Protection of Personal Information Act
Act 4 of 2013 regulates how personal information must be processed, including employee health and safety data.
Key Requirements
Lawful Processing
Process personal information only with consent or other lawful basis, ensuring accountability and transparency.
Purpose Specification
Collect personal information for specific, explicitly defined, and lawful purposes related to OH&S management.
Data Minimization
Collect only personal information that is adequate, relevant, and not excessive for OH&S purposes.
Security Safeguards
Implement appropriate technical and organizational measures to protect personal information from unauthorized access.
Data Subject Rights
Respect employees' rights to access, correct, and delete their personal information where applicable.
Notification of Security Breaches
Notify Information Regulator and affected data subjects of security compromises without unreasonable delay.
Reporting Requirements
| Report Type | Deadline | Form/Document |
|---|---|---|
| Security Breach Notification | Without unreasonable delay | Notification to Information Regulator |
| Data Subject Requests | Within 30 days of request | POPIA Request Response |
| Processing Operations | Prior to processing (if required) | Prior Authorization Application |
| Privacy Impact Assessment | Before high-risk processing | PIA Report |
Automate Your POPIA Compliance
Ensemble automatically tracks deadlines, generates required reports, and ensures you never miss a compliance obligation.