Skip to content

POPIA

Short notes on the Protection of Personal Information Act, 2013 (POPIA)


What is this Act for?

This law has as its purpose (which is broadly in line with international laws of this sort), the protection of personal information and therefore privacy in the context of data. Privacy extends to how personal information is collected, stored, used or manipulated. Hence, the purpose of POPI is to:

  • give effect to the constitutional right to privacy by safeguarding Private Information;
  • balance the right to privacy against other rights, like the right of access to information;
  • regulate the manner in which Private Information must be processed;
  • provide persons with rights and remedies if POPI is contravened.

Understanding POPI terminology

Your information:

This is anything that can identify who you (the 'data subject') are or who someone else is.

It includes a name, identity number, address, gender, race, religion, medical issues, employment history, email, photograph, social media accounts, biometrics, personal views and opinions or statements, disability, language – anything that could enable someone else to find out something about you or any other person.

Responsible Party:

A person who decides how Personal Information is processed and what this Personal Information is used for. A responsible party can be a natural person, juristic person such as a company or group of companies, or a government body. In the context of SMSPortal's services, you, our customer, are viewed as the Responsible Party.

Operator:

A natural or juristic person that processes Personal Information for the responsible party. Pattern Matched Technologies™ would act as the Operator in the process of rendering our services and products.


What is the Act saying about ‘personal information?

What can be done:

Since you (and every other person) are likely to give personal information to many institutions and individuals, this Act restricts how those entities or people can deal with your (and their) information which includes how they (or you) collect, record, store, distribute, share, sell, receive, transmit, destroy and retrieve this.

In short, the Act deals with any of these activities, which it refers to as ‘processing’ your (and their) data. It addresses all data in any form, which it refers to as a ‘record’ – in other words that personal information can be in any form at all (e.g. written or filmed) but will still be a ‘record’. It excludes ‘purely household activities.’


When does it apply?

You need to be fully compliant with all sections of the Act by 1 July 2021 when POPIA will be enforced:

PMT recommends you to act now to ensure that you are aligned with the requirements as soon as possible. WASPA is already seeking to implement these requirements under the WASPA Code.

The key provisions of this Act deal with the rights of people to object to the processing of their data at any time (unless they are required to provide it for a lawful purpose, or to provide it willingly in the course of obtaining a service). They also deal with the obligation to ask for permission to ‘process’ personal information. This means:

  • you ask for only the bare minimum of personal information required;
  • the person understands why they are giving their personal information, how their information will be used, and for what purpose.

Every organisation (company or other entity) must appoint its own Information Officer. The Officer must bring the organisation into line with the requirements of the Act, and liaise, when necessary, with the Information Regulator.


Direct marketing and unsolicited communications

The definition of direct marketing is quite wide, as it refers to communications that are directly targeted at promoting goods or services as well as 'indirect' marketing messages. Communications required to be sent by law (such as bank statements or a television license renewal notice) along with communications that are necessary for the conclusion or performance of a contract do not have to comply with the regulations relating to direct marketing, even if those communications have an indirect result of promoting products or services of the sender.

POPI distinguishes between new and existing customers when it comes to marketing consent. Section 69(3) of the Act defines existing customers, and while there is no clear definition of what defines new customers, should they not fall into the definition of existing customers, the regulations relating to new customers are applicable. Section 69(3) of the Act states that the responsible party (you as the sender of marketing messaging) will not have to request marketing consent from an existing customer if the following requirements are met:

Existing Customers:

  • The responsible party must have obtained the customer's contact details in the context of the sale of the responsible party's products or services.
  • The Personal Information must have been collected to market the responsible party's own products and services.
  • The customer must have been given a reasonable opportunity to object to the use of their personal information for marketing purposes, free of charge and without too much formality. This opportunity must have been given to the customer at the time the information was collected and every time marketing is sent to the customer.

New Customers:

  • If you are contacting someone for the very first time but you want to be able to contact them again, you will need their voluntary, informed, specific, opt in in writing with their full name and signature. You must also record the name and contact information of the contact marketer and their information officer or the deputy information officer (see above), the date and place where consent is given by the person, the type of goods or services you want to contact them about, and the method of future communication (SMS, email or phone).
  • You may only contact people who you have an existing relationship with, or who gave you information when they asked about your product or service, or if you are going to offer them similar products or services to those they asked about or previously bought, and they have been told that they may be contacted for further marketing, and they are always given an opportunity to opt out.
  • Note that no one is automatically opted in – if a person doesn’t tick the opt-in box, they must not be taken to have opted in. You need express consent. You may not pre-populate the box with a tick, the user must tick the box themselves. You will need to prove that you obtained the personal information of any person in your database with their specific consent, or in the circumstances in (a) or (b) above, and having given them information about how to opt out.

References

  • de Stadler, E. and Esselaar, P. (2015). A Guide to the Protection of Personal Information Act. Cape Town, South Africa: JUTA