What about POPI & PAIA? Flashcards
(9 cards)
What do POPI and PAIA stand for?
POPI: Protection of Personal Information Act (4/2013).
PAIA: Promotion of Access to Information Act (2/2000).
Who regulates these acts in South Africa?
The Information Regulator of South Africa oversees compliance with both POPI and PAIA.
What is considered Personal Information (PI)?
Personal Information includes details such as:
Race, gender, sex, pregnancy, marital status, social origin, color, sexual orientation, age, health, disability, religion, conscience, belief, culture, language, birth.
Education, medical, financial, criminal, employment history.
Identifiers (e.g., ID number, email, phone number, address).
Biometric data (e.g., blood type, fingerprints).
Personal opinions, views, preferences.
Private/confidential correspondence.
Third-party views about a person.
A person’s name, if it reveals further identifying information.
What is Special Personal Information?
This refers to:
* A child under parental control.
* A data subject’s religious beliefs, race, trade union membership, political views, health, sexual life, or criminal behavior.
What does “Processing” mean under POPI?
It refers to any operation involving personal data, including:
Collection, recording, storage, modification, retrieval, consultation, use, transmission, distribution, blocking, erasure, or destruction.
Where can Personal Information be found?
In databases, payroll systems, contracts, CCTV footage, telephone records, emails, word-processing documents.
Is processing of special information allowed?
Generally, no, unless:
* Consent is provided.
* It is required to exercise a right or fulfill a legal obligation.
* There are sufficient security guarantees to protect individuals.
What does Section 32 of POPI exclude from prohibition?
Medical professionals, healthcare facilities, insurers, and medical schemes can process health-related data under a contractual duty of confidentiality, unless legally required to do so.
What role do Information Officers (IOs) play?
They ensure compliance with the POPI & PAIA Acts, overseeing the handling and protection of personal data in organizations.