IMPORTANT UPDATE ON THE EFFECTIVE DATE FOR THE POPI ACT

IMPORTANT UPDATE ON THE EFFECTIVE DATE FOR THE POPI ACT

EFFECTIVE DATE FOR THE POPI ACT

Businesses operating in South Africa are presently awaiting the implementation date of the Protection of Personal Information Act 4 of 2013 (POPI Act).

The president is expected to act on the request made by the Information Regulator after various statements about the commencement date. It is likely that the Act will come into effect in April 2020. There will be a one-year transitional period after the commencement date for all companies to comply with its provisions.

Which sections of the Act are already being implemented?

Limited sections of the Act are already being implemented, but the implementation of most of the POPI Act provisions dealing specifically with the compliance requirements applicable to enterprises are expected to be announced by the President on a later date, in all probability April this year.

Sections of the Act that are already effective include the following:

  • The definitions (Section 1)
  • The establishment of the Information Regulator; the powers, duties and functions of the Regulator; appointment and terms of office of members of the Regulator; and appointment of staff and the chief executive officer (Part A of Chapter 5);
  • The Minister may promulgate Regulations relating to the establishment of the Regulator and in turn allow the Regulator to promulgate Regulations in respect of certain areas (Section 112 of the Act); and
  • The procedures for promulgating Regulations by the Minister and the Regulator (Section 113).

What will the impact of the POPI Act be on businesses?

POPI assigns responsibility for protecting personal data to a responsible party (and not the Information Regulator). A responsible party is a public or private body or any other person that determines the purpose of and means for processing personal information.

All South African businesses should have started their POPI audit processes, not only to ensure compliance but also to avoid unnecessary costs and ultimately participate in the global data economy.

Organisations that need to comply with both the POPI Act and the General Data Protection Regulation (GDPR) should first focus on complying with the GDPR to ensure that Personal data can only flow freely between the European Union (EU) and South African companies.

In conclusion

To fully implement POPI is an onerous process and involves on-site audits, assessments, amendment of agreements with certain suppliers and training of staff. Businesses should therefore start implementing the compliance requirements as soon as possible to ensure proper implementation. In one of our earlier blogs, 'Final POPI Act regulations published - what you should know', we have touched on the first few steps that are crucial for organisations to start complying, raise awareness and begin the planning process.

SERR Synergy assists businesses in compiling Data and Information Protection Reports. Our professional legal team ensures that physical information and cybersecurity risks of organisations are identified and managed to maintain the confidentiality, integrity and availability of data. We provide various policies for organisations to implement in order to ensure compliance in such a way that it provides business value to our clients and allows for improvement in efficiencies and effectiveness by meeting the compliance requirements.

About the Author: Retha van Zyl completed her BCom Hons (Economics and Risk Management) studies at the North West University. She joined our team in January 2016 and currently holds the title ‘Information Compliance Advisor’. She specialises in POPI and PAIA compliance, which includes compiling and submitting PAIA Manuals to the Human Rights Commission. She also compiles the Data and Information Protection Report to identify risks associated with information security and drafts Information Security policies for procedural compliance in each department within an organisation.

Sources:
  1. https://www.michalsons.com/blog/popi-commencement-date-popi-effective-date/13109?gclid=CjwKCAiA44LzBRB-EiwA-jJipJ2-OPtX0--DoAj3_7-rTEE-sMN2HU0kO404oZxF7ELihYunfnu0BhoCXNMQAvD_BwE
  2. https://printingsa.org/update-on-popi/
  3. https://www.saica.co.za/Technical/LegalandGovernance/Legislation/ProtectionofPersonalInformationAct/tabid/3335/language/en-ZA/Default.aspx

Newsletter Inner

Get Instant Access to This Download

Enter your details below, and we'll email the pdf straight to your inbox.

Upload requirements

You May Also Like

 
POPI Act Guidelines - Processing Personal Information subject to Prior Authorisation
Personal information has become one of the most powerful commodities in the modern world. In this new age of processing Personal Information, companies that process Personal Information outside the borders of South Africa will be subject to foreign data privacy and protection laws such as the General Data Protection Regulation (GDPR).
 
Embracing digital technologies: the key to thriving in today's changing markets
Exploring the importance of companies embracing digital technologies to adapt to changing markets and ensure success in the long run.
 
IMPORTANT UPDATE ON THE EFFECTIVE DATE FOR THE POPI ACT
Businesses operating in South Africa are presently awaiting the implementation date of the Protection of Personal Information Act 4 of 2013 (POPI Act).