Employers need to be fully compliant with POPIA by 30 June 2021. Non-compliance can result in significant penalties - up to 10 years imprisonment and/or R10 million in administrative fines.
POPIA applies to personal information and special personal information that is subject to processing or further processing. Processing encompasses a wide range of activities including the initial obtaining of personal information and the use and retention of that information as well as access, disclosure and final disposal of that information.
From an employment perspective, POPIA applies to:
Employers must therefore ensure that they lawfully process the personal information of job applicants, employees, retired employees and dismissed employees. To the extent that employers process personal information of independent contractors and other service providers, they must also ensure that they lawfully process such information.
Lawful processing will be achieved by complying with the eight conditions set out in POPIA:
POPIA prohibits processing of special personal information, which includes information on race, health, criminal behaviour and trade union membership unless:
From an employment perspective, employers should take the following steps to ensure POPIA compliance:
Section 99(1) of POPIA provides that a data subject or the Regulator (at the request of the data subject) may institute a civil action for damages against a responsible party for breach of POPIA. Action may be instituted irrespective of whether or not there is intent or negligence on the part of the "responsible party". "Responsible party" include employers.
Employers must bear in mind that many employees process high volumes of personal information both internally and externally. A good example of this in practice is the Human Resources function of any employer.
Employers will need to ensure that they follow the steps listed above to limit the risk of employees processing information unlawfully and in contravention of POPIA.
Employers should bear this section in mind as it creates significant legal risk for employers if employees do not process information lawfully and in compliance with POPIA.