The Information Regulator has been appointed and we are waiting for the regulations to be issued and POPIA to become effective. While you will have 12 months to comply once POPIA is in effect – the implications of non-compliance are so significant that developing a compliance mindset within your business now is imperative. Here is a practical guide on steps your business can start taking on the road to compliance:
- Identify what personal information you collect, from whom and where you store it.
- Perform a gap analysis to identify risks- do it yourself by referring to the eight principles contained in POPIA or engage an expert.
- Implement compliance training for your staff and consider approaches to training new joiners.
- Review your contracts – consider amendments to include POPIA compliance clauses.
- Review your IT security and physical security.
- Have a privacy policy drawn up and consider where links to such policy should be maintained.
- Put in place a security protocol for staff covering online and physical access.
- Appoint a privacy officer.
Considerations should not be limited to POPIA alone – international data protection laws may apply – if you processing the personal information of EU residents you may need to comply with the new EU General Data Protection Regulations. Furthermore, if you are receiving personal information of EU residents via a US company to process such information, it is likely that such US company will require you to comply with the new EU-US Privacy Shield.
Louella Tindale offers an end-to-end compliance solution tailored to your business which considers both local and international compliance requirements. Contact: louella@louellatindale.com

