
Quick overview of the Protection of Personal Information Act PoPiA
The Protection of Personal Information Act (POPI Act), akin to the EU GDPR in South Africa, establishes specific parameters for responsible parties (referred to as controllers in other jurisdictions) to lawfully process the personal information of data subjects, encompassing both natural and juristic persons. Unlike mandating consent from data subjects for processing, the POPI Act places the responsibility on the entity determining the purpose and method of personal information processing to adhere to stipulated conditions. Comprising eight general conditions and three additional ones, the responsible party is also accountable for ensuring compliance by their operators, who undertake the actual processing.
The significance of the POPI Act lies in its role in safeguarding data subjects against potential harm, such as theft and discrimination. Non-compliance poses various risks, including reputational damage, substantial fines, imprisonment, and potential damages claims payable to affected data subjects. Notably, the primary risk, following reputational damage, is the imposition of fines for the failure to adequately protect account numbers.
The most profound impact is observed in organizations extensively processing personal information, particularly special personal information, data pertaining to children, and account numbers. Industries significantly affected by the POPI Act include financial services, healthcare, and marketing.
Offences, Penalties and Administrative Fines
Sections 100 – 106 of the POPI Act deal with instances where parties would find themselves “guilty of an offense”. The most relevant of these are:
- Any person who hinders, obstructs or unlawfully influences the Regulator;
- A responsible party which fails to comply with an enforcement notice;
- Offences by witnesses, for example, lying under oath or failing to attend hearings;
- Unlawful Acts by responsible party in connection with account numbers;
- Unlawful Acts by third parties in connection with account number.
- Section 107 of the Act details which penalties apply to respective offenses.
For the more serious offences the maximum penalties are a R10 million fine or imprisonment for a period not exceeding 10 years or to both a fine and such imprisonment.
For the less serious offences, for example, hindering an official in the execution of a search and seizure warrant the maximum penalty would be a fine or imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.
Failure to comply with the requirements of the POPI Act could have dire consequences.
To view the full PoPi Act click here --> POPI Act which can be downloaded from Act No. 4 of 2013 : Protection of Personal Information Act, 2013
Is your organisation Compliant?..
...Best you contact StormWarning! today for a NIST CyberSecurity Audit and we will do our very best to answer that question for you and your organisation, rest assured, we will diligently endeavor to support your organization while adhering to the constraints of your budget.