Start preparing for PoPI

1 March 2017 Editor's Choice, Security Services & Risk Management

The Protection of Personal Information Act (PoPI) may not have been made effective yet, but businesses need to make compliance one of their top priorities for 2017. This according to Wayne Clarke, managing director of Metrofile Records Management, who states that the appointment of the Information Regulator by the President is imminent.

Wayne Clarke.
Wayne Clarke.

“From the appointment of the regulator, companies will officially have one year to update their databases and practices or risk facing massive fines, or even imprisonment for liable individuals. While many businesses have already proudly proclaimed that they are PoPI compliant, there is a startling number of companies that are not,” he says.

“We see quite a few companies that are either behind schedule on their PoPI compliance plans, or that have not started a meaningful compliance strategy at all. In fact, the 2015 Records and Information Management Trends Index commissioned by Metrofile, indicated that 22% of South African companies have not started to implement compliance measures related to their record storage and management.”

South African businesses should realistically already have started their PoPI implementation processes, in order to ensure compliance by the cut-off date. “Converting any company’s records and information systems to reach a state of compliance is a long and expensive process, which is why organisations realistically require a multi-year time frame. That said, it is not impossible for a company to reach a state of compliance within 12 months.”

The first step, according to Clarke, is to outsource the company’s conversion strategy. “In light of the significant pressure that is now on unprepared businesses, the decision to outsource their PoPI related responsibilities such as secure record storage, management and destruction, may be an ideal solution. Keep in mind however, that accountability cannot be outsourced to an information management provider. A company is still responsible for ensuring and enforcing its own compliance.

Clarke provides the following PoPI checklist to further assist businesses:

Month 1 – Find a service provider fast

Now is the time to find a PoPI compliance service provider. Reputable law firms are often considered the best options for lead service providers in this instance, but specialist record storage, software and training service providers are also viable options, depending on the nature and needs of the business.

Month 2 – Classify and understand

The first step in the company’s PoPI compliance plan is to start classifying the information that is kept on file. Know exactly which of the company’s data contains personal information, determine why it is being retained, and define how long it needs to be kept. If the information in question is not essential to the company’s operations, earmark it for deletion.

Month 3 – Conduct an internal audit

Your company’s contract with the chosen service provider should be in the final processes of being negotiated. Conduct an initial internal audit of the company’s processes used to collect, record, store, disseminate and destroy personal information. Use the information gathered in this audit to make an initial assessment of where information is at risk or is being duplicated.

Month 4 – Deal with unnecessary information

The first of PoPI’s compliance conditions is the purpose requirement. The service provider’s first task should be to assist in destroying all pieces of personal information that the company does not need. Both digital and physical files need to be processed by a reputable document destruction service, in order to guarantee that no information is compromised.

Month 5 – Transparency is key

A company must notify its data subjects, where, how and why their data is being stored. With this in mind, the company now needs to start work on a process to inform clients the name and address of the company processing their information, whether said information is voluntary or mandatory, and what this information will and will not be used for.

At the same time, the service provider should already be in the process of updating and securing the company’s information and data backup system. This is no quick process, and a company needs to be prepared to work around any interruptions that might be caused by this over the coming months.

Month 6 – Evaluate data capturing processes

The compliance condition for this month is information quality. With the service provider still updating data storage, this month should be spent in consultation with them on how to maintain data value, and devising reasonable processes for employees to follow in order to effectively capture and file accurate information.

Month 7 – Staff training

While in the process of changing employee procedures, this month is also the time to address the compliance condition of responsibility. All company employees are responsible for conforming to the regulations regarding clients’, employees’ and company personal information. Therefore, the company-wide policies, responsibilities and roles for data handling, have to be established and complied with.

Focus of secondary data processing

For the compliance condition of additional processing, the service provider and the company this month need to lay down clear-cut processes for the further processing of existing information. Conducting client updates and sharing information between departments must be in line with the same regulations that apply to initial data collection. Keep in mind that the company also requires a procedure to deal with data subject objections and requests.

Month 9 – Information Security

The PoPI legislation requires all-round security as part of its compliance conditions. This should be the service provider’s forte, meaning that now is the time to officially gain clarity from the service provider on the following functions, going forward:

• How personal information will be protected from unauthorised or unlawful access, unnecessary mutilation or deletion.

• How to ensure the reliability of personal information, both from a technical and operational standpoint.

• How these standards will be ensured with all parties that receive data from, or process data on behalf of your company.

Month 10 – Define boundaries

The penultimate compliance condition to address is the restriction of processing. A defined boundary needs to be established regarding the processing of personal information. Keep in mind that a company cannot claim ownership of any personal information, and the company now needs to relay clear instructions to its employees on what they can and cannot do with said information.

Month 11 – Time to troubleshoot

If all is going to plan, the majority of the company’s PoPI compliance procedures are in place and ready to be used. Keeping in mind that the company should be ready to engage the regulator and the public from next month, the service provider now needs to assist in systems checks and final troubleshooting of the existing procedures and systems.

Month 12 – Client and stakeholder involvement

Data subject involvement is the final compliance condition to master. With the majority of the company’s PoPI conditions in order, the company should be ready to withstand the intense scrutiny of its existing and potential clients.

If you have not done so already, inform your clients of their right to update or delete personal information from any of the company’s systems. Remind the client that they may, at any time, request a validation from the company as to whether their personal information is held. They are also entitled to a description and reason for the retention of said personal information.

When the Information Regulator’s powers are in full effect, along with the penalties for non-compliance, the company needs to be in a position to declare the processing of personal information to the Regulator.

The company now needs to look towards maintaining its levels of compliance. Under the new regulator, companies need to commit to annual reassessments of their information systems. The regulator will also continuously be looking at new types of personal information, and businesses will need to stay abreast of these changes as they happen.

“It is important for businesses to understand that they can achieve most if not all of the requirements set out in the PoPI Act. There are of course more and less vital aspects of PoPI, and companies reporting honestly to the new Information Regulator, are likely to be given additional time to attain compliance with some of PoPI’s less pressing points. This grace will of course be reliant on the level of compliance that the company has already attained,” Clarke concludes.

For more information go to www.metrofile.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.