32

Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

Embed Size (px)

DESCRIPTION

Ovations Group is ideally positioned to help South African companies implement processes and best practices to ensure compliance with the Protection of Personal Information (PoPI) act. This presentation outlines the fundamentals of the act and explains how the Ovations Group can assist companies in avoiding the pitfalls PoPI presents.

Citation preview

Page 1: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance
Page 2: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

OVERVIEW

OUR APPROACH

OUR OFFERINGS

CONCLUSION

Page 3: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

DO YOUR POLICIES AND PROCEDURES ENABLE DATA PRIVACY?

Page 4: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

THE PROTECTION OF PERSONAL INFORMATION (POPI) ACT WILL HAVE AN IMPACT ON ALMOST EVERY COMPANY OPERATING IN SA?

DID YOU KNOW:

Page 5: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

THE POPI ACT WILL

ESTABLISH ACODE OF CONDUCT FOR CONFIDENTIAL HANDLING OF PERSONAL INFORMATION

Page 6: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

CONDITIONS FOR LAWFUL PROCESSING OF PERSONAL INFORMATION

Collection of data

Processing limitations

Retention of data

Deletion of information

Data security

Data subject participation

Notification

7

Page 7: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

COLLECTION OF DATA

Information must be collected directly from the individualExceptions:– Public records– Consent given to a third party – Law enforcement

Page 8: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

COLLECTION OF DATA

The person must be aware of the purpose for collecting their personal information and give consent

There is additional consent needed to store and process data outside of South Africa

Page 9: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESSING LIMITATIONS Businesses are not permitted to processpersonal information of children under 18

Page 10: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

Religious or philosophical beliefs

PROCESSING LIMITATIONSUnless specifically permitted, you areNOT ALLOWED to process information about…

Page 11: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

Trade union membership

or political opinions

PROCESSING LIMITATIONSUnless specifically permitted, you areNOT ALLOWED to process information about…

Page 12: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESSING LIMITATIONSUnless specifically permitted, you areNOT ALLOWED to process information about…

Health, sexual life or biometric details

Page 13: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

Race or ethnic origin

PROCESSING LIMITATIONSUnless specifically permitted, you areNOT ALLOWED to process information about…

Page 14: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESSING LIMITATIONSUnless specifically permitted, you areNOT ALLOWED to process information about…

Criminal Behaviour

Page 15: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

RETENTION OF DATA

Information must NOT be kept any

longer than is necessary for

processing

Page 16: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

DELETION OF INFORMATION

Data must be destroyed as soon as possible

It must be impossible for data to ever be recovered or reconstructed

Page 17: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

DATA SECURITY

Technical and organisational security measures to prevent data loss or damage, or unlawful access to personal information are essential.

Page 18: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

DATA SUBJECT PARTICIPATION

A person must be able to:

Find who has their data

Request a copy of all personal information heldby an organisation

Request amendments or deletion of their data, and receive proof this has been done

**********

Page 19: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

ENFORCEMENT

Official complaint process

Punishment up to 10 years imprisonment and/or fine up to R10 million

Civil action may also be taken

Page 20: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

OVERVIEW

OUR APPROACH

OUR OFFERINGS

CONCLUSION

Page 21: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

OUR APPROACH

We can help you define a strategy and roadmap to become compliant with the POPI Act.

We provide a complete and holistic execution that interweaves the key areas of PEOPLE

PROCESSESTECHNOLOGY

Page 22: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESS DIAGRAMOur transformational approach focusing on enablement of people, process and technology.

INSIGHTTRANSFORMATION

ROADMAPENABLEMENT

• People understanding• Skills and capacity• Process capability• Technology availability

and capability

Design the business response to ensure effective and efficient compliance

Prioritised investment route map based on business and IT considerations in support of defined architecture

Currentstate

POPI vision and strategy

People educationProcess compliance

Technology capability

Page 23: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESS DIAGRAMOur transformational approach focusing on enablement of people, process and technology.

INSIGHTTRANSFORMATION

ROADMAPENABLEMENT

• People understanding• Skills and capacity• Process capability• Technology availability

and capability

Design the business response to ensure effective and efficient compliance

Prioritised investment route map based on business and IT considerations in support of defined architecture

Currentstate

POPI vision and strategy

People educationProcess compliance

Technology capability

Page 24: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESS DIAGRAMOur transformational approach focusing on enablement of people, process and technology.

Currentstate

POPI vision and strategy

People educationProcess compliance

Technology capability

Status of Enablement

Business and compliance risks

Business and risk

considerations

Costs and time considerations

Business architecture

Information systems architecture

Technology architecture

People enablement

Page 25: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

OVERVIEW

OUR APPROACH

OUR OFFERINGS

CONCLUSION

Page 26: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

STRATEGY

POPI Strategy and Implementation Roadmap

Business case development

Page 27: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

TRAINING AND EDUCATION

POPI Act and Implications customised for implemented solutions

Page 28: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

CHANGE & COMMUNICATION

Strategy & Planning

Development & execution of awareness campaigns

Page 29: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

DATA

Data Audits, Security &

Management

Page 30: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

PROCESS & CONTENT

Process Solution Design & Automation

Records Management assessment, design & enablement

Security policy enablement

Content archival solutions

Content Governance

Document destruction services    

Page 31: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

OVERVIEW

OUR APPROACH

OUR OFFERINGS

CONCLUSION

Page 32: Ovations Group - Introducing the Protection of Personal Information (PoPI) act and achieving compliance

Ovations is equipped to transform your business to comply with the Protection of Personal Information Act.

LET US HELP YOU BECOME COMPLIANT