Demystifying data storage

August 2014 Integrated Solutions

The advent of the PoPI (Protection of Personal Information) Act sent many companies reaching for the tranquilisers. Ignorance of the Act is no excuse but organisations can quickly and easily come to grips with the parameters of data storage in terms of legislation. Hi-Tech Security Solutions discusses effective data storage, retention and disposal.

Metrofile’s managing director, Guy Kimble, points out that while the PoPI Act might be the latest act instituted for the management and storage of data, the effective management of records should already form part of an organisation’s business modus operandi.

Guy Kimble.
Guy Kimble.

According to Justin Parry, managing director of Perceptive Software’s local distributor, OrangeNow, PoPI requires proactive records management with the prescription that records of personal information should not be retained for any longer than is necessary for achieving the purpose for which the information was collected, unless the underlying law, contractual terms or in certain cases, the individual’s consent, dictate holding longer than the required retention period.

The first step in the process of managing data in accordance with PoPI is determining what data the organisation holds that is relevant to the PoPI Act. This data should then be tagged as PoPI sensitive in order to differentiate it from other company data that does not contain personal information.

Parry says that it is important for companies to put an education programme together and ensure corporate buy in. “A big part of PoPI is transparency and the ability to demonstrate a roadmap that includes both business and technology involvement. Once this is in place we normally recommend a thorough content audit – understanding specifically which processes collect, capture and store personal information and importantly the purpose for which such information is stored.

“Once understood and optimised, organisations should then ensure that documents or content management systems are sufficiently flexible to manage and classify such information with systemic and process level ability to deliver control and auditability of the document and records management components,” he adds.

It must be stressed that organisations take full responsibility for the management, secure storage and eventual disposal of data. As per the Regulator, this responsibility cannot be transferred to a third party and the third party cannot be held solely accountable for the data. By appointing a senior executive in the company as the responsible custodian of this data, they will comprehend and accept the seriousness and need to protect PoPi related data adequately.

A privacy officer should be appointed and thereby becomes responsible for the data from the moment it enters the organisation to the moment it is purged or physically destroyed. This entails identifying PoPI sensitive data together with the relevant departments throughout the organisation, classifying data, reviewing the manner of storing data, setting of retention periods, and the final disposal of the data.

When capturing data, the onus is on the organisation to make sure that the person from whom the data is being gathered is made fully aware of what data is being collected, why it is being collected, how it will be stored and for how long it will be stored. In addition, they must give permission (or not) to the organisation regarding whether information can be used by the organisation or shared with a third party for any reason other than the original intended purpose.

If for example, a visitor to the premises has to gain entrance via a boom gate, then typically the driver’s licence will be scanned and electronically stored. The organisation is responsible for ensuring that the server on which this data is stored has the requisite firewalls and SSL certificates that provide encryption of the organisation’s IT system to prevent unauthorised access to the data.

It is critical to have a records management policy and plan of action in place to ensure compliance with the PoPI Act. This will detail the type of information held by the organisation, in what format (physical/hardcopy or electronic/digital) the data will be stored and the retention policy.

In the event of a data breach, organisations must inform the Regulator and if the information is extremely sensitive (banking details and/or passwords or PIN codes) then the company needs to contact the people to whom the information belongs and provide full disclosure of the breach.

The retention period is very subjective and should be discussed with the company auditors to ensure that it complements rather than conflicts with what is required in terms of the legislated requirements. Sensibility is the keyword here and retention periods should be reasonable and justifiable.

With regard to purging and destruction of data, Kimble suggests that organisations determine feasible and reasonable retention review periods, then implement a cyclical purge of electronic data that has reached this window. Similarly, hard copy data can be destroyed, by for instance, shredding, on predefined dates. Since the fines and ­penalties around inappropriate disposal of hardcopy material are quite onerous, it is often prudent to secure the services of a company that will provide a secure shredding service. The appointed privacy officer will be responsible for ensuring that a record is kept as evidence as to the manner in which data was disposed of.

Depending on the size of your organisation, the amount of data you have, and the competencies and capacities of your employees, it is often advisable to seek counsel and assistance from specialists in the field of data storage.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Human-centric control rooms
Iritron Integrated Solutions Surveillance Residential Estate (Industry)
Iritron and Oculus show that when it comes to control rooms, people, not just technology, are at the centre of the most significant performance differentiators today, not just how efficiently the technology works.

Read more...
Cape Town estates gain access to advanced security technology at Securex
Securex South Africa News & Events Integrated Solutions
For the first time, estate and complex security decision-makers in the Western Cape will have direct access to the breadth of solutions and expertise these shows are synonymous with.

Read more...
Smarter security for safer estate living
neaMetrics Suprema Integrated Solutions Surveillance Access Control & Identity Management Residential Estate (Industry)
The expansion of residential estates has led to many communities being constructed with security as an afterthought. Unfortunately, fencing, cameras, and a guard at the gate only create a false sense of safety, which vanishes after the first incident.

Read more...
Making drone security more accessible
Editor's Choice Integrated Solutions Residential Estate (Industry) AI & Data Analytics IoT & Automation
Michael Lever discusses advances in drone technology, focusing on cost reductions and the implementation of automated services, including beyond line of sight capabilities, for residential estates with SMART Security Solutions.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
SMART Estate Security Conference KZN 2025
Arteco Global Africa OneSpace Technologies SMART Security Solutions Technews Publishing Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
May 2025 saw the SMART Security Solutions team heading off to Durban for our annual Estate Security Conference, once again hosted at the Mount Edgecombe Country Club.

Read more...
Community-centric security architecture
Regal Security Distributors SA Integrated Solutions Residential Estate (Industry)
Securing any large area, whether it is a commercial park or a residential estate, is as much about protecting and monitoring the internal environment as it is about protecting the perimeter.

Read more...
Identity, Security & Access Alliance focuses on intelligence and integration
SMART Security Solutions Ideco Biometrics BoomGate Systems Bosch Building Technologies Technews Publishing Integrated Solutions Surveillance Access Control & Identity Management
The Identity, Security & Access Alliance (ISAA) hosted several launch events in Johannesburg in August, showcasing the participating companies’ technical solutions with a primary focus on the solutions made possible by integrating high-quality systems to deliver comprehensive solutions.

Read more...
Make BIG and COMPLEX small and manageable
neaMetrics Suprema AI & Data Analytics Surveillance Integrated Solutions
Traditional CCTV and access systems often operate separately, creating gaps in visibility and efficiency. TRASSIR and Suprema have partnered to develop an integrated platform that improves security, operations, and situational awareness.

Read more...
Layered security for complex spaces
Regal Security Distributors SA Integrated Solutions Industrial (Industry) Commercial (Industry)
The positive impact of loss prevention and risk management on the bottom line is far more than just a number; it means that assets are physically secure, insurance premiums remain low, and people are protected.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.