0% found this document useful (0 votes)
32 views1 page

PPI and The Conditions For Processing Information

Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views1 page

PPI and The Conditions For Processing Information

Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

The Eight Conditions for Lawful

Processing of Personal Information


Complying with the Protection of Personal Information Act
The Protection of Personal Information Act will require every public and private body to comply with the eight conditions
that prescribe the minimum threshold requirements for lawful processing of personal information in South Africa. Public
and private bodies should be mindful of the rights and remedies of persons to protect their personal information from
processing that is not in accordance with the Protection of Personal Information Act.

Overview Openness
These eight conditions set out the requirements for the Only process personal data after updating PAIA manual
lawful processing of personal information. The data subject must be aware of the collection of the data
Accountability and the name and address of the responsible party, whether
The responsible party must ensure that the conditions for voluntary or mandatory, and of any law authorising
lawful processing of personal information set out in the Act, collection, except if
and all the required measures, are complied with.  data subject is already aware
 all particulars are stated in PAIA information manual
Processing limitation  data subject consents to non-compliance
Business processes provide the context for processing  information will be used without identifying data subject
personal information – i.e. the specific purpose  personal information is already in the public domain.
Data collection must be proportionate to purpose – minimal
Data processing must be for a legitimate purpose Data Subject Participation
Data subjects must give consent
Establish communication processes with data subjects (via
Collection of personal data must be directly from the data
the Information Officer)
subject unless it is contained in a public record
Provide data subjects with access to personal information
Data models prevent inference of prohibited data elements
Enable data subjects to request correction of personal data
Limit the transfer of personal data to service providers
Manner of access to information is defined in PAIA manual.
Data subject must be able to object, in prescribed manner.

Purpose Specification Security Safeguards


Collection of personal information must be for a specifically Business controls for maintaining integrity:
defined, lawful purpose related to a function of the  Identify personal data (structured and unstructured) in all
business processes (formal and informal)
responsible party  Identify business processing manual controls
Data subject must be aware of the purpose of collecting data  Identify application systems and IT processes that support
The purpose for processing personal information must be the business processes
clear  Identify programmed procedures supporting the
Record retention must not be longer than necessary unless complete and accurate processing of personal data
required by law, a contract or the data subject has consented  Maintain appropriate granularity in user access controls
 Maintain appropriate application level security
A record of the use of personal data to make a decision must  Maintain appropriate information resource protection
be retained for such period required by a law or long enough  Prevent data leakage (structured and unstructured data)
for the data subject to request access to the record  Maintain the capability to detect security breaches
Destroy, delete or de-indentify as soon as practically possible  Regularly review contractual obligations of third parties
Destruction of personal information must be in a manner Prohibit the processing of special personal information
that prevents reconstruction in an intelligible form. Comply with the requirements of Information Officer and/or
Information Regulator.

Further Processing Limitation Action Plan


Further processing must be compatible with original purpose Identify the legitimate business purposes for processing data
Be aware of the potential consequences of further processing Establish a register of processing personal data
Take note of any contractual rights and obligations Obtain prior authorisation from the Information Regulator of
processing of personal data when required
Take steps to prevent further processing of personal data
Contact and communicate with data subjects
Data mining must not exceed original purpose Obtain consent from data subjects
Allow retention for historical, statistical or research purposes Enable data subjects to object to processing of personal data
Stop unlawful processing Perform risk assessment for the protection of personal data
Information Quality Educate staff
Maintain the accuracy of collected personal information Implement a system of internal control to maintain integrity
Check that personal data is not misleading Secure structured and unstructured data
Ensure that personal data is up-to-date Reduce record retention, destroy unnecessary personal data
Be aware of the impact the integrity of personal data has on Change contracts and obligations of service providers
the purpose for collecting personal data (additional costs of outsourcing for increased security)
Note: master data must exclude unnecessary records Appoint an Information Officer for data subjects to liaise with
Note: master data must be secured, and accessed only on the Respond to requests of the Information Officer
need-to-know basis. Comply with requirements of the Regulator.

IT Governance Netwrok, copyright 2012 www.itgovernance.co.za [email protected]

You might also like