After much anticipation and a period of almost seven years it has been officially announced that the core sections of the Protection of Personal Information Act (POPIA) commenced on 1 July 2020 and on 30 June 2021.
These core sections took effect on 1 July 2020 and organisations will be allowed twelve months to 30 June 2021 to become compliant with the Act.
POPIA makes it critical for organisations that process personal information of individuals such as employees or customers, and juristic persons such as companies or trusts, to put data privacy systems in place to ensure that personal information is used only for the purposes permitted and is protected against unauthorised access or loss.
Impact
The Act affects all businesses, and public and private entities, and will impact on technology, policies, procedures and risk and compliance frameworks across the business including in ICT, HR and marketing.
Given the wide-ranging implications of the Act and the likely impact on technology and processes, it is prudent for organisations to begin preparations as soon as possible to ensure compliance can be achieved within the relatively short phasing-in period of 12 months.
We advise that organisations should begin a review of their personal information processing systems to ensure compliance with the Act’s obligations in order to avoid the significant civil and criminal sanctions associated with non-compliance.
Getting started
Organisations should assess the amount of preparation needed to ready themselves for the implementation of the Act by considering the following steps, at a minimum:
- Audit policies and processes used to collect, record, store, disseminate and destroy personal information.
- Define the purpose of the information gathered and processed.
- Limit the processing parameters.
- Take steps to notify the data subjects.
- Check the rationale for any further processing.
- Ensure information quality.
- Notify the Information Protection Regulator.
- Accommodate data subject requests.
- Retain records for required periods.
- Consider data that is being transferred across borders.
The Act creates burdensome and time-consuming obligations to ensure systems and processes are compliant, potentially to develop new systems and deploy additional technology, and set up a compliance framework, which will place additional pressures on businesses while dealing with the impact of the COVID-19 pandemic at the same time.
| Imraan Mahomed | Director and Practice Group Leader | mail me |
|
![]() |
| Hedda Schensema | Director | mail me |
|
![]() |
| Jean Ewang | Director | mail me |
|
![]() |
| Phetheni Nkuna | Director | mail me |
|
![]() |
| Bongani Masuku | Director | mail me |
|
![]() |
|
| Lawtons Africa | |
|

































