Legal updates and opinions
News / News
POPIA, Employment Contracts and Policies and Procedures
by Ahmore Burger-Smidt, Director and Head of the Data Privacy Practice; Jacques van Wyk, Director, Labour & Employment Practice; and Bradley Workman-Davies, Director, Labour & Employment Practice
With effect of 1 July 2020 a number of material provisions of the Protection of Personal Information Act 2013 (“POPIA”) will come into operation. As more fully detailed in a recent Werksmans’ Update, a number of these provisions impose substantive obligations on businesses (including employers) regarding the processing of personal information.
Positive obligations are placed on employers to, among others, ensure that they comply with the provisions of POPIA regarding the processing of their employees’, customers’ and service providers’ information. It is also important that their employees are equally aware of, and comply with, these obligations when processing any such information on behalf of the employer.
Employers will have 12 months, from 1 July 2020, to ensure that such measures are in place.
It is important that adequate provisions be inserted into contracts of employment and that workplace policies and procedures are implemented to ensure compliance with POPIA. These should include:
(a) The designation of an information officer;
(b) Procedures ensuring information is processed in a lawful manner;
(c) Ensuring that the processing of personal information is done in accordance with the eight conditions provided for in the legislation;
(d) Obtaining consent from employees for the processing of their personal information;
(e) Providing training and information to human resources practitioners as well as employees in order to ensure that information is processed lawfully and that employees, as ‘data subject’s , are aware of their rights;
(f) Putting in place measures to ensure the processing of ‘special personal information’ is lawful;Dealing with any cross-border processing of information; and
(g) Implementing procedures to address and deal with any complaints from, among others, employees regarding the processing of their personal information;
We are able to assist with preparation and/or reviewing of abovementioned and to advise on all aspects of POPIA.
Latest News
Your customer has entered business rescue. The next move matters
by Eric Levenstein, Director and Head of Insolvency & Business Rescue, Amy Mackechnie, Senior Associate, and Clio Patricios, Candidate Attorney [...]
Invisible data collection through a privacy lens
by Ahmore Burger-Smidt, Director and Head of Regulatory More than seven million pairs of Meta’s Ray-Ban smart glasses were sold [...]
Cybercrime across borders: Navigating Africa’s fragmented legislative landscape – Part 2
by Ahmore Burger-Smidt, Director and Head of Regulatory, and Boitumelo Khwene, Candidate Attorney In Part one of this series, we [...]
Cybercrime across borders: Navigating Africa’s fragmented legislative landscape – Part 1
by Ahmore Burger-Smidt, Director and Head of Regulatory, and Boitumelo Khwene, Candidate Attorney The Compliance Imperative By the time you [...]
The externalisation of South African Intellectual Property – Navigating exchange control rules and copyright law in cross-border computer software development
by Janine Hollesen, Director and Head of Intellectual Property, Deon Griessel, Director, and Khanyisa Tshoba, Associate 1. The Regulatory Landscape: [...]
When AI becomes the incident: From rogue agents to prompt injection – Is your organisation ready to detect it, stop it and report it?
by Tebogo Sibidla, Director Artificial Intelligence (AI) is rapidly moving from answering questions to taking actions on our behalf. This [...]
