
PoPIA: Can businesses ask for vaccine status information?
Preeta Bhagattjee, Aphindile Govuza and Reece Westcott 9 Mar 2022
![]() |
PoPIA anniversary: Have you done enough?The 1st of July 2022 marks the one-year anniversary of the compliance deadline of the Protection of Personal Information Act No 4 of 2013 (PoPIA) for all organisations. While the operational provisions of this Act became effective on 1 July 2020, a one-year grace period was granted to allow businesses to effect the necessary changes. This resulted in a compliance drive to bring various information practices in line. ![]() Image source: tumsasedgars – 123RF.com Compliance with this Act requires ongoing vigilance. At this stage, it is imperative that organisations understand the implications of their personal information practices and put in place systems and measures to manage both their existing and ongoing obligations. What has happened since PoPIA came into effect?In order to address compliance with PoPIA, your organisation has most likely had to:
Compliance with PoPIA has in certain circumstances necessitated a fundamental shift in the manner in which businesses approach various aspects of their operations. With this shift has come various challenges in accommodating such a transition. Examples include:
Over the past year, developments in case law relating to data privacy have aided us in better understanding the compliance requirements set out in PoPIA. However, this understanding must be accompanied by practical guidelines to assist organisations in the development and implementation of compliance programmes that take into account their specific needs and operational parameters. How to ensure your complianceTo address any potential compliance gaps within your business, a number of fundamental steps should be considered and taken. These may include:
The above-mentioned steps are useful in establishing certain best practices in your organisation’s PoPIA compliance journey; however, ongoing obligations necessitate a constant review of your organisational processes to ensure that they do not fall short of the PoPIA requirements over time. How to educate yourself furtherIn recognition of the one-year anniversary of PoPIA, CMS will be publishing a series of articles to take stock of the relevant developments since the enactment of PoPIA, which will broadly deal with:
Understanding the intricacies and implications of the requirements set out in PoPIA will require your active engagement and consultation to test your operations against the prescripts of the Act. It is not sufficient to deal with your obligations on a theoretical basis alone, as the requirements relating to various organisations may differ on a case-by-case basis. Compliance with the present and ongoing obligations of PoPIA must be accompanied by a practical process that allows your organisation to meaningfully measure compliance and address the deficiencies identified. About the authorZaakir Mohamed, Director: Head of Corporate Investigations and Forensics; Savanna Stephens, Senior Associate: Corporate and Commercial; and Mawande Ntontela, Associate: Corporate Investigations and Forensics, at CMS South Africa |