What is POPI all about?
POPI refers to South Africa’s Protection of Personal Information Bill which seeks to regulate the Processing of Personal Information.
Personal Information broadly means any information relating to an identifiable, living natural person or juristic person (companies, CC’s etc.) and includes, but is not limited to:
- contact details: email, telephone, address etc.
- demographic information: age, sex, race, birth date, ethnicity etc.
- history: employment, financial, educational, criminal, medical history
- biometric information: blood type etc.
- opinions of and about the person
- private correspondence etc.
Processing means broadly anything done with the Personal Information, including collection, usage, storage, dissemination, modification or destruction (whether such processing is automated or not).
Some of the obligations under POPI are to:
- only collect information that you need for a specific purpose
- apply reasonable security measures to protect it
- ensure it is relevant and up to date
- only hold as much as you need, and only for as long as you need it
- allow the subject of the information to see it upon request
When will POPI affect me?
The Bill is expected to become law in early 2013. A compliance grace period of 1 year will exist, which may be extended to a maximum 3 years after the Act has come into force.
Does POPI really apply to me?
Accountability for compliance rests with a Responsible Party, meaning a public or private body or any other person which,
alone or in conjunction with others, determines the purpose of and means for processing personal information. Generally the Responsible party must be resident in South Africa or the processing should occur within South Africa (subject to certain exclusions).
There are cases where POPI does not apply. Exclusions include:
- purely household or personal activity
- sufficiently de-identified information
- some state functions including criminal prosecutions, national security etc.
- journalism under a code of ethics
- judiciary functions etc.
Why should I comply with POPI?
POPI promotes transparency with regard to what information is collected and how it is to be processed. This openness is likely to increase customer confidence in the organisation.
POPI compliance involves capturing the minimum required data, ensuring accuracy, and removing data that is no longer required. These measures are likely to improve the overall reliability of the organisation databases.
Compliance demands identifying Personal Information and taking reasonable measures to protect the data. This will likely reduce the risk of data breaches and the associated public relations and legal ramifications for the organisation.
Non-compliance with the Act could expose the Responsible Party to a penalty of a fine and / or imprisonment of up to 12 months. In certain cases the penalty for non-compliance could be a fine and / or imprisonment of up 10 years.
Who is affected by this legislation?
The answer is quite simple – everybody. Every business will have to align itself with this Act or face the consequences, and every individual and business is entitled to the protection afforded by this Act.
How bulky is the process to align with the legislation?
Depending on the current practices and policies of the business, experts in the field estimate anything from 6 months to 5 years.
Who is going to be held accountable should I not comply with the legislation?
The business owner/s will be held accountable in terms of this Act.
I run a small business with few personnel and clients. Why must I adhere to this Act?
The Act does not make a distinction between small, medium or large businesses and everybody is measured according to the same standard.
What is the benefit for me/my business when I comply with this Act?
The benefit lies in the fact that you are operating lawfully in terms of the South African legislation. Consumer confidence studies have shown that consumers would, in 90% of cases, much rather do business with companies that are transparent who complies with legislation, than any other business.
What is personal information?
The definition of Personal Information in terms of the legislation makes it difficult, if not impossible, to exclude ANY information as not being personal.
What are the consequences should I decide to not comply with the legislation?
The Act is clear in this regard and administrative fines can reach up to R 10 million and / or imprisonment for up to 10 years.