
POPI stands for Protection of Personal Information.
Organisations should consider what Personal Information they capture, manage and store, and how best to secure IT.
POPI is all about Privacy.
Develop a POPI Plan.
These simple measures may help your business ease into POPI compliance:
- Appoint an information security officer.
- Develop internal ethical standards for the processing of personal information.
- Provide adequate training for employees involved in processing personal information.
- Keep a record of each processing activity.
- Review or develop internal guidelines for employees.
- Build privacy and security into all your processes and systems, and into the day-to-day operation of your organisations.
- Implement a Clean desk policy.
- Use Strong Passwords and multi factor authentication.
- Restrict or limit access to unauthorised personnel.
- Implement end point security.
- Acquire Threat hunting software.
- Analyse what information is gathered and kept.
- Delete information that is not required.
Implement comprehensive Employee information security awareness training.
What is POPIA?
POPIA stands for the Protection of Personal Information Act, Act No. 4 of 2013 or POPI Act.
This is the new law and is something that most (if not all organisations) will need to follow.
POPI is the act of protecting Personal Information.
This implies that all the policies, procedures, processes and practices in the organisation relating to personal information, are in fact doing POPI.
POPIA is merely the name of the law.
POPI is based on eight conditions for the lawful processing of personal information and under each condition there are several key requirements.
Here is a summary go to https://popia.co.za/ to read the full act.
1. Accountability
Personal information must be processed lawfully and in a reasonable manner and It should not infringe on any person’s privacy.
2. Processing limitation
Acquiring and processing of personal information should always be relevant and never excessive, and the data subject’s consent should be obtained before his or her information is processed.
3. Purpose specification
It may only be collected for a specific, lawful and explicitly defined purpose that relates to the data collector’s function or activity and must not be retained for any longer than is necessary.
4. Further processing limitation
Any further processing of personal information must be related to the purpose for which the information was originally collected.
5. Information quality
Ensure that any personal information collected is complete, accurate, truthful and updated.
6. Openness
Compile a detailed privacy policy, document the process of collecting information as required by POPI’s provisions and notify data subjects when their personal information is processed.
7. Security safeguards
Take all the appropriate measures to keep it confidential, guard any against unlawful acts and prevent its loss, damage or destruction.
8. Data subject participation
Data subjects must be able to confirm whether an organisation holds any of their personal information, be allowed to correct their information, or request that the responsible party destroy or delete it.