POPI: Are you all set?

The protection of privacy in South Africa has undergone intense investigation over the last decade. In late 2005 the South African Law Reform Commission found that there wasn’t adequate protection and that a new, separate piece of legislation was needed for the proper protection of one’s personal information. This paved the way for the long process which is now finally coming to an end with the Protection of Personal Information Act (“POPI”) recently passed by the National Assembly and now awaiting enactment.

POPI will have as its main aim the protection of personal information. It has been stated that POPI has been designed to protect personal information given the fact that in today’s digital age there are serious implications in how this type of information is handled. Should an organisation or “responsible party” as named by POPI, request your personal information, they can only capture and use it with your consent. Organisations will further have to ensure that it is kept up to date and that they have put in place, reasonable security measures which are in line with industry standards. This in itself can be quite a tall order for many organisations that handle personal information of their clients.

As soon as POPI is signed into law all public and private organisations that process personal information will have a transition period of one year to address their compliance. The onus rests on the organisation to comply and compliance failure cannot only bring about reputational damage but can also lead to fines of up to R10 million or imprisonment of up to 10 years.

POPI restricts how personal information can be collected and used and to this end sets out eight principles of compliance for organisations:

1. Accountability

All responsible parties which range from the man on the street to corporate giants must adhere to all of POPI’s principles.

2. Processing limitation

Lawfulness is key. The method of information collection must be lawful and not infringe on one’s right to privacy. Processing must be adequate, relevant, not excessive, relative to the purpose for which the processing was undertaken and only done with the consent of the individual (barring a few exceptions). Personal information must always be collected directly from the data subject, unless the POPI provides otherwise.

3. Purpose specification

Collection of personal information must be for a specific, explicitly defined and lawful purpose of which the individual must be aware. The purpose for which your information is going to be used must be explicitly stated and only kept until the desired result for which it was collected has been achieved.

4. Further processing limitation

Further processing of the information must be in accordance or compatible with the purpose for which it was originally collected.

5. Information quality

The organisation must take all reasonable steps to safeguard personal information while making sure it is accurate, complete, not misleading and updated whenever it so demands. When taking these steps, regard must be had as to the purpose for which the information was gathered or would be used for further processing.

6. Openness

The responsible party must at all times disclose to the individual all reasons behind the collection of their personal information. This includes for example the source, application and the individual’s rights in respect of such information and who will have access to the information.

7. Security safeguards

A responsible party must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unlawful access to personal information.

8. Data subject participation

An individual can at any time, free of charge request from an organisation whether they hold any of their private information. Upon provision thereof, the individual may demand correction or deletion of information that is inaccurate, out of date, misleading or that was obtained illegally.

Organisations need to take note of these principles and assess to what extent these principles will apply to them. Proactively obtain help to assess the compliance of your business and start putting measures in place to ensure your compliance with POPI as compliance will not be an overnight exercise and will require planning and understanding on your part.

October 25, 2013
Checkmate for Pawn Agreements: How the Recent SCA Judgment Protects Consumers from Pawnbroker Profits

Checkmate for Pawn Agreements: How the Recent SCA Judgment Protects Consumers from Pawnbroker Profits

In a landmark judgment delivered on 9 April 2025, where VDT Attorneys acted on behalf of the National Credit Regulator, the South African Supreme Court of Appeal (the “SCA”) brought clarity to the rights and obligations of consumers and pawnbrokers when dealing with pawned goods. In the case of The Loan Company (Pty) Ltd v National Credit Regulator and Another (1104/2023) [2025] ZASCA 40, the SCA confirmed a critical principle, i.e. if a pawned asset is sold for more than the outstanding loan and lawful charges, the surplus must be refunded to the consumer. Pawnbrokers cannot lawfully keep the full sale proceeds. This ruling marks a major victory for consumer protection, reinforcing South Africa’s commitment to fairness in credit transactions.

Heritage Day: Reflections from a New Breed law firm

Heritage Day: Reflections from a New Breed law firm

On 24 September, we pause to take time off to commemorate Heritage Day, a day enshrined in both our public calendar and the Constitution. A constitutional affirmation of who we are, where we come from, and where we are headed as a nation. As a new breed law firm, we reflect on how the practice of law is intertwined with the heritage of the very people it serves.

Treasury halts controversial tax proposal on preference shares

Treasury halts controversial tax proposal on preference shares

Due to the potential adverse investment impact and stakeholder concerns on the proposed amendment to the definition of “hybrid equity instrument” in the 2025 draft Taxation Laws Amendment Bill (“Bill”), the proposed amendment has been retracted. On 03 September, the National Treasury issued a media statement retracting the proposal to redefine hybrid equity instruments, which has been a relief to all stakeholders.

Sign up to our newsletter

Pin It on Pinterest