Legal updates and opinions
News / News
Information Regulator issues Guidelines for the development of Codes of Conduct effective 1 March 2021
by Ahmore Burger-Smidt, Director and Head of Data Privacy Practice and member of Competition Law Practice; and Dimakatso Khumalo, Candidate Attorney
- On 22 February 2021, the South African Information Regulator (“Regulator“) published Guidelines to develop Codes of Conduct (“Guidelines“) under the Protection of Personal Information Act No. 4 of 2013 (“POPIA“).
- It is probable that organisations which fall within the same industry will encounter similar or even identical data protection issues. Codes of Conduct provide such organisations with useful guidance on industry-standard approaches to these issues. By developing and implementing Codes of Conduct, organisations are in a better position to demonstrate to individuals that it takes their data protection rights seriously. This, in turn, may persuade those individuals to do business with that organisation rather than with its competitors.
- The South African economy is saturated by a plethora of industries/industry sectors, and professional and vocational bodies (“industry bodies“). All these industry bodies have distinct and unique ways of managing their business, profession or vocation to an extent that there is not a one size fits all compliance approach across all industries. As a consequence, industry specific dynamics ought to inform the way forward considering the impact of POPIA industry members. The conditions and implementation for the lawful processing of personal information under POPIA will undoubtedly be influenced by the distinct features that each of these industry bodies possess. The members of these industry bodies are expected to collect different personal information of their clients as well as employees in order to conduct their business.
- The Guidelines (once effected) envisage to direct and assist relevant bodies, including bodies or class of bodies of specified industries, professions, or vocations, to draft their own Codes of Conduct with the aim ofcompliance with the provisions of POPIA. The Guidelines establish a standard that the Regulator will apply when evaluating Codes of Conduct for approval and also afford to those industries, considering the implementation of a code of conduct, a practical guide to clearly address the aspects that the Regulator deems important.
- The Guidelines will assist relevant bodies to prepare and submit for approval Codes of Conduct to the Regulator. It aims to provide a step by step process guidance. It is clear from the guidelines that industry bodies should conduct consultation with their stakeholders and decide on their own procedures and processes to be followed in dealing with, not only complaints, but also with overall compliance with POPIA through more specific and tailored compliance mechanisms. Simply put, the Codes of Conduct serve as a Roadmap to Compliance.
- These industry bodies will therefore benefit tremendously from Codes of Conduct which are more specific and professional orientated, and which target the unique aspects of the profession they are regulating, while remaining compliant with the provisions of POPIA.
- The guidelines can be downloaded and reviewed in order to consider what impact they will have on you organisation
Latest News
Notification of data breaches… setting the record straight
Report data breaches "We reminded them of their duty to report any breach in data security to us. The report [...]
The requirements for Rescission Applications, restated
The requirements for Rescission Applications The Constitutional Court recently handed down judgment in what was effectively a refresher course on [...]
Data breaches: to notify, or not to notify, that is the question
Data breaches We have had a number of clients approach us on the issue of security compromises or "data breaches" [...]
Jacob Zuma’s medical records: off limits or fair game
Jacob Zuma's medical records Discussions around medical records have taken centre stage at former president Jacob Zuma's trial for corruption, [...]
Can crypto assets be exported?
The movement of crypto assets between digital wallets The Financial Surveillance Department of the South African Reserve Bank or "FinSurv" [...]
The COMESA Competition Commission’s increasing emphasis on competition enforcement and conduct cases
The COMESA Competition Commission 1. The Common Market for Eastern and Southern Africa (COMESA) covers 21 countries namely Burundi, the [...]