The information regulator released the Information Regulator Strategic Plan for 2022/3 to 2026/7. The plan outlines the steps that the regulator will take to implement its vision for 2027. The regulator’s key focus is to fulfil its dual mandate as set out in the Protection of Personal Information Act and the Promotion of Access to Information Act. The regulator will focus on protecting personal information and facilitating access to information. In this post, we summarise the important plans and explain what they could mean for you. This plan is quite important because it provides insight into what the regulator plans to do.
The regulator’s enforcement powers are now effective. This means that we can expect the regulator to hand down enforcement notices as they provide complainants with remedies when someone infringes their rights.
What does the 2022/3 to 2026/7 plan cover?
The plan is divided into three Parts.
Part A
- Further to what we discussed above; the regulator lists six relevant court judgments under Part A.
- The six judgments offer various court’s legal interpretations of POPIA and PAIA. (We recommend that you refer to our POPIA judgments and PAIA judgments pages for a more comprehensive list of court judgments.)
Part B
- This section discusses the effect that external environmental factors could have on the regulator’s implementation plan. For example, an economic factor like an increase in the country’s national debt could lead to budget cuts. A budget cut could impact on the regulator’s budget.
- Another example is that people do not have a competent understanding of legislation and compliance, it could lead to the regulator receiving more complaints. Therefore, the regulator must conduct more public awareness campaigns and companies should hold more stakeholder engagements.
- There are some positive developments. For example, the regulator has:
- Filled important vacancies with qualified staff.
- Effective enforcement powers.
- A dual mandate enabling them to balance privacy and access to information.
- The regulator has some shortcomings like:
- inadequate office space,
- some of regulator’s policies are still pending approval
- a poor information and communication technology infrastructure.
Part C
The regulator plans to measure their performance against the plan through the following indicators:
- The percentage of complaints the regulator receives, investigates, and finalises.
- The number of responsible parties that the regulator will monitor on compliance.
- A percentage of the population who are aware of their right to privacy (as it relates to the protection of personal information).
- A percentage of the population who are aware of their right to request access to information.
- The number of education programmes that the regulator will conduct to promote protection of personal information and access to information.
How does the new plan compare to the previous 2021/2022 plan?
The regulator previously published its annual performance plan for 1 April 2021 to 31 March 2022 and presented it in different formats to different audiences. For example, the regulator held a readiness stakeholder engagement on 15 June 2021. Here are a few highlights from the 2021/2022 plan and our comments on the progress:
- Fixing the registration of information officer portal – The regulator has done a full redesign of their website. The information officer portal is still under construction.
- Template for a PAIA manual
- The regulator published PAIA manual template for a public and private body.
- The regulator also published a PAIA guide to assist a person on how to access their personal information.
- Unfortunately, the templates leave bodies to determine many facts themselves and have many shortcomings. You don’t have to use these templates. You can ask us to review or draft a PAIA manual for you.
- Notice on prior authorisation – the regulator has not issued a new notice on prior authorisation.
The 2022/3 to 2026/7 plan covers the regulator’s implementation plans in great detail. However, we did not receive clarity around regulatory developments from last year. For example, we still have no indication of when the regulator will announce commencement dates for the rules relating to the procedure for handling POPIA complaints. We also don’t know when the regulator will finalise the proposed amendments to the POPI regulations since the comments process closed last year.
Actions you can take regards the regulator strategic plan
- You can dive into the details of the regulator’s strategic plan for 2022/3 to 2026/7 by downloading it.
- Find out how to comply with POPIA by joining our Data Protection Programme.
- Find out how to comply with PAIA by joining our Access to Information Programme.
- You can learn about and stay up to date with the latest developments in cybercrime by visiting our main Cybercrimes page.
- Be alerted to any new developments by subscribing to our newsletter.