top of page
Resourcing

POPIA

 

 

What is POPIA?

 

The Protection of Personal Information Act No.4 of 2013 (POPIA) is South Africa’s legislation for the protection of individuals’ personal information against unethical use. The preamble to the Act states the intention is in order to:

 

“Regulate, in harmony with international standards, the processing of personal information by public and private bodies in a manner that gives effect to the right to privacy subject to justifiable limitations that are aimed at protecting other rights and important interests.”

 

Since its passing into law, the Government has taken an incremental approach to the commencement of different sections of the Act. In terms of a proclamation issued by the President, sections 110 and 114(4) of the Act commenced on 30 June 2020 and the remainder of the Act’s sections commenced on 1 July 2020.The commencement date denoted the start of a one-year grace period for businesses to ensure that they fully comply with POPIA, which in turn ended on 1 July 2021. The purpose behind POPIA can therefore be seen as the promotion of the constitutional right to privacy by ensuring that responsible parties and operators engage in lawful processing of personal information in accordance with, and with respect for, the rights of data subjects.

 

Responsible Parties and Operators

 

The responsible party in respect of POPIA is the public or private body or any other person which determines the purpose of and means for the processing of information. An operator is a person or entity who processes information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party. Putting this into context, you, the customer, are the responsible party for your employees’ (data subjects) personal information. Hanani Project Management Solutions is acting as an operator for your benefit, processing your employees’ personal information in order to assist you in your payroll obligations. The relevance of this is that a party’s role determines their rights, obligations and liabilities.

 

Lawful Processing of Personal Information

Personal information is information which can be used to identify a data subject – a definitive list can be found in Section 1 of the Act. The data subject is the person to whom the personal information relates and can be either a natural or juristic person. Almost any way that a company interacts with the personal information of a data subject constitutes processing – a definitive list is once again available in Section 1 of the Act.  Under POPIA there are eight principles for the lawful processing of information, aimed at posing a balance between the necessary processing of data for business purposes and protecting the rights of individuals. 

 

These are:

  1. Accountability

  2. Processing Limitation

  3. Purpose Specification

  4. Further Processing Limitation

  5. Information Quality

  6. Openness

  7. Security Safeguards

  8. Data Subject Participation

 

More detailed information on each of these principles is provided in Chapter 3 of POPIA. Whose legal responsibility it is to ensure compliance with POPIA depends on the relationship between the data subject and the organisation doing the processing.

 

Rights of Data Subjects

Under POPIA, data subject rights include the right to access what information of theirs is held, the right to correct information, the right to be notified of collection and the purpose of the collection, the right to object to the processing of their information and, in certain circumstances, the right to erasure. In the case of an alleged infringement of a data subject’s rights, any person has the right to lodge a formal complaint with the Regulator. Pursuant to section 74, complaints can be made to the Information Regulator, by completing and submitting the relevant form found on their website.

 

POPIA and Hanani Project Management Solutions

 

Hanani Project Management Solutions has always been committed to the strictest levels of data protection and privacy. We treat all personal information of your company and employees with the utmost circumspection and respect for the rights of data subjects. More detailed information on how we do this can be found in our Privacy Policy 

 

Privacy and data protection are cornerstones of the culture at Hanani Project Management Solutions, and, as such, we have for some time been largely compliant with the obligations that are now statutorily imposed by virtue of being an operator under POPIA.

 

These obligations have been codified within POPIA as follows:

  • Processing – Only process information with the authorisation of the responsible party.

  • Confidentiality – Treat personal information which comes to their knowledge as confidential.

  • Security – Put in place technical and organisational measures to ensure that the confidentiality and integrity of personal information is protected, and immediately notify the responsible party where there are reasonable grounds to believe that personal information of a data subject has been accessed or acquired by an unauthorised person.

 

The personal information provided to Hanani Project Management Solutions by you includes information such as data subjects’ names, dates of birth, nationality, gender, physical address, email address and bank details. On signup and in order to make use of Hanani Project Management Solution’s online platforms, you are required to agree to our Terms of Service. These contain a clause consenting to the lawful collection and processing of personal information.

 

As was the case before POPIA, Hanani Project Management Solutions will continue to make reasonable efforts to assist you in the provision of personal information in line with obligations to all users (data subjects) rights under POPIA, as laid out in sections 23 to 25 of the Act. 

 

As well as complying with the principles of lawful processing, which for Hanani Project Management Solutions includes meeting the three obligations covered above, the following are relevant:

  • Appointment and registration of a company Information Officer – Hanani Project Management Solutions our Information Officer has been appointed and can be contacted at support@hanani.co.za

 

Processing of Special Personal Information – processing of certain data, such as race and philosophical beliefs, is prohibited except in certain circumstances, including where such processing is necessary to meet legal obligations. It is under this exception that Hanani Project Management Solutions is allowed to process special personal information with your (and by extension your anyone representing you’s) consent.

Library
bottom of page