Many organisations are trying to implement POPIA. They’re trying to assess the impact of POPIA on their organisation and then analyse the gap. This makes a lot of sense because you need to understand the impact and the gaps before you find solutions to fill them.
Many organisations are engaging consultants or lawyers to assist with the process
Questions you should be asking
Organisations want to implement POPIA as effectively as possible. Many of them are asking themselves these questions:
- What should I focus on?
- How can I fast-track my efforts?
- How do I reduce the overall cost of compliance?
- How do I ensure I get value from the process?
- What is the best way of doing a gap analysis?
- Which compliance method should I follow?
- What compliance method best suits my business?
Practical insights to implement POPIA
We have been helping organisations assess the impact of POPIA on their operations and conduct gap analyses, and we have gained practical insights we think are valuable.
As a starting point, we believe in a practical implementation of privacy. This has nothing to do with focusing on the eight privacy principles (aka conditions) exclusively and then implementing them. Interpretation of the principles does not drive the practical implementation of the programme. Of course, you have to understand the principles. However, the main reason for doing so is not to drive your privacy programme, but rather to identify the regulatory hot buttons so you know what to monitor.
Doing a thorough and comprehensive analysis of a large business is a huge undertaking
A complete analysis takes a lot of time and effort. Its price tag can get high. You want to know you are actually going to get value out of it at the end of the day. You want to be sure that your compliance efforts actually add value.
Just do one activity as part of an initial assessment
Our suggestion is that you not conduct a comprehensive data protection gap analysis initially. This may sound crazy coming from a lawyer, but bear with me. It is simply not possible to completely control personal information, as doing so would bring the company to its knees.
We suggest that the first thing you do is a relatively high-level analysis. As part of this, you can pick one activity (or process) in your business. Make it a really important one. One that your executives will lose sleep over because it’s so serious to the organisation given its specific circumstances, and POPIA will only make that situation worse. Or one that really adds to your bottom line. One that would have a serious financial impact on your organisation if it failed or was unlawful. A high-risk one. For example, it might be applications for new accounts or email marketing campaigns. Or one that would have a reputational impact on your organisation.
Then map that activity, create a record of it, and conduct a full analysis of that single activity. Analyse how POPIA impacts it and identify the gap. While you’re at it, maybe broaden the scope to include any laws (including POPIA) that relate to that activity. If the activity relates to marketing via SMS, for example, the applicable laws would include POPI, the CPA, the ECT Act, and the WASPA Code of Conduct.
You could also consider the business requirements for the activity while reviewing the regulatory requirements.
Follow your method from start to finish for that one particular activity. Find and implement the solutions (such as a privacy policy) necessary to plug any gaps.
This work costs much less because its scope is narrower.
The advantages
There are many advantages to doing it this way.
You want to get the recipe right and then make lots of cakes. Not make lots of cakes that flop and then try and fix the recipe.
- You will be able to fine-tune your method. It will give you a great idea of how to proceed in the future. It is almost like a pilot project.
- You ensure that you are focusing on the right activity. You are working on an activity (or process) that is really important.
- You may be able to analyse your other activities (or processes) yourself, thereby reducing the overall cost of the complete implementation.
- You can satisfy yourself that you are working with the right consultants or lawyers who know what they are doing. You can also identify the right consultants or lawyers to implement the required solutions. We don’t do everything, and we know who the right people are for different tasks.
- You don’t have to commit to a huge project up front.
- You will implement solutions faster. You don’t want to spend a year analysing all your activities and then only get around to implementing solutions. You want to conduct the initial analysis and implement solutions quickly.
- You can follow an agile approach that lets you quickly check whether it is suitable for your particular business. It also lets you make adjustments as you go.
The steps to analyse one activity
These are the common steps to analyse one activity. However, it is important to be flexible. So, we can agree on the applicable steps on a case-by-case basis based on the activity you have chosen.
- We hold a two- to three-hour workshop where you explain your activity to us. We ask questions to get a better understanding and identify where POPIA and other laws will have an impact.
- We then draft a report that sets out the gaps and recommends solutions.
If you are interested, please send us an email describing the activity (or process) you would like to record and analyse, and we will contact you to discuss your requirements further and provide you with a quote for that exercise.