Insights into PoPIA compliance

Issue 3 2021 Security Services & Risk Management

By now everyone knows PoPIA (The Protection of Personal Information Act) becomes a reality on 1 July 2021 and there will be no extensions. For those who may not have prepared or even know what they need to be doing, Hi-Tech Security Solutions asked Carrie Peter, solution owner at Impression Signatures for a few insights on what this piece of legislation means in the real world.

Hi-Tech Security Solutions: What are the realities when it comes to PoPIA compliance? Do companies have to reinvent the wheel to be compliant?

Carrie Peter: In some cases they will have to reinvent the wheel, but that will be dependent on their internal security and privacy controls. From something as simple as a customer completed form, to far more complex systems that hold deeply private data such as medical records, minimalism and privacy needs to be baked in. The extent to which a company will have to reinvent the wheel will depend on where the company is at starting position.


Carrie Peter.

Due to safety and privacy issues, many organisations may already be in a position where they have been complying to regulations, such as informing the customer of the reason for retaining information. For these organisations, compliance may just involve slight adjustments in protocol. For other organisations, compliance may entail more extensive steps and re-configurations.

Hi-Tech Security Solutions: Apart from the threats of jail for directors, what are the real risks of non-compliance (from legal and other perspectives)?

Carrie Peter In addition to potential imprisonment, non-compliance may lead to heavy fines. Section 107 of the Act states: “For the more serious offences the maximum penalties are a R10 million fine or imprisonment for a period not exceeding 10 years or to both a fine and such imprisonment. For the less serious offences, for example, hindering an official in the execution of a search and seizure warrant, the maximum penalty would be a fine or imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.”

Further to this, the costs that can be caused by data breaches and security issues can make the fines seem light. Reputational damage, productivity losses and data losses can cause millions of rands in damage. Responding to a minor cyber incident can cost millions of rands. Organisations that do not comply also run the risk of losing the confidence of their customers and clients, since the Act has been instated to protect the privacy and confidentiality of their information, this loss of trust can potentially result in a downturn in business.

Hi-Tech Security Solutions: What should companies be ready for in terms of people asking what private information the organisations hold for them? Can an individual insist a company provides and then deletes all info they have on them? How long does a company have to supply/delete such personal information?

Carrie Peter: According to the Act, the data subject must be informed about the reason for the information requested. The organisation also has to inform the data subject about and gain permission for, the sharing of that personal information to any additional third parties. The data subject has the right to request the reason for personal information obtained at any time.

The data subject also has the right to request what information an organisation has about the subject and to order the deletion of that information. The organisation must comply and the information must be deleted immediately upon request without any penalties, conditions or fines to the data subject.

Hi-Tech Security Solutions: With 1 July looming, what are your top three tips for companies to ensure they are compliant or will be compliant?

Carrie Peter: My suggestions are:

1. Understand what private data you hold and what private data you need to hold – gather and hold only what you need.

2. Understand consent – it is fine to gather and hold data if you have consent to do so. Make sure that all data obtained has the consent of the data subject.

3. Trust no one – develop a risk management and mitigation programme and regularly assess your day-to-day practices against this. Keep record of compliance measures at all times.

For more information go to www.impression-signatures.com


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Alarms are smarter than ever
Spectrum Security Products Technews Publishing SMART Security Solutions Arxtech Perimeter Security, Alarms & Intruder Detection
Modern smart alarms are evolving beyond simple sirens and basic alerts. They now include features such as system health checks, remote management, real-time notifications, mobile apps, and multiple communication options.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.