Information protection resources for video surveillance companies

Issue 3 2021 Editor's Choice

Cathexis Technologies values data protection. It is also committed to helping its clients comply with data protection laws. Cathexis has therefore produced a PoPIA Privacy Guide[1] that provides guidelines for understanding and applying personal data protection when using CathexisVision video surveillance management software.

The Protection of Personal Information Act (PoPIA) was signed into law in South Africa in 2013, with various sections coming into effect in the years that followed. It is a comprehensive law which aims to protect individuals’ personal data, by holding organisations accountable for capturing, processing and storing personal information responsibly. What is personal information? Under PoPIA, it is data that identifies, relates to, describes, or could reasonably be linked with a particular consumer.

While the deadline for companies to register a data protection officer has already passed (31 March 2021), the deadline for enforcement of PoPIA by the Information Regulator is 1 July 2021. PoPIA applies to any organisation operating in South Africa, or organisations operating outside South Africa which offer products and services to customers or businesses within South Africa. Compliance depends on the combination of an organisation’s access to and use of personal data.

Eight conditions[2] form the foundation of compliance and determine how personal information may be legally gathered, processed and held under the Act: accountability, processing limitations, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation. PoPIA also outlines rights which authorise people to know the operator’s purpose in using their personal data and allows them to check that it is being carried out lawfully.

Privacy is necessarily about security: for information to remain private, it must also be held securely. By strengthening your organisation’s cybersecurity measures, you can strengthen its likelihood of compliance with the PoPI Act. Why is compliance important? There are risks to non-compliance: damage to the company’s reputation and enforcement action by the Information Regulator.

As the limits of PoPIA have not yet been tested by the courts and Information Regulator, the best business plan is to act to mitigate risks and prioritise personal data protection. Yet compliance is not simply about avoiding penalties. By developing an organisational culture underpinned by cybersecurity and respect for your customers’ privacy rights, your company can protect its brand, gain a competitive advantage and build trust with consumers.

Privacy by design is a core principle of the Protection of Personal Information Act. Privacy and security need to be embedded within all of your organisation’s practices, systems and technology, demonstrating a culture of data protection. In short, your company needs to know and document what data it holds, its source, who it is shared with and how it is used.

The features in CathexisVision software that support PoPIA compliance measures include optional database shredding, data encryption, video signing, archive security, password control and watermark overlays on video footage. For more information, you can consult the official PoPIA website[3] and the PoPIA Privacy Guide[1] developed by Cathexis Technologies, which has been tailored to address compliance in the security sector and the use of video surveillance software.


Steps to take to ensure PoPIA compliance within your organisation

• Appoint an information officer and deputy within the organisation.

• Train staff in data protection and PoPIA compliance.

• Carry out a personal information impact assessment to assess your company’s compliance.

• Develop a compliance framework which includes the organisation’s policies regarding data collection, usage, storage, and security and the company process for handling complaints.

• Document all personal data processing activities.

• Communicate clearly with data subjects and customers: make it easy for them to access Data Subject Access Request forms and provide on-site and online notices when collecting personal information.

• Ask for data subjects’ consent when collecting information, record that consent and review the company’s processes for requesting and recording consent.

• Only store personal data as long as is necessary for the original lawful purpose of its collection.

• Create procedures for responding to data subject access requests and an information security policy for identifying and managing possible data breaches.

• Depending on the size of your company and the scale of data processing it carries out, budget for compliance measures, covering legal help, assessments, insurance and training.

For more information contact Cathexis Africa, +27 31 240 0800, info@cathexisvideo.com, www.cathexisvideo.com

[1] https://cathexisvideo.com/resources/cathexisvision-privacy-guide/

[2] https://popia.co.za/protection-of-personal-information-act-popia/chapter-3-2/chapter-3/

[3] https://popia.co.za/


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Enhance control rooms with surveillance and intelligence
Leaderware Editor's Choice Surveillance Mining (Industry)
Dr Craig Donald advocates the use of intelligence and smart surveillance to assist control rooms in dealing with the challenges of the size and dispersed nature common in all mining environments.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Mining (Industry) Risk Management & Resilience
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
A constant armed struggle
Technews Publishing XtraVision Editor's Choice Integrated Solutions Mining (Industry) IoT & Automation
SMART Security Solutions asked a few people involved in servicing mines to join us for a virtual round table and give us their insights into mine security today. A podcast of the discussion will be released shortly-stay tuned.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Risk Management & Resilience
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Risk Management & Resilience
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Unlocking Africa's AI potential
Editor's Choice News & Events AI & Data Analytics
Africa's AI market is set to grow exponentially; by investing in AI education, training, and ethical practices, African nations can harness the power of AI to transform the continent and create a brighter future for its people.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Risk Management & Resilience
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...
Entries to southern Africa OSPA Awards now open
Technews Publishing Securex South Africa Editor's Choice News & Events
The southern Africa OSPAs are part of a global awards scheme that recognises and rewards teams, individuals and organisations for their commitment and outstanding performance within the security sector.

Read more...
Securex has moved to June
Technews Publishing Editor's Choice News & Events
Following the formal announcement of the date for South Africa’s national election, 29 May 2024 , which happened to be in the middle of the planned dates for Securex South Africa, Securex will now take place from 11 – 13 June 2024 at Gallagher Estate in Midrand.

Read more...