Data protection authorities around the world can issue or approve Codes of Conduct under applicable data protection law. Monitoring bodies or associations often draft them and then submit them to the authority to be issued. To facilitate this process authorities often publish guidelines on codes of conduct so that they can be drafted in accordance with them. It would be useful if the guidelines issued by authorities around the world were consistent to the extent that they can.

Guidelines to develop codes of conduct by the Information Regulator

The Information Regulator in South Africa published Guidelines to Develop Codes of Conduct under the Protection of Personal Information Act, 2013 (POPIA) on 22 February 2021 but they are effective from 1 March 2021. You can download them from their website.

The regulator consulted with anyone who had an interest in the guidelines. You could have given input and made comments in writing before 17 January 2020 (close of business at 16h00). The Information Regulator held an in-person consultation with interested parties on 6 November 2019 at the Midrand Conference Centre.

According to section 65 of POPIA, “the Regulator may provide written guidelines:

  • to assist bodies to develop codes of conduct or to apply approved codes of conduct;
  • relating to making and dealing with complaints under approved codes of conduct; and
  • about matters the Regulator may consider in deciding whether to approve a code of conduct or a variation or revocation of an approved code of conduct.”

“Before providing guidelines for the purposes of subsection (1)(b), the Regulator must give everyone the Regulator considers has a real and substantial legitimate interest in the matters covered by the proposed guidelines an opportunity to comment on them. The Regulator must publish guidelines provided under subsection (1) in the Gazette.”

What do the Guidelines to develop Codes of Conduct cover?

  1. Introduction: Legislative Framework
  2. Issuing of Codes by the Regulator
  3. Code Governance
  4. Complaints Handling
  5. Reviewing, Varying and Revocation of Approved Code

EU Guidelines on Codes of Conduct and Monitoring Bodies

Following a public consultation process, the EDPB adopted Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies on 4 June 2019.

They include a checklist for submission in Appendix 3 of the Guideline which will be particularly useful for associations or bodies who would like to draft a code.

A competent supervisory authority has to approve the final version of a Code of Conduct. Appendix 2 assists in choosing the right supervisory authority for a transnational code. The submitting body should put some thought into this decision, as the chosen supervisory authority will be the single point of contact during the whole approval process. The chosen supervisory authority informs other concerned supervisory authorities and those can submit comments on the code.

In addition, a monitoring body has to be identified and approved to monitor the code. The Guidelines specify the requirements for such a monitoring body in detail.

Actions you can take

  • Consider what impact the information regulator’s guidelines will have on your organisation by downloading them.
  • Have a code of conduct by asking Michalsons to draft them for you.
  • Find out how these guidelines or a code of conduct will impact your specific circumstances by getting our advice.