No more abuse of personal information
The enactment of a new data law will end the abusive use of personal information and bring South Africa in line with internationally accepted privacy principles.
In October 2005, the Law Commission finalised a review of South Africa’s privacy and data protection laws and recommended a new and separate law to deal with the protection of personal information. After the review of numerous comments by the Law Commission and certain amendments to the original law, Cabinet approved the Protection of Personal Information Bill which is now heading for approval by Parliament.
According to Reinhardt Buys of Deloitte Legal, the Bill will have far reaching implications for those businesses in the private and public sector that collect and use personal information of individuals. “By establishing duties on those who process personal information and rights for those whose information is being processed, the Bill gives much more control to the individual,” he says.
The Bill provides for no less than 22 duties and obligations on companies who process personal information. Once enacted, the Bill will prevent the collection of personal information without the prior consent of the individual. Once collected, data may only be used for the specific purpose that was disclosed to the individual prior to collection.
“Companies will not be able to retain records of personal information for periods longer than necessary for achieving the purpose the data was obtained in the first place,” continues Buys. “In compliance with the principle of information quality, companies which process personal information will have to ensure that the data is complete, accurate and not misleading.”
The principle of openness requires data collectors to register with the Information Protection Regulator. In terms of section 22 of the Bill, individuals from whom data is collected will have the right to request companies to confirm, free of charge, whether or not they hold personal data of the individual and to whom such data was disclosed.
In terms of the security principle, companies will have to implement appropriate, reasonable technical and organisational measures to prevent the loss or unauthorised use of personal information. Companies will have to identify all internal and external risks to personal information and establish and maintain appropriate security safeguards.
“In addition to a well drafted privacy and data protection policy, companies will have to invest in technologies like encryption and access control” says Buys. Section 21 places an obligation on companies to notify the individual of unauthorised use or disclosure of personal information in order to allow the person to take protective measures.
“If an employee laptop containing personal information is stolen, the employer will have to inform every person whose data is at risk,” cautions Buys. “The processing of so-called ‘special personal information’ which includes personal information of a child and the religious beliefs of an adult may only be processed in a very limited manner.”
Finally, companies will have to appoint Information Protection Officers to ensure compliance with the provisions of the Bill. The Information Protection Regulator will have wide-ranging investigative and enforcement powers.
“Non–compliance with the provisions of the Bill will expose companies to complaints being lodged with the Regulator, criminal fines and civil damages claims from individuals,” concludes Buys.
Protection of personal information – comments and views