The Protection of Personal Information Act (or POPI Act) is South Africa’s equivalent of the EU GDPR. It sets some conditions for responsible parties (called controllers in other jurisdictions) to lawfully process the personal information of data subjects (both natural and juristic persons).
Is Popi Act in force?
In a statement, the law firm said: “We can confirm that Popi Act is still coming fully into effect on 1 July 2021.” The act was signed into law in 2013 but parts of it became effective a year later.
If you fail to comply with the POPI Act, whether intentional or accidental, you can be liable for an administrative fine of up to R10 million. If your clients are impacted by a data breach, POPIA even empowers them to take civil action for damages.
How do I comply with Popi?
What are the steps to become POPI Compliant?
Step 1: Create Awareness. Ensure your employees are aware of the POPI Act and the regulations set out which they need to adhere to.Step 2: Data Collection Assessment. Step 3: Company Policies Review. Step 4: Gap Audit. Step 5: Implementation and Training.
The regulator may exempt a responsible party from having to comply with POPIA (or part of it) if: the public interest outweighs the interference of privacy, or. the benefit to the data subject (or third party) outweighs the interference of privacy. (section 37)
Who must register for Popi?
The Act applies to any person or organisation who keeps any type of records relating to the personal information of anyone, unless those records are subject to other legislation which protects such information more stringently.
How do I report a Popi violation?
Complaints (complete POPIA/PAIA form 5):
– should you feel that your personal information has been violated, you may use this e-mail address to lodge a complaint.
Condition 7 details the security measures POPI requires for personal information. It says that the responsible party must employ “appropriate, reasonable technical and organizational measures” designed to prevent both unlawful access and the loss or damage of the personal information.
What are the 8 conditions of the POPI Act?
Principle 1: Accountability. Principle 2: Processing Limitation. Principle 3: Purpose Specification. Principle 4: Further Processing Limitation.
Why should you comply with POPI Act?
The POPI Act requires businesses to regulate how information is organised, stored, secured, and discarded. This ensures that the business can maintain the integrity and confidentiality of its clients’ and employees’ personal information by preventing loss, damage, and unauthorised access to the personal data.
What size companies are affected by Popi act?
The general rule of thumb is that if you have an organisation that has less than 50 employees then you would be considered a “small” business from a data protection perspective. Companies with more than 50 employees, would fall into the category of an SME or large corporate.
POPI is applicable to any person, business or entity that processes personal information of data subjects, for example profit companies, non-profit companies, hospitals and medical practitioners, medical schemes, insurers, attorneys, estate agents, government departments, state owned companies and entities and
When was the POPI Act gazetted?
The Protection of Personal Information (POPIA) Act has been signed into law by the President on 19 November and published in the Government Gazette Notice 37067 on 26 November 2013.
What is date of effect of an act?
4.2 A Bill that has been assented to and signed by the President becomes an Act of Parliament and must be published shortly thereafter in the Gazette. An Act takes effect (becomes binding on everyone) when it is published in the Gazette or on a date determined in terms of the Act.
What is Popi policy?
an external customer privacy policy (sometimes called a POPI policy), a general corporate or legal compliance policy, which sometimes covers what is in a data protection policy but in a general way, a project charter.
The 8 POPIA Conditions:
The POPI Act is a new all-inclusive piece of legislation that safeguards the integrity and sensitivity of private information. Companies are required to carefully manage the data capture and storage process of Personal Information within the lawful framework as set out in the Act.
When did Popi come into force?
Here is a practical guide to the most important aspects of the POPI act which will come into effect on 1 July 2021. All businesses with employees, customers and suppliers must comply with the Protection of Personal Information Act (often called the POPI Act or POPIA) which comes into effect on 1 July 2021.