POPIA

POPI Update: Parliament wants POPIA to commence urgently

Parliament has stressed that it wants South Africa's data protection law called the Protection of Personal Information Act (POPIA) to commence urgently. We still don't have any specific commencement date or deadline but Parliament said "we need specific timeframes". We [...]

By |2024-02-22T15:56:38+02:00May 13th, 2020|Categories: POPI and Data Protection|Tags: , , , , |

POPI Update: The commencement date is not 1 April 2020

There are media reports that the Protection of Personal Information Act (POPI Act or POPIA) commenced today 1 April 2020. This is incorrect. POPIA has not commenced. The President has not proclaimed the date in the Government Gazette. The Information [...]

By |2022-12-20T11:37:50+02:00April 1st, 2020|Categories: POPI and Data Protection|Tags: , , , |

First POPI Regulations 2018 in South Africa explained

The Information Regulator in South Africa published the first POPI regulations on 14 December 2018 (or POPIA regulations or POPI Act Regulations as some people call them). The regulations say that "These Regulations shall be called the Regulations relating [...]

Data protection audit by an authority | GDPR audit

Data protection authorities around the world have started to do a data protection audit (or GDPR audit) on controllers to check that they comply with data protection law. Essentially, the authority compares your organisation to a data protection law that [...]

Ireland should be your one-stop shop for data protection

In everyday language, a ‘one-stop shop’ is a business offering multiple services and the only place you need to fulfil your needs. A ‘one-stop shop’ means something else from a data protection perspective in the context of the GDPR, although [...]

By |2022-11-07T13:28:25+02:00August 6th, 2019|Categories: POPI and Data Protection|Tags: , , |

Is the ICO being too harsh with its GDPR fines?

This week, the UK Information Commissioner's Office (ICO) issued two intentions to fine organisations for breaches of the GDPR. It has not issued these GDPR fines yet, and both organisations still have an opportunity to respond to the intention with [...]

By |2019-07-12T17:09:32+02:00July 11th, 2019|Categories: POPI and Data Protection|Tags: , , |

Review of a Commentary on the Protection of Personal Information Act

A Commentary on the Protection of Personal Information Act is a good legal textbook that lawyers and law students will find useful in raising their awareness about this very important topic that is about to become a big deal in [...]

By |2022-11-29T14:07:48+02:00December 20th, 2018|Categories: POPI and Data Protection|Tags: , , |

Who is liable for damages suffered by data subjects?

When a data subject's right to privacy is infringed or someone fails to protect their personal data, and they suffer damages as a result. Who is liable for those damages? Who should the data subject be taking legal action against? Is [...]

GDPR compliance deadline – what we’ve learned

They say hindsight is 20/20. And usually, it's not helpful to hear that. But for once we can really apply what we've learnt. By helping organisations meet the GDPR compliance deadline, we've identified the key stumbling blocks to avoid as [...]

By |2022-12-08T15:23:02+02:00May 23rd, 2018|Categories: POPI and Data Protection|Tags: , |

Information regulator strategic plan for 2017 to 2020 – a heads up

The Information Regulator released the Information Regulator Strategic Plan for 2017 - 2020 on 9 June 2017. This plan is quite important and requires all private and public bodies to sit up and take note. It contains an explanation [...]

Information Security Laws or Privacy Laws – What is appropriate security?

Information security laws (many of which are also privacy laws) across the globe require you to secure the personal data that you process. The General Data Protection Regulation (GDPR) in Europe, the Data Protection Act in the United Kingdom, and the [...]

Minimum Information Security Standards (MISS) Summary

The Minimum Information Security Standards (or MISS) is a standard for the minimum information security measures that any institution must put in place for sensitive or classified information to protect national security. If you work with public service information resources, [...]

By |2022-12-19T12:03:33+02:00February 28th, 2017|Categories: Cybersecurity Law|Tags: , , , |