POPIA

The Protection of Personal Information Act (POPIA) is South Africa’s data protection law. This is a summary or short explanation of why it …

Who should be the designated or deputy information officer?

Now, there is a question. It depends on the organisation, but often, it is someone in legal or compliance. But no formal qualifications are required by law. It is essential that the person you select as your information officer (IO) [...]

By |2024-09-04T10:54:11+02:00August 20th, 2024|Categories: , |

How do I register my information officer on the Information Regulator portal?

Responsible parties should register their information officer online (encouraged) as soon as possible. Failing to register your information officer is not a criminal offence, but there can be severe consequences. If you struggle to register on the portal, we [...]

By |2025-03-12T15:12:28+02:00August 16th, 2024|Categories: , , |

Does the information regulator communicate with other regulators to ensure its compliance with adequate safeguarding measures?

The Information Regulator (IR) does communicate with other regulators but because each regulator has its own mandates, the IR is confined to the parameters of POPI and PAIA and anything that falls outside the four corners of these Acts will [...]

By |2024-03-22T11:37:17+02:00March 22nd, 2024|Categories: , , |

What are the information regulator’s plans to work with other regulators in ensuring alignment in inputs on the standard frameworks and policies that will cover cybercrimes?

The initial difficulty that South Africa is facing is that it does not have a cybercrimes commission. At present, the Information Regulator works closely with the police and the Hawks but uses its own processes separate to those used by [...]

By |2024-03-22T11:28:35+02:00March 22nd, 2024|Categories: , |

What does the information regulator look for during a POPIA or PAIA compliance assessment?

The Information Regulator (IR) has discretion in when to assess organisations' data processing practices under both POPIA and PAIA. They follow prescribed procedures and inform applicants about the scope and reasons for the assessment. For POPIA assessments, factors considered include [...]

By |2024-03-22T11:08:04+02:00March 22nd, 2024|Categories: , , |

What are some of the information regulator’s strategies for dealing with a criminal situation when contacting the police is not an option?

The information regulator would like to clarify that it is not a cybercrime agency and does not investigate cybercrimes. They do concede that there is a need for a cybercrime agency to assist in the regulation of cybercrimes in the [...]

By |2024-03-22T10:24:38+02:00March 22nd, 2024|Categories: , |