<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>POPI Archives - Cognite Marketing</title>
	<atom:link href="https://www.cognite.co.za/tag/popi/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cognite.co.za/tag/popi/</link>
	<description></description>
	<lastBuildDate>Fri, 09 Jun 2023 05:29:00 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://www.cognite.co.za/wp-content/uploads/2023/02/Cognite-Marketing-Favicon-150x150.jpg</url>
	<title>POPI Archives - Cognite Marketing</title>
	<link>https://www.cognite.co.za/tag/popi/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Why is South Africa’s POPI Act so important?</title>
		<link>https://www.cognite.co.za/why-is-south-africas-popi-act-so-important/</link>
		
		<dc:creator><![CDATA[C0gn1t3_M@rk3t1ng]]></dc:creator>
		<pubDate>Wed, 21 Jul 2021 07:11:39 +0000</pubDate>
				<category><![CDATA[Digital Marketing]]></category>
		<category><![CDATA[Learn About Marketing Your Business]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[POPI]]></category>
		<guid isPermaLink="false">https://www.cognite.co.za/?p=19921</guid>

					<description><![CDATA[<p>In this digital age, it has become more important than ever to protect your data and private information online. The risk of privacy breaches threatens organisations, businesses and people of all kinds.</p>
<p>The post <a href="https://www.cognite.co.za/why-is-south-africas-popi-act-so-important/">Why is South Africa’s POPI Act so important?</a> appeared first on <a href="https://www.cognite.co.za">Cognite Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In this digital age, it has become more important than ever to protect your data and private information online. The risk of privacy breaches threatens organisations, businesses and people of all kinds. The Protection of Personal Information Act (commonly known as the POPI Act or POPIA) is the new foundation of South Africa’s data protection laws.</p>
<p>The purpose of the POPI Act is to protect the personal information of people and organisations, mitigating the potential risks that come with private data breaches. The POPI Act looks to prevent South Africans from having their money or identity stolen as a result of personal information being collected and misused.</p>
<p>Essentially, the POPI Act wants to protect the privacy of South Africans by keeping our mobile, computer and financial data safe and regulated. The right to privacy is a fundamental human right and extends beyond our physical privacy and into our online presence. The POPIA’s compliance requirements are intended to help create a more secure digital environment for South Africans to conduct our business and share online information.</p>
<p><strong>Is the POPI Act new?</strong></p>
<p>The short answer is: no. The Protection of Personal Information Bill was first drafted in 2009 and spent a decade navigating South Africa’s legislative system. In 2020, the Bill passed and became what we know today as the Protection of Personal Information Act.</p>
<p>The POPI Act is South Africa’s equivalent to the EU’s GDPR (General Data Protection Regulation) which set conditions for responsible parties to lawfully process the personal information of data subjects. This is not intended to stop the processing of personal data, but to create legal and security requirements for its collection and use.</p>
<p>South Africa’s POPI Act does not stop organisations or individuals from processing personal data or require consent from their data subjects to process that information. Whoever, or whichever organisation, decides to process personal information in South Africa will be responsible for complying with the regulations and conditions of the POPI Act.</p>
<p><strong>POPI Act compliance has begun</strong></p>
<p>The President announced in mid-2020 that a one-year grace period would begin on 1 July 2020 before the Act becomes law. This 12-month period was intended to give South Africans and organisations the opportunity to become compliant with the new POPI Act. As of 30 June 2021, the POPI Act has commenced with its compliance expectations and corresponding Information Regulators and Officers should be assigned within your organisation.</p>
<p><strong>Who does the POPI Act apply to?</strong></p>
<p>The Act, essentially, applies to all South African persons or organisations that record or store any type of personal information that belongs to other data subjects. Unless those data records are subject to more stringent regulations, that organisation must process that personal information in compliance with the POPI Act.</p>
<p>“Processing” personal information would include the acts of collecting, receiving, recording, organising or retrieving private data, as well as the using, sharing, disseminating, selling or distributing of that data. Any natural or juristic persons (or organisations) who “process” personal information here must comply with South Africa’s data protection laws, including large corporations and government bodies.</p>
<p><strong>Things you should know about the POPI Act</strong></p>
<p>The POPI Act is made up of eight general conditions and three extra conditions that all responsible parties must meet in order to comply. These responsible parties are also responsible for any compliance failures by operators or service providers that they have hired to process their data.</p>
<p>As of the beginning of this month (July 2021), all South Africans and organisations are expected to be fully compliant with the POPI Act. In order to help you gauge your compliance with our new data protection laws, here are a few things you should consider:</p>
<ul>
<li>Audit all of your current data procedures used to process, store or share any personal information. Can you confirm that all of your data is secured according to POPIA compliance requirements?</li>
<li>Organise and classify all personal information being stored and understand why you are processing that data. Ensure that you only access and save appropriate (lawful) data.</li>
<li>Evaluate the methods you are using for processing information. Is that data being processed correctly in accordance with the POPI Act?</li>
<li>Remain consistent in your reasoning. Your reasons for processing, saving or sharing of any personal information should be valid and maintain consistency over time.</li>
<li>Transparency is critical. Make sure that every individual is aware when personal data is being stored or shared – and what you intend to do with it. Users have a right to know why their private information is being processed.</li>
<li>Organisations must ensure their data quality and accuracy. All personal information being processed should be checked to make sure it is accurate, complete and not misleading.</li>
<li>Assign your Information Regulators and Information Officers. They will be responsible for ensuring your organisation’s POPIA compliance when processing personal information.</li>
<li>All private data should be processed for the purpose it was intended and only stored for the time required. A record of transactions and data should be kept for users, however personal information must be deleted after it has served its purpose.</li>
<li>Understand all regulations and restrictions for cross-border and international data transfers. Any private data, coming in or out of South Africa, will also be accountable to the laws of the country you are sharing personal information with.</li>
</ul>
<p>Understanding the rules and regulations of South Africa’s POPI Act will be critical for any persons or business that are processing private data – at any scale. The POPI Act is not intended to become a financial or administrative burden for South African organisations. Rather, it is intended to transform the way we store and share personal information, making our processing more efficient, secure and safe for South Africa’s Internet users.</p>
<p><strong>Cognite Marketing does not offer legal advice. Always consult a legal expert to ensure your compliance with the POPI Act and any other regulations.</strong></p>
<p>What Cognite Marketing does offer is industry-leading expertise in the fields of digital marketing and online data analytics. Visit <a href="http://www.cognite.co.za/">Cognite Marketing</a> and find out how we can transform your business’s online presence.</p>
<p>The post <a href="https://www.cognite.co.za/why-is-south-africas-popi-act-so-important/">Why is South Africa’s POPI Act so important?</a> appeared first on <a href="https://www.cognite.co.za">Cognite Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is GDPR and why is compliance important for your South African company?</title>
		<link>https://www.cognite.co.za/what-is-gdpr-and-why-is-compliance-important-for-your-south-african-company/</link>
		
		<dc:creator><![CDATA[C0gn1t3_M@rk3t1ng]]></dc:creator>
		<pubDate>Thu, 07 Jun 2018 06:47:51 +0000</pubDate>
				<category><![CDATA[Learn About Marketing Your Business]]></category>
		<category><![CDATA[Content Marketing]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[POPI]]></category>
		<guid isPermaLink="false">https://www.cognite.co.za/?p=7704</guid>

					<description><![CDATA[<p>GDPR compliance is compulsory for every business or organisation that collects, maintains, or uses the personal data of EU citisens. The implementation of the General Data Protection Regulation (GDPR) and the subsequent need for GDPR compliance will have a significant impact on how businesses and organisations approach data protection, regardless of their geographical location.  GDPR Data Protection Rules include a comprehensive definition of what constitutes personal data, the rights of individuals to know how their personal data is being used, what personal data can be collected under the GDPR Data Protection Rules, and how businesses and organisations obtain each individual's informed consent.</p>
<p>The post <a href="https://www.cognite.co.za/what-is-gdpr-and-why-is-compliance-important-for-your-south-african-company/">What is GDPR and why is compliance important for your South African company?</a> appeared first on <a href="https://www.cognite.co.za">Cognite Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>GDPR compliance is compulsory for every business that collects, maintains, or uses the personal data of EU citisens. The implementation of the General Data Protection Regulation (GDPR) and the subsequent need for GDPR compliance will have a significant impact on how businesses and organisations approach data protection, regardless of their geographical location.</p>
<p>It is important to make the distinction between an EU Directive and an EU Regulation. An EU Directive is a general set of guidelines EU member states can base their own national laws around, whereas, an EU Regulation is EU-wide legislation that all member states have to comply with and is enforceable by law.</p>
<p>GDPR is an EU Regulation. It replaces the previous 1995 EU Data Protection Directive and standardises data protection laws throughout the European Union. The regulation gives businesses and organisations operating in multiple EU member states a uniform set of rules to work within and resolves issues that could not have been foreseen in the 1995 Directive, such as data processing in the cloud.</p>
<h3><b>Key factors</b></h3>
<p>The EU General Data Protection Regulation came into force on 25th May, 2018 and applies to every business within or outside of the European Union. The key factors of the GDPR Data Protection Rules include a comprehensive definition of what constitutes personal data, the rights of individuals to know how their personal data is being used, what personal data can be collected under the GDPR Data Protection Rules, and how businesses obtain each individual&#8217;s informed consent to use the individual&#8217;s personal data.</p>
<p>The definition of what constitutes personal data will affect every business that uses cookies on their website as it is considered personal data under the GDPR Data Protection Rules. Other identifiers now considered to be personal data include racial or ethnic origin, religious or philosophical beliefs, and genetic or biometric data.</p>
<p>Businesses and organisations reviewing their GDPR compliance efforts should take careful note of how they obtain each individual&#8217;s informed consent. Personal data can only be collected, maintained, or used if an individual has given their consent by a recordable affirmative action. Hence, the individual must be told before giving their consent what the data will be used for and their right to withdraw their consent.</p>
<h3><strong>GDPR compliance</strong></h3>
<p>Any business that collects personal data without informed consent or that fails to delete the data after an individual withdraws their consent, is in breach of GDPR. There are many rights that individuals have that businesses should take into account when reviewing their GDPR compliance. These individual rights include:</p>
<ul>
<li>The right to access stored personal data</li>
<li>The ability to rectify errors in an individual&#8217;s personal data</li>
<li>Know how personal data will be used</li>
<li>Know how long personal data will be stored</li>
<li>Know how personal data is being shared</li>
<li>Individuals can be “forgotten” and have any stored personal data permanently deleted</li>
<li>Know the source of personal data if informed consent was not given</li>
</ul>
<p>In order to comply with the GDPR Data Protection Rules for the rights of individuals, businesses will have to revise their data collection, storage, and processing mechanisms to ensure personal data can be isolated, extracted, and permanently deleted as required.</p>
<h3><strong>GDPR penalties</strong></h3>
<p>Authorities will be given the power to conduct GDPR compliance audits and impose penalties for non-compliance.<br />
Penalties for non-compliance with GDPR can vary widely depending on the nature of the violation, the volume of records disclosed without authorisation, and the efforts made by the business to mitigate a breach of personal data. In worse case scenarios, the penalties for non-compliance with GDPR are substantial, including:</p>
<ul>
<li>Non-compliance with the regulation&#8217;s security standards can result in a fine of up to €10 million or 2% of global annual turnover</li>
<li>Non-compliance with the regulation&#8217;s privacy standards can result in a fine of up to €20 million or 4% of global annual turnover</li>
</ul>
<p>Further penalties for failing to comply with GDPR can be imposed if a business fails to report the unauthorised exposure of personal data within seventy-two hours of the exposure being discovered. The business may also be charged with a criminal offence depending on the national law of the EU member state. If the unauthorised exposure of personal data is likely to result in the affected individual potentially suffering identity theft or fraud, financial loss, discrimination, damage to reputation, or other significant economic or social disadvantage, the breach also has to be notified.</p>
<h3><strong>What you can do</strong></h3>
<p>Many organisations are just beginning to get to grips with personal data capture and use, and the sophisticated level of monitoring and policing that the new legislation mandates. Businesses will need to implement wide-ranging changes to how they process, secure, protect, and report on the data they hold. Businesses can get the ball rolling by:</p>
<ul>
<li>Understanding how GDPR affects you as a business and how you are going to be impacted by this ruling. Consider carrying out a full assessment of which changes apply to your business and the areas which present the greatest risk</li>
<li>It’s crucial that your company understands the resources needed to transform the way the organisation handles personal data and the risks of not complying</li>
<li>The law will hold organisations fully responsible for meeting the new data requirements, so make sure you review existing systems, procedures, and contracts with cloud vendors to avoid hefty fines</li>
<li>Depending on the level of change required in your business, consider appointing a Chief Data Officer or an external partner to oversee GDPR-readiness of your organisation</li>
</ul>
<h3><strong>Be protected, be compliant</strong></h3>
<p>Personal data is increasingly at the heart of a modern organisation’s operations, and this is an excellent time to make sure the level of your data protection in place is fit for the new digital era. Staying within the law is one thing, but meeting changing customer expectations is equally important.</p>
<p>In order to keep up with GDPR Regulation, you can view this helpful checklist:</p>
<ul>
<li><a href="https://gdprchecklist.io/"><strong>https://gdprchecklist.io/</strong></a></li>
</ul>
<p><strong><em>*Please note that Cognite does not offer legal advice. We are just making people aware of it. Businesses and organisations concerned about GDPR compliance should take professional legal advice*</em></strong></p>
<p><strong>Helpful links</strong></p>
<ul>
<li><a href="https://en.wikipedia.org/wiki/General_Data_Protection_Regulation" target="_blank" rel="noopener">https://en.wikipedia.org/wiki/General_Data_Protection_Regulation</a></li>
<li><a href="https://www.eugdpr.org/" target="_blank" rel="noopener">https://www.eugdpr.org/</a></li>
</ul>
<p>&nbsp;</p>
<p>The post <a href="https://www.cognite.co.za/what-is-gdpr-and-why-is-compliance-important-for-your-south-african-company/">What is GDPR and why is compliance important for your South African company?</a> appeared first on <a href="https://www.cognite.co.za">Cognite Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
