Data generated from smart buildings must be PoPIA-compliant

Issue 4 2021 Security Services & Risk Management

The Covid-19 pandemic has irrevocably changed the way buildings are being designed, constructed and managed.

Architects and building owners are turning to technology to deliver an enhanced user experience as occupants increasingly demand buildings that are not only intelligent and more energy efficient, but also hygienically safe, especially in high-traffic commercial environments such as offices, hotels, shopping malls, airports and hospitals.

“The creation of smart buildings can yield considerable value when it comes to monitoring occupancy rates and supporting a safe and healthy environment, but it must be remembered that digitally engineered buildings generate a substantially large quantity of data,” says Databuild CEO, Morag Evans.

“And while the collection of data can be extremely useful in gaining insights that help improve the overall safety and well-being of building occupants, gathering information on behavioural patterns includes personal data and this must be processed in a manner that does not infringe on building occupants’ rights.”

The Protection of Personal Information Act (PoPIA), which came into effect on 1 July, specifically seeks to protect personal information and prevent it from being misused and abused.

According to the Act, everyone has a right to privacy and protection against the unlawful collection, retention, dissemination and use of personal information.

“The management and protection of personal data is therefore a key consideration for smart building owners and landlords,” says Evans.

Minimise data collection

“One of the best ways to mitigate the risk of non-compliance with PoPIA regulations is to minimise the volume of data that is collected,” she advises. “Only collect what is necessary for immediate usage. For example, temperature and lighting sensors can be used to change settings when persons enter and leave a room. Storing users’ individual preferences significantly increases the volume of data being collected as the system is required to ‘remember’ these preferences. Sensors that function on standard settings, however, are far less data dependent.”

Ensure data security

PoPIA also requires that adequate control measures be put in place to safeguard all the data being collected. “Building owners and landlords are not only required to ensure that the data is secure from a technical perspective, but also that in the event of a data breach, the fallout can be dealt with effectively and speedily. The larger the amount of data collected, the harder this is to do.”

Design with PoPIA in mind

“The Coronavirus has redefined the way people relate to the buildings in which they work, live and meet and technology – and the data it generates – is playing a pivotal role in the development of safe and efficient spaces.

“It is therefore imperative that these smart infrastructures are designed and built with data and personal information protection measures in mind to ensure that this data does not fall into the wrong hands,” Evans concludes.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Visualise and mitigate cyber risks
Security Services & Risk Management
SecurityHQ announced its risk and incident management capabilities for the SHQ response platform. The SHQ Response Platform acts as the emergency room, and the risk centre provides the wellness hub for all cyber security monitoring and actions.

Read more...
Eighty percent of fraud fighters expect to deploy GenAI by 2025
Security Services & Risk Management
A global survey of anti-fraud pros by the ACFE and SAS reveals incredible GenAI enthusiasm, according to the latest anti-fraud tech study by the Association of Certified Fraud Examiners (ACFE) and SAS, but past benchmarking studies suggest a more challenging reality.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Security Services & Risk Management
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...