
Certification of POPIA Compliance
Examples of what can be evaluated?
- Governance of processing operations
- Record of processing operations
- Processing operations are in compliance with the conditions
- International data transfers
- Data sharing with third parties
- Personal information impact assessments
- Consent management
- Monitoring of processing operations
- Record of interferences and data breaches
- Risk management
- Breach reporting to the Information Regulator
- Staff competencies
- Staff recruitment
- Processing of employee information for the purpose of salary payment.
- Cloud - Infrastructure as a service
- Cloud - Platform as a service
- Cloud - Software as a service
- Cloud processing with/without transfers outside SA.
| Processing activity (as per the register) | Role | Level 1 Organisation | Level 2 Circumstances / purpose | Level 3 functional application |
Level 4 IT infrastructure |
| Recruitment | Responsible party | Financial institution | HR department | SAP-HR | Windows server farm, Oracle DB |
| Newsletter | Responsible party | Financial institution | Marketing | CRM | Cloud solution SAAS |
| AML/KYC | Responsible party | Financial institution | Compliance | World Check | Unix servers – Oracle DB |
What is achieved?
Assurance that:
- The constitutional right to privacy is being respected and fulfilled.
- Compliance with Conditions for the lawful processing of personal information.
- Appropriate technical and organisational measures have been implemented
- Adequate safeguards are implemented to protect data subject rights.
POPIA Compliance Framework Development and Implementation
Assessment criteria focus on:
- framework completeness
- safeguards to protect personal information
- capability in protecting privacy rights
- readiness for non-compliance
- breach notification capability.
Compliance with the conditions for the lawful processing of Personal Information
Assessment criteria focus on:
- the legitimacy of the processing of personal information
- the conditions for the lawful processing of personal information
- the data subjects’ rights
- the personal information impact assessments, pursuant to regulation 4(b)
- the safeguards put in place to protect personal information
- the obligation to notify data subjects of breaches.
POPIA Personal Information Impact Assessments
Assessment criteria focus on:
- target of evaluation
- documentation of processing operations
- risk assessment
- countermeasures
- implementation of effective safeguards.
