POPI Compliance certification

Flakmunki

Active Member
Joined
Oct 13, 2008
Messages
52
Howzit All,

Apologies if this post is the wrong section, this seemed to be the best fit.

At my company we deal with a lot of virtualisation and cloud solutions and the POPI compliance question and whether the setups will comply is coming up a lot lately.

For those who dont know what POPI is : http://www.justice.gov.za/legislation/acts/2013-004.pdf

Does anybody know if there is certification that can be done or training that can be attended to knowledge up on this, especially on the POPI act in the I.T space?
 

newklear

Expert Member
Joined
Apr 15, 2008
Messages
1,458
Howzit All,

Apologies if this post is the wrong section, this seemed to be the best fit.

At my company we deal with a lot of virtualisation and cloud solutions and the POPI compliance question and whether the setups will comply is coming up a lot lately.

For those who dont know what POPI is : http://www.justice.gov.za/legislation/acts/2013-004.pdf

Does anybody know if there is certification that can be done or training that can be attended to knowledge up on this, especially on the POPI act in the I.T space?

Hey Flakmunki

Here and here
 

poffle

Executive Member
Joined
Apr 21, 2007
Messages
5,462
Lol, good luck with Cloud solutions and POPI! Client data spread across multiple servers... not gonna happen.
 

Cray

Honorary Master
Joined
Oct 11, 2010
Messages
34,548
Lol, good luck with Cloud solutions and POPI! Client data spread across multiple servers... not gonna happen.

Cloud data spread across servers in multiple countries is irrelevant as long as all data is stored in countries that have similar POPI legislation.
 

MagicDude4Eva

Banned
Joined
Apr 2, 2008
Messages
6,479
The closest you get with storing PII in the cloud is if those cloud companies comply to safe harbour rules. I guess the biggest challenge will still be jurisdiction: Let's say you host in the cloud, your cloud services get compromised due to the cloud service providers negligence and your customer data leaks - in this case you as the company will have violated POPI and would have a very difficult time to make the service provider accountable.

I personally will never host our customer data anywhere but in SA (and on our dedicated equipment). Most guys who jumped onto AWS 2-3 years ago are now having serious OPEX issues due to the exchange rate (their cost has gone up by 70% in 4 years).
 
Top