Data Protection

How ready is your business for a Data Protection audit ? 

Do you have an information officer?

Have you mapped your personal information?     

Do you have a data protection policy?     

Do you have a data retention policy?   

Do you have documented data processing arrangements?         

Do you conduct supplier due diligence?     

Do you have a breach response procedure?

Do you know where your data is stored?   

Do you transfer personal information outside the country?       

Have your employees attended data protection training?           

 

Your answers to these questions may indicate that you organisation has areas which require further review.

 

 

Why is Data Protection important for businesses? 

Data Protection is not only a legal requirement, it is also a business, reputational and risk management issue. 

Does the Protection of Personal Information Act (POPIA) apply to my business?

This applies to all organisations which process personal information in South Africa, irrespective of the size or type of entity. 

What are some of the key Data Protection requirements for a business?

Businesses must process information lawfully and transparently, collect only what is neccessary, keep it secure, respect individuals rights and comply with POPIA's retention, breach-notification, and information officer appointment requirements. 

What are the key actions to comply with the Data Protection direct martketing requirements?

A company may not engage in direct marketing without consent from the recipient. You may ask for consent only one time. If consent is not granted, you may not contact the recipient again for the puposes of direct marketing.