Legal updates and opinions
News / News
Long road to data protection
On 14 December 2018, the Regulations relating to the Protection of Personal Information were finally published by the Information Regulator (“Regulator“) under section 112(2) of the Protection of Personal Information Act, Act 4 of 2013. These Regulations shall commence on a date to be determined by the Regulator by Proclamation in the Government Gazette.
WHAT YOU NEED TO KNOW
The Regulations provide for various forms to be completed when a data subject wants to:
- object to the processing of their personal information;
- request the correction, deletion or destruction of their personal information; and
- lodge a complaint with the Regulator.
More importantly and for immediate action, companies must take note of and implement, the additional responsibilities of the Information Officer to ensure that:
“(a) a compliance framework is developed, implemented, monitored and maintained;
(b) a personal information impact assessment is done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information;
(c) a manual is developed, monitored, maintained and made available as prescribed in sections 14 and 51 of the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000);
(d) internal measures are developed together with adequate systems to process requests for information or access thereto; and
(e) internal awareness sessions are conducted regarding the provisions of the Act, regulations made in terms of the Act, codes of conduct, or information obtained from the Regulator.”
Furthermore, the Regulations provide for forms setting out the necessary information required in terms of which the Regulator will exercise its duties.
The publication is a clear step in the direction of the Regulator commencing official duties early in 2019.
As a country, we are soon to embark on an interesting road where the privacy of individuals and specifically data privacy will have to be considered in detail in all business activities.
Latest News
Your customer consented to direct marketing – but can you still contact them after they have registered on the National Opt-Out Registry?
by Tebogo Sibidla, Director Many businesses assume that once a customer has consented to direct marketing, they may continue contacting [...]
Employers have rights too: Rebalancing the modern workplace
by Bradley Workman-Davies, Director South African labour law is often discussed through the lens of employee protection. That is unsurprising. [...]
From policy direction to regulation: Is South Africa finally achieving rapid deployment?
by Corlett Manaka, Director and Head of Disputes, Akhona Bilatyi, Director and Kuhle Joja, Associate In September 2024, we published [...]
South Africa: Merger Notification Thresholds and Filing Fees Increase from 1 May 2026
by Ahmore Burger-Smidt, Director and Head of Regulatory and Raisah O Mahomed, Associate South Africa's Minister of Trade, Industry and [...]
“Corporate Death by Winding-Up”: Pretoria High Court Reaffirms the Badenhorst Principle
by Eric Levenstein, Director and Head Insolvency & Business Rescue, Amy Mackechnie, Senior Associate and Clio Patricios, Candidate Attorney A [...]
South Africa’s Information Regulator: What the 2025/26 Annual Performance Plan means for Business (as presented to the Portfolio Committee on 5 May 2026
by Ahmore Burger-Smidt, Director and Head of Regulatory “It is only the inner sanctum of a person, such as his/her [...]
