
Explore the protection of personal information act (papaya) in South Africa, including its lawful bases for organizations to collect, disseminate, and retain personal data, and the penalties for noncompliance.
Outline the current South Africa data protection landscape under popia, including commencement dates, information regulator roles, and the 12-month transition to compliance.
Explore how the information regulator's guidance on processing personal information supports containment of covid-19 by guiding public and private bodies to limit privacy rights while reducing spread and impact.
At the of this lecture you should understand the characteristics of personal information and be able to distinguish the following:
Personal information versus information
Personal information versus confidential information
Explore a proposed guideline for identifying personal information, using a checklist across categories such as names, numbers, online identifiers, contact details, demographics, health, biometrics, history, beliefs or opinions, and correspondance.
Explore the 17 categories of processing under POPIA, from active collection and passive receipt to storage, restriction, and destruction, with real-world examples for managing personal information.
Under the POPIA course all you should know, openness requires transparent processing, documentation, and notifying data subjects with purpose, source, recipients, rights, and regulator contact.
Explain how to safeguard personal information under popia by implementing reasonable technical and organizational measures for integrity and confidentiality, and outline breach notification requirements.
Explore current cyber security trends, including rising threats and alerts from internet interconnectivity, and the growing need for skilled analysts and employee education to prevent data breaches.
Analyze how social media expands the cyber security attack surface by revealing vast personal data, from YouTube videos to emails and searches, highlighting data value and protection needs.
Institute admin controls and tech controls to start a cybersecurity program, including policies, incident response, disaster recovery, asset management, threat modeling, and ongoing monitoring and logging.
Explore threat actors from internal users to hackers, hacktivists, and governments, and how they compromise personal data through malware, data sales, political motives, and large-scale attacks.
Respond quickly to personal information breaches to limit damage to confidentiality, integrity, and availability. Recognize events versus incidents and learn how a computer security incident response team coordinates the response.
The POPIA course is an engaging, illustrative, and interactive course. It is based on the Protection of Personal Information Act (POPIA), a comprehensive privacy law that is mandatory for all businesses within the private and public sector that process personal information in South Africa. Using illustrative graphics, animations, and real-life examples, the course details the crucial elements of POPIA that businesses should be aware of in order to comply. The course illustrates how through the POPIA, businesses will be able to maintain the integrity and confidentiality of their clients’ and employees’ personal information by preventing loss, damage, and unauthorized access to the personal data.
Consequences of non-compliance with the POPI Act
Ignorance when it comes to the POPIA act could have devastating consequences for many organizations. Violators of the POPI Act could be fined up to R10 million or face 10 years imprisonment. Moreover, your business also runs the risk of damaging client relationships and overall business reputation, should you act recklessly with personal information.
Course Objectives
After this course, learners will learn the following sections of the POPI Act:
the purpose of the Act,
the application and exclusion provisions,
the lawful processing of personal information and exemptions thereof
sections relating to the Information Officer,
sections relating to the Information Regulator,
provisions regulating direct marketing by means of unsolicited electronic communications,
enforcement, complaints, offenses, and penalties