POPIA Deadline July 2021

POPIA Deadline July 2021

All organisations who process personal information about employees, customers, and suppliers and those who process data and share information offshore must comply to provisions as set out in the Protection of Personal Information Act. (POPIA)

 Section 114(1) is of particular importance as it states that all forms of processing of personal information must, within one year after the commencement of the section, be made to conform to the Act. This means that entities (both in the form of private and public bodies) will have to ensure compliance with the Act by 1 July 2021. However, it stands to reason that private and public bodies should attempt to comply with the provisions of the Act as soon as possible in order to give effect to the rights of individuals.

See: https://www.saica.co.za/Portals/0/Technical/LegalAndGovernance/ms_20200622_POPIA_Sections_Commencement.pdf

Entities which process personal information must ensure that it is done in a lawful way. The Act is fundamental in safeguarding persons’ personal information and thus protecting them against data breaches and theft of personal information.

Knowledge is of critical importance.

It is only in knowing what to look out for how to prevent it and what to do if Cyber Attacked (Fact its inevitable)  so that we can adequately protect and prevent. See www.cyberaweh.co.za

In today’s world of geopolitical turmoil and the ever-increasing speed of technological innovation, the threat from actors with the necessary motivation, financial means, and technological capabilities, is real. Hence, the orchestration of a large-scale cyber-attack is likely a matter of “when”, not “if”.

See: https://perspectives.dtcc.com/downloads/whitepaper/large-scale-cyber-attacks-on-the-financial-system

Section 19 of the POPIA act  Security measures on integrity and confidentiality of personal information

  • A responsible party must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent:
  • Loss of damage to or unauthorised destruction of personal information; and
  • Unlawful access to or processing of personal information.

In order to give effect to subsection (1), the responsible party must take reasonable measures to identify all reasonably foreseeable internal and external risks to personal information in its possession or under its control:

  • Establish and maintain appropriate safeguards against the risks identified.
  • Regularly verify that the safeguards are effectively implemented; and ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards.

The responsible party must have due regard to generally accepted information security practices and procedures which may apply to it generally or be required in terms of specific industry or professional rules and regulations.

Penalties for non-compliance

All persons bound by the provisions of POPIA have until no later than 01 July 2021 in which to become compliant with the provisions of the Act, and organisations should not underestimate how quickly the 12 months grace period will lapse considering the processes that need to be adopted for compliance to be possible. The infringement of the provisions has far-reaching consequences such as a maximum of R10 million fines per infringement, 10 years imprisonment or both a fine and imprisonment.

See:

Why Cyber Security Awareness Training

Awareness stimulates and motivates those being trained to care about security and to remind them of important security practices. Awareness is also used to reinforce the fact that security supports the mission of the organization by protecting valuable resources.

www.cyberaweh.co.za

Latest Articles

Cyberbullying in South African Schools  

A Deep Dive into the Crisis and Responses Introduction Cyberbullying has emerged as a significant concern in South African schools, affecting learners' mental health, academic performance, and overall well-being. Unlike traditional bullying, cyberbullying occurs...

read more

WHAT IS CYBERBULLYING?

Cyberbullying is any form of intentional harm inflicted through digital communication tools—whether it’s on a phone, a social media platform, or a game chat. It includes threats, humiliation, exclusion, and even impersonation, and it can affect anyone—anywhere,...

read more

Safeguarding Against Phishing Threats.

A Comprehensive Guide: In the rapidly evolving landscape of cybersecurity, phishing has emerged as a pervasive threat, with cybercriminals employing increasingly sophisticated tactics to deceive individuals and compromise sensitive information. Businesses in South...

read more