{"id":15486,"date":"2017-10-20T14:59:31","date_gmt":"2017-10-20T12:59:31","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=15486"},"modified":"2017-10-20T14:59:31","modified_gmt":"2017-10-20T12:59:31","slug":"when-do-south-african-organisations-have-to-comply-with-gdpr","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2017\/10\/20\/when-do-south-african-organisations-have-to-comply-with-gdpr\/","title":{"rendered":"When do South African organisations have to comply with GDPR?"},"content":{"rendered":"<p><em>Blog courtesy of Redstor<\/em><\/p>\n<p>The General Data Protection Regulation is a piece of legislation that was approved and put in place by the European Parliament in April 2016. As European Law, it will fully take effect after a 2-year transition ending 25 May 2018; it will impact not only the UK and the member states of the EU but countries that are trading with the EU.<\/p>\n<p>As a result, there are questions that require answering; namely how do you comply and when can you transfer data?<\/p>\n<p><strong>When can personal data be transferred outside the European Union?<\/strong><\/p>\n<p>Personal data may only be transferred outside of the EU in compliance with the conditions for transfer. A transfer of personal data to a third country or an international organisation may take place where the commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question, ensures an adequate level of protection.<\/p>\n<p>You may transfer personal data where the organisation receiving the personal data has provided adequate safeguards. Individuals\u2019 rights must be enforceable and effective legal remedies for individuals must be available following the transfer. Adequate safeguards may be provided for by:<\/p>\n<ul>\n<li>A legally binding agreement between public authorities or bodies;<\/li>\n<li>Binding corporate rules (agreements governing transfers made between organisations within in a corporate group);<\/li>\n<li>Standard data protection clauses in the form of template transfer clauses adopted by the commission;<\/li>\n<li>Standard data protection clauses in the form of template transfer clauses adopted by a supervisory authority and approved by the commission;<\/li>\n<li>Compliance with an approved code of conduct approved by a supervisory authority;<\/li>\n<li>Certification under an approved certification mechanism as provided for in the GDPR;<\/li>\n<li>Contractual clauses agreed authorised by the competent supervisory authority; or<\/li>\n<li>Provisions inserted into administrative arrangements between public authorities or bodies authorised by the competent supervisory authority.<\/li>\n<\/ul>\n<p><strong>Complying with the regulation<\/strong><\/p>\n<p>In compliance with GDPR, organisations must ensure measures have been taken to minimise risk and the chance of data breach. These processes and policies will also ensure organisations are accountable and can be governed; part of the ICO guidelines on GDPR reads: organisations must \u201cimplement appropriate technical and organisational measures that ensure and demonstrate compliance\u201d.<\/p>\n<p>If firms do not comply with the regulations that are put forward by GDPR, they can be subject to hefty fines. Both the data controller and the data processor will be subject to fines, with the regulatory bodies of each country working in tandem to establish the appropriate measures to take. For the UK, the ICO will be funded by the fines that they administer \u2013 meaning they will have a vested interest in ensuring that fines are as large as possible. Furthermore, companies of all sizes will be subject to punishment for non-compliance. Recently, the Spanish authorities fined Facebook for having inadequate data sharing policies, the fine totalled 1.2 million euros. Facebook was found guilty of \u2018not adequately collecting the consent of either their users or non-users\u2019.<\/p>\n<p><strong>PoPI vs GDPR<\/strong><\/p>\n<p>GDPR operates in a similar vein to the Protection of Personal Information Act (PoPI) altering the scope of data protection, management and governance in South Africa.<\/p>\n<p>PoPI, simply put, is legislation that protects a person\u2019s right to privacy and the measures that must safeguard their personal information when it is processed by a responsible party. The eight principles governing the protection of personal information \u2013 during its processing and use \u2013 against loss, damage and its unlawful or unauthorised access, processing and destruction are summarised as following:<\/p>\n<p>\u2022 Accountability<br \/>\n\u2022 Processing limitation<br \/>\n\u2022 Purpose specification<br \/>\n\u2022 Further processing limitation<br \/>\n\u2022 Information quality<br \/>\n\u2022 Openness<br \/>\n\u2022 Security safeguards<br \/>\n\u2022 Data subject participation    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blog courtesy of Redstor The General Data Protection Regulation is a piece of legislation that was approved and put in place by the European Parliament in April 2016. As European Law, it will fully take effect after a 2-year transition ending 25 May 2018; it will impact not only the UK and the member states [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":15487,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[481,136,399,19],"tags":[733,1080,445,876,453,1458],"class_list":["post-15486","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-government","category-industry-expert","category-more-news","category-regional-news","tag-data-protection","tag-europe","tag-gdpr","tag-popi","tag-south-africa","tag-uk"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/15486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=15486"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/15486\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/15487"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=15486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=15486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=15486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}