Insights into PoPIA compliance

Issue 3 2021 Security Services & Risk Management

By now everyone knows PoPIA (The Protection of Personal Information Act) becomes a reality on 1 July 2021 and there will be no extensions. For those who may not have prepared or even know what they need to be doing, Hi-Tech Security Solutions asked Carrie Peter, solution owner at Impression Signatures for a few insights on what this piece of legislation means in the real world.

Hi-Tech Security Solutions: What are the realities when it comes to PoPIA compliance? Do companies have to reinvent the wheel to be compliant?

Carrie Peter: In some cases they will have to reinvent the wheel, but that will be dependent on their internal security and privacy controls. From something as simple as a customer completed form, to far more complex systems that hold deeply private data such as medical records, minimalism and privacy needs to be baked in. The extent to which a company will have to reinvent the wheel will depend on where the company is at starting position.


Carrie Peter.

Due to safety and privacy issues, many organisations may already be in a position where they have been complying to regulations, such as informing the customer of the reason for retaining information. For these organisations, compliance may just involve slight adjustments in protocol. For other organisations, compliance may entail more extensive steps and re-configurations.

Hi-Tech Security Solutions: Apart from the threats of jail for directors, what are the real risks of non-compliance (from legal and other perspectives)?

Carrie Peter In addition to potential imprisonment, non-compliance may lead to heavy fines. Section 107 of the Act states: “For the more serious offences the maximum penalties are a R10 million fine or imprisonment for a period not exceeding 10 years or to both a fine and such imprisonment. For the less serious offences, for example, hindering an official in the execution of a search and seizure warrant, the maximum penalty would be a fine or imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.”

Further to this, the costs that can be caused by data breaches and security issues can make the fines seem light. Reputational damage, productivity losses and data losses can cause millions of rands in damage. Responding to a minor cyber incident can cost millions of rands. Organisations that do not comply also run the risk of losing the confidence of their customers and clients, since the Act has been instated to protect the privacy and confidentiality of their information, this loss of trust can potentially result in a downturn in business.

Hi-Tech Security Solutions: What should companies be ready for in terms of people asking what private information the organisations hold for them? Can an individual insist a company provides and then deletes all info they have on them? How long does a company have to supply/delete such personal information?

Carrie Peter: According to the Act, the data subject must be informed about the reason for the information requested. The organisation also has to inform the data subject about and gain permission for, the sharing of that personal information to any additional third parties. The data subject has the right to request the reason for personal information obtained at any time.

The data subject also has the right to request what information an organisation has about the subject and to order the deletion of that information. The organisation must comply and the information must be deleted immediately upon request without any penalties, conditions or fines to the data subject.

Hi-Tech Security Solutions: With 1 July looming, what are your top three tips for companies to ensure they are compliant or will be compliant?

Carrie Peter: My suggestions are:

1. Understand what private data you hold and what private data you need to hold – gather and hold only what you need.

2. Understand consent – it is fine to gather and hold data if you have consent to do so. Make sure that all data obtained has the consent of the data subject.

3. Trust no one – develop a risk management and mitigation programme and regularly assess your day-to-day practices against this. Keep record of compliance measures at all times.

For more information go to www.impression-signatures.com


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Amendments to the Private Security Industry Regulations
Technews Publishing Agriculture (Industry) News & Events Associations
SANSEA, SASA, National Security Forum, CEO, TAPSOSA, and LASA oppose recently published Amendments to the Private Security Industry Regulations regarding firearms.

Read more...
Local is a lekker challenge
Secutel Technologies Technews Publishing AI & Data Analytics
There are a number of companies focused on producing solutions locally, primarily in the software arena, but we still have hardware producers churning out products, many doing business locally and internationally.

Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.

Read more...
Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...
How can South African organisations fast-track their AI initiatives?
AI & Data Analytics Security Services & Risk Management
While the AI market in South Africa is anticipated to grow by nearly 30% annually over the next five years, tapping into the promise and potential of AI is not easy.

Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year, SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.

Read more...
From the editor's desk: What’s a trillion between friends?
Technews Publishing News & Events
Back in the bad old days of 2015, some (who didn’t want to take the blame for coming up with that number) estimated the amount of money lost to corruption by the South African government to be around ...

Read more...
Stallion repositions itself as a services provider
News & Events Security Services & Risk Management
Stallion has rebranded as Stallion Integrated Solutions to reflect its expanded capabilities beyond traditional security services to delivering integrated solutions that enhance safety, asset management, and operational efficiency.

Read more...
Seven tips to help ensure your backup batteries work
Power Management Security Services & Risk Management
Load shedding is back, officially or not. Lance Dickerson offers seven tips to prolong the life of your power backup systems and ensure they perform as intended when needed.

Read more...
Cybersecurity best practice
Information Security Security Services & Risk Management
Breach and attack simulation has become an essential element of cybersecurity strategies in any modern business by allowing companies to actively detect and resolve vulnerabilities through real-world attack simulations.

Read more...