top of page

What is POPI?

POPI is South Africa‘s data privacy law and it stands for the Protection of Personal Information Act, 2013. It is sometimes also referred to as POPIA. It governs when and how organizations collect, use, store, delete and otherwise handle personal information.

What is personal information under POPIA?

Information that can be used to personally identify a natural or juristic (i.e. organizations) person. This information about a person includes, but is not limited to:

  • Name and Age         

  • Race

  • Gender/ Sexual Orientation

  • Pregnancy

  • Martial status 

  • National / Ethnic Social Origin

  • ID Number

  • Email Address / Contact

  • Location / Physical

  • Photos / Video Footage / Voice recording / Biometrics Information

Who does POPI apply to?

POPI applies to all local and foreign organizations processing (i.e. collecting, using or otherwise handling) personal information in South Africa.

What does the POPIA regulate?

  • How a data subject can object to the processing of their personal information

  • How a data subject can request the correction or deletion of information.

  • The responsibilities of an information officer. (Important)

  • How to apply for the regulator to issue a code of conduct.

  • How to request marketing consent. (Important!)

  • How to submit a complaint to the regulator.

  • How the regulator will act as a conciliator in investigations.

  • What the regulator must do before it investigates you.

  • How the regulator will try to settle complaints.

  • How the regulator will conduct assessments.

  • How the regulator will notify people during investigations.

Does POPI provide benefit to businesses?

POPIA provides the opportunity to analyse and have more control over the data handled within your organisation and to better understand its purposes. As data is an increasingly valuable resource, better data management can increase the efficiency and effectiveness of any business.

What does POPI mean for consumers?

Consumers will benefit from POPI’s requirements in that their personal information must be protected and it can only be collected or handled where there is a lawful justification for doing so. POPI gives consumers specific rights in respect of organizations handling their personal information and it gives consumers greater control over their personal information. Consumers are informed about what personal information is collected, by who and why so that consumers are able to make informed decisions.

Does POPI add anything to my constitutional right to privacy?

Every person has a constitutional right to privacy, which has many aspects (including privacy in the home, private communications and private information about a person). POPI gives practical effect to that right insofar as it relates to personal information handled by organisations. It provides a direct mechanism through which that aspect of the right can be enforced.

Here's how we ensure your data is handled responsibly:

Promoting Compliance: We actively encourage and ensure compliance with the legal requirements for the lawful processing of your personal information.

Handling Your Requests: We are here to assist you with any requests you may have under POPIA, whether initiated by you or as required by the Information Regulator.

Collaborating with Regulators: We work closely with the Information Regulator, especially in investigations related to prior authorizations, as outlined in Chapter 6 of POPIA.

Comprehensive Compliance: Our commitment extends to making sure that we comply comprehensively with all the provisions of POPIA.

Strong Compliance Framework: We have established and maintain a robust compliance framework to ensure your data is protected.

Data Impact Assessments: We conduct personal information impact assessments to guarantee that we have implemented adequate measures and standards.

Transparency with a PAIA Manual: Our Promotion of Access to Information Act (PAIA) manual is readily available, reflecting our commitment to transparency.

Efficient Access to Information: We have efficient internal processes and systems to promptly process your requests for access to your information.

Enhancing Awareness: We conduct internal awareness sessions as required, keeping our team well-informed and prepared.

 

Rest assured that these responsibilities, as defined in section 55 of POPIA, are integral to our mission of safeguarding your personal information and ensuring that we uphold the law. Your trust in us is of utmost importance, and we are dedicated to maintaining the highest standards in data protection and compliance."

bottom of page