Limited - Records & Information Presentation: Data Protectio...
Lorson Resources Limited - Records & Information Presentation: Data Protectio...
 

Viewers also liked

How to Avoid Making PPC Mistakes
How to Avoid Making PPC MistakesHow to Avoid Making PPC Mistakes
How to Avoid Making PPC MistakesLance Bachmann
 
A range of reading notebooks
A range of reading notebooksA range of reading notebooks
A range of reading notebooksdonamore1
 
Courier Mail Article_Career One_Russo Recruitment
Courier Mail Article_Career One_Russo RecruitmentCourier Mail Article_Career One_Russo Recruitment
Courier Mail Article_Career One_Russo RecruitmentSalene Gallagher
 
Guide to Winning Micro-Moments
Guide to Winning Micro-MomentsGuide to Winning Micro-Moments
Guide to Winning Micro-MomentsLance Bachmann
 
Power point guía didáctica AEA
Power point guía didáctica AEAPower point guía didáctica AEA
Power point guía didáctica AEAAlejandro Ramos
 
Big Data Analysis and Terrorism
Big Data Analysis and TerrorismBig Data Analysis and Terrorism
Big Data Analysis and TerrorismAmanda Tapp
 
Clase sobre las necesidades básicas de los niños (1) (1)
Clase sobre las necesidades básicas de los niños (1) (1)Clase sobre las necesidades básicas de los niños (1) (1)
Clase sobre las necesidades básicas de los niños (1) (1)VERÓNICA SINCHIGUANO
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal InformationFrancois Naude Jr.
 
Dystopian Controls #2 DBlock
Dystopian Controls  #2 DBlockDystopian Controls  #2 DBlock
Dystopian Controls #2 DBlockdonamore1
 
H block - protagonist
H block  - protagonistH block  - protagonist
H block - protagonistdonamore1
 
H block characteristics
H block characteristicsH block characteristics
H block characteristicsdonamore1
 
Power point guía didáctica aea
Power point guía didáctica aeaPower point guía didáctica aea
Power point guía didáctica aeaAlejandro Ramos
 

Viewers also liked (15)

How to Avoid Making PPC Mistakes
How to Avoid Making PPC MistakesHow to Avoid Making PPC Mistakes
How to Avoid Making PPC Mistakes
 
A range of reading notebooks
A range of reading notebooksA range of reading notebooks
A range of reading notebooks
 
Courier Mail Article_Career One_Russo Recruitment
Courier Mail Article_Career One_Russo RecruitmentCourier Mail Article_Career One_Russo Recruitment
Courier Mail Article_Career One_Russo Recruitment
 
Guide to Winning Micro-Moments
Guide to Winning Micro-MomentsGuide to Winning Micro-Moments
Guide to Winning Micro-Moments
 
Computación Grafica jairo andres
Computación Grafica jairo andresComputación Grafica jairo andres
Computación Grafica jairo andres
 
Power point guía didáctica AEA
Power point guía didáctica AEAPower point guía didáctica AEA
Power point guía didáctica AEA
 
Algoritmos Raster jairo andres rincon
Algoritmos Raster jairo andres rinconAlgoritmos Raster jairo andres rincon
Algoritmos Raster jairo andres rincon
 
SEO & SEM Together
SEO & SEM TogetherSEO & SEM Together
SEO & SEM Together
 
Big Data Analysis and Terrorism
Big Data Analysis and TerrorismBig Data Analysis and Terrorism
Big Data Analysis and Terrorism
 
Clase sobre las necesidades básicas de los niños (1) (1)
Clase sobre las necesidades básicas de los niños (1) (1)Clase sobre las necesidades básicas de los niños (1) (1)
Clase sobre las necesidades básicas de los niños (1) (1)
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal Information
 
Dystopian Controls #2 DBlock
Dystopian Controls  #2 DBlockDystopian Controls  #2 DBlock
Dystopian Controls #2 DBlock
 
H block - protagonist
H block  - protagonistH block  - protagonist
H block - protagonist
 
H block characteristics
H block characteristicsH block characteristics
H block characteristics
 
Power point guía didáctica aea
Power point guía didáctica aeaPower point guía didáctica aea
Power point guía didáctica aea
 

Similar to Protection of Personal Information

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
Hexagon presentation light.pptx
Hexagon presentation light.pptxHexagon presentation light.pptx
Hexagon presentation light.pptxPabRonaldCalanoc1
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017CloudWATCH Consortium
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptxDATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptxgentlejosh3161
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityARDC
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICECFG
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsWSO2
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADr. Oliver Massmann
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management Endcode_org
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Michael Adamberry
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Michael Adamberry
 
Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Kimberly Verska
 

Similar to Protection of Personal Information (20)

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
Hexagon presentation light.pptx
Hexagon presentation light.pptxHexagon presentation light.pptx
Hexagon presentation light.pptx
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
POPI_Overview_E
POPI_Overview_EPOPI_Overview_E
POPI_Overview_E
 
POPI_Overview_E
POPI_Overview_EPOPI_Overview_E
POPI_Overview_E
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017GDPR clinic - CloudWATCH at Cloud Security Expo 2017
GDPR clinic - CloudWATCH at Cloud Security Expo 2017
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptxDATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
 
3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE3A – DATA PROTECTION: ADVICE
3A – DATA PROTECTION: ADVICE
 
General Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity ArchitectsGeneral Data Protection Regulation (GDPR) for Identity Architects
General Data Protection Regulation (GDPR) for Identity Architects
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
Data Protection & Risk Management
Data Protection & Risk Management Data Protection & Risk Management
Data Protection & Risk Management
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
 
Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006
 

Recently uploaded

Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxAbhayThakur200703
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 

Recently uploaded (20)

Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptx
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 

Protection of Personal Information

  • 1. PROTECTION OF PERSONAL INFORMATION ACT NO. 4 OF 2013 (“POPI”) OCTOBER 2016
  • 2. INTRODUCTION • POPI was signed into law on 19 November 2013 • Commencement date of: • section 1; Part A of Chapter 5; and • section 112; and • section 113 was on 11 April 2014
  • 3. INTRODUCTION • Rationale behind POPI: • Section 14 of the Constitution – right to privacy • to protect the misuse and abuse of personal information in RSA and cross- border flow of information • introducing a minimum set of requirements for the processing of personal information • establishing an Information Regulator to perform duties in terms of POPI and PAIA • to align legislation with modern society
  • 4. IMPORTANT DEFINITIONS • “consent” – is any voluntary, specific and informed expression of will of which permission is given for the processing of personal information • “data subject” – is a person to whom personal information relates • “filing system” – is a structured set of personal information, whether centralised, decentralised or dispersed geographically • “operator” – is a person who processes personal information in terms of a contract or mandate
  • 5. IMPORTANT DEFINITIONS • “personal information” – is information relating to an identifiable, living, natural person, juristic person including, but not limited to: • Race, gender, pregnancy, marital status, national, ethnic or social origin • Education, medical, financial, criminal or employment history • ID, symbol, e-mail address, physical address, telephone number, location, online identifier or particular assignment to the person • Correspondence sent by the person that is explicitly or implied to be confidential or private of nature or any further information that would reveal the contents of the original correspondence • about the person
  • 6. IMPORTANT DEFINITIONS • Views or opinions of another individual about the person • Name of a person if it appears with other personal information relating to the person or if the disclosure itself would reveal the information
  • 7. IMPORTANT DEFINITIONS • “processing” – means any operation or activity or set of operations, whether or not by automatic means, concerning personal information: • the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use • dissemination by means of transmission, distribution or making available in any other form • merging, linking, as well as restriction, degradation, erasure or destruction of information • “responsible party” – is a public or private body or any person which, alone or in conjunction with others, determines the purpose of and means for processing personal information
  • 8. APPLICATION OF THE ACT • Applies to the processing of personal information where the information is entered in a record by a responsible party AND • when it is recorded by non-automated means, it forms part of a filing system or is intended to form part thereof AND • where the responsible party is domiciled in RSA • If not domiciled in RSA, but makes use of automated or non-automated means in the republic – unless those means are used only to forward personal information through the republic
  • 9. CAVEATS • If any other legislation provides for lawful processing of personal information that are more extensive, then the extensive conditions will prevail – section 3 • POPI will apply in any other case irrespective of whether other legislation provides for the lawful processing of information
  • 10. EXCLUSIONS • Section 6 determines that POPI does not apply: • when data is processed for personal or household activities • when personal information has been de-identified • if a public body processes personal information for national security, criminal matters or judicial functions • when personal information is processed for Journalistic, artistic or literary expression • Caveat in section 3 – more extensive protection in other legislation
  • 11. LAWFUL PROCESSING • There are 8 principles that has to be followed: • Accountability • Processing limitation • Purpose specification • Further processing limitation • Information quality • Openness • Security safeguards • Data subject participation
  • 12. LAWFUL PROCESSING • Accountability • The responsible party must ensure that he/she/it comply with the provisions of POPI at the time of determination of the purpose and means of the processing • Processing limitation • Lawfulness (should not infringe privacy) • Consent, justification and objection • Processing is just if there is an obligation, protects a legitimate interest of the data subject, pursuing legitimate interests of the responsible party • Consent may be withdrawn at any time
  • 13. LAWFUL PROCESSING • Minimalism – purpose for which information is processed has to be: • Relevant • Not excessive • Adequate • Collection – directly from the data subject
  • 14. LAWFUL PROCESSING • Purpose specification • Collection • Must be for a specific purpose relating to the function of the responsible party • The data subject must be informed of the purpose of collection • Retention and restriction • Not longer than it is necessary for unless required by law or for the function of the responsible party • Personal information must be destroyed, deleted or de-identified as soon as practicable after it is no longer required to be retained
  • 15. LAWFUL PROCESSING • Further processing limitation • Must be for the purpose for it was collected for • Further processing is not incompatible with the purpose if further processing is necessary for compliance with section 1 of the SARS Act, No.34 of 1997 • Information quality • Openness • Documentation • Must maintain documentation of processing operations – section 14 or 51 of PAIA • Notification when collecting data
  • 16. LAWFUL PROCESSING • Notify of the purpose of collecting the information • Whether supply is mandatory or voluntary • Flow of information is cross-border and need to advise on the other countries’ privacy laws
  • 17. LAWFUL PROCESSING • Security Safeguards • Security measures on data integrity and confidentiality • appropriate and reasonable • Identify internal and external risks • Regularly verify, review and update safeguards • Information processed by operator • Only with authorisation of the responsible party • Confidentiality • Security Compromises • Need to notify the regulator and the data subject • Notify as soon as becoming aware of breach
  • 18. LAWFUL PROCESSING • Data subject participation • Access to personal information • Correction of personal information • Manner of access – in accordance with PAIA • Prohibition on processing special personal information • Beliefs, race, sex, trade union membership and health (act contain more) • Criminal behaviour – all that is alleged • Section 27 - 33 list exclusions to special personal information
  • 19. CROSS BORDER INFORMATION FLOW • Responsible party may not transfer personal information to a 3rd party in a foreign country unless: • The 3rd party has similar privacy laws, corporate rules or a biding agreement to that effect • The data subject consents to the transfer • The transfer is necessary for contractual performance • Transfer is necessary for the conclusion of agreements in the interest of the data subject • Transfer is for the benefit of the data subject
  • 20. COMPLAINTS • Any person may submit a complaint with the Regulator • It must be in writing • The Regulator may then conduct a pre-investigation • Act as a conciliator at any time during the investigation • May decide not to take any action on a complaint • Conduct a full investigation • Refer the compliant to the Enforcement Committee • Take any other action referred to in terms of the Act
  • 21. OFFENCES AND PENALTIES • 2 categories • Serious offences – fine or imprisonment of not more than 10 years • Less serious offences – fine or imprisonment of not more than 12 months • Administrative fines – not exceeding R10 million Rand
  • 22. TRANSITIONAL ARRANGEMENTS • All processing of personal information must within 1 year conform to the Act • The 1 year period may be extended by the Minister