Privacy by design – the cornerstone of addressing privacy risks

1
311

Nada Ford | Legal Manager | Tax & Legal | mail me |
Beulah Simpson | Associate Director | Tax & Legal | mail me |
Fathima Rawat | Legal Manager | Tax & Legal | mail me |
Finn Elliot | Legal Partner | Tax & Legal | mail me |

| KPMG South Africa |


The privacy and protection of personal information has been front of mind for many organisations since the enactment of the Protection of Personal Information Act (POPIA) in 2013 and its subsequent commencement in July 2020.

Most organisations have been scrambling to become ‘POPIA compliant’ within the short transitional period and have not had the time or inclination to ‘future proof’ new technology, processes, services or products from a privacy perspective. That is, they have not been applying the concept of ‘Privacy by Design’ into their business.

The concept of ‘Privacy by Design’, a term coined by Ann Cavoukian, the former Information and Privacy Commissioner of Ontario, Canada, necessitates that data privacy is embedded into every new and/or modified technology, process, service or product that involves the processing of personal information at its inception. The European Union’s General Data Protection Regulation (GDPR) provides for the term ‘Protection by Design’. The effects of both concepts are similar.

In terms of the ‘Privacy by Design’ principles, organisations should proactively ensure that appropriate and effective measures and standards exist from the outset to comply with the conditions for the fair, transparent, lawful and secure processing of personal information throughout the lifecycle of the personal information within the organisation. Privacy should be the default setting from the outset – it should not be an add-on or afterthought. Respect for the data subject is paramount, making sure that the measures employed by organisations that process personal information are user-centric is also important.

An EU perspective of ‘Privacy by Design’

It is an explicit requirement, in terms of the GDPR, that data protection principles should be considered throughout the project lifecycle, from implementation and on an ongoing basis after the new technology, process, service or product has been designed.

In this regard, technical and organisational data protection measures are required to be implemented taking into account:

  • state of the art of available technology;
  • cost of implementation;
  • nature, scope, context and purpose of processing; and
  • impact the data processing will have on the rights and freedoms of individuals.

Ultimately, the measures deployed by the organisation must be appropriate and effective as assessed against their purpose (i.e., to protect the rights of the individuals whose personal information is being processed in a manner that is compliant with data protection principles). The safeguards that have been identified by the organisation must be integrated into the processing activities to protect the personal information of individuals.

One of the key methods used to give effect to the concept of ‘Privacy by Design’ is the


The full article is reserved for our subscribers!

Read the full article by Nada Ford, Beulah Simpson, Fathima Rawat and Finn Elliot, KPMG South Africaas well as a host of other topical management articles written by professionals, consultants and academics in the August/September 2023 edition of BusinessBrief.


VIEW our subscription options

ALREADY SUBSCRIBED?


Questions or problems?

admin@bbrief.co.za | +27 (0)11 788 0880 |


 



1 COMMENT

LEAVE A REPLY

Please enter your comment!
Please enter your name here