The one-year grace period under South Africa’s Protection of Personal Information Act 2013 (POPIA) ends today. Organisations processing personal information in South Africa must now comply in full, with the Information Regulator able to enforce.
Key points
- Condition 7 requires reasonable, risk-based technical and organisational security measures, regularly verified and updated.
- Security compromises must be notified to the Information Regulator and data subjects as soon as reasonably possible.
- Information Officers must be registered with the Regulator.
- Operators (processors) need written contracts requiring security measures.
POPIA applies to responsible parties using means in South Africa to process personal information, so UK organisations with South African operations, customers or processors should review their contracts, breach procedures and security controls.
Source: Protection of Personal Information Act 4 of 2013 (South African Government)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.