Back

Organisational PoPIA Compliance De-identifying, Information Matching, and Filing Systems

Published: Monday, June 21, 2021

Information Technology (IT)Legal ManagementTelecommunicationsSecurity LogisticsSecurityOffice Equipment

There are many crucial factors involved in the Protection of Personal Information Act (PoPIA). For compliance, it is imperative for organisations to fully understand all these factors and how they play out in the real world. Three of the crucial areas that must be discussed include de-identifying, information matching programmes, and filing systems.

    Press Release feature Image

    There are many crucial factors involved in the Protection of Personal Information Act (PoPIA). For compliance, it is imperative for organisations to fully understand all these factors and how they play out in the real world. Three of the crucial areas that must be discussed include de-identifying, information matching programmes, and filing systems.

     

    The PoPIA act has been established for the protection of personal information pertaining to entities as well as individuals. Since the commencement of this act on the 1st of July 2020, Impressions Signatures, a local provider of e-signatures, has made it its mission to freely provide relevant information to organisations regarding the Act through its PoPIA Campaign.

     

    De-identifying data refers to when data that could potentially identify someone is hidden or removed. This personal data of a data subject could be identifying either on its own or in combination with other data.  Data is considered identifiable of a data subject if it reveals the data subject’s identity directly; if it can be manipulated to identify the data subject indirectly; or if it can be linked to other data which would in turn identify the data subject.

     

    “Essentially, the de-identifying of the data is a cornerstone of PoPIA. This act is directly purposed to protect personal information. Therefore, it is imperative that organisations are aware of identifying data and that they take the necessary steps to make that data anonymous by hiding or removing it,” explains Carrie Peter, Solution Owner at Impression Signatures.

     

    When organisations are working with data that is essential to provide the necessary service or business operation, any identifying data that is not required must be de-identified - and the data set must be completely de-identified before it is shared. “An example of this is an online order. Initially the customer’s name and address may be required for delivery, however once the delivery has been made that identifying data is not required for stocktake records. The data should therefore be de-identified before sharing the stock numbers,” continues Peter.

     

    Another key area of compliance is related to the use of an information matching programme. This programme is designed to collect, compare, clean, and organise sets of information. Two sets of information are matched and compared. This comparison can be done either manually or digitally and includes documents that hold personal information about ten or more data subjects.

     

    “When utilising these programmes it is imperative that consent is obtained for any and all information utilised and stored by an organisation. This consent needed extends to older data sets that are stored within the organisations filing systems and so on. This means that organisations need to track down, match, clean and sanitise their historical data sets to ensure that the data is consolidated and secured. Consent for new and historical data must be explicitly secured for each piece of data, for the exact reason that, that data is required,” adds Peter.

     

    The third crucial area to be addressed is that of filing systems. Filing systems refer to any set of personal data records stored by an organisation. These records could be manually stored in a filing cabinet, or digitally stored, centralised, decentralised, or dispersed on a functional or geographical basis. This data can be accessed with specific search criteria, such as being searched alphabetically. For compliance, these records must be safely secured to avoid them being lost, stolen, or misused. This can be achieved through restricting access to digital storage using a filing cabinet that can be locked. Access to these records should only be granted to those who have obtained the necessary consent from the data subject(s).

     

    “All three of these areas are crucial when it comes to compliance to PoPIA. Once understood, compliance in these areas is easily managed,” concludes Peter.  

     

    Issued by Perfect Word Consulting (Pty) Ltd

    For more information, contact perfectword@trinitas.co.za

     

    - ENDS -

     

    Boilerplates:

     

    About Impression Signatures

    Founded in 2011, Impression Signatures (an iOCO company) is the leading provider of e-signature solutions in South Africa. Our patented approach is locally created whilst committing to making this innovative technology available to the public enabling true social inclusion to fully realize digital transformation in South Africa. For more information, visit www.impression-signatures.com.

     

    About iOCO

    Established to simplify ICT, iOCO is Africa’s leading integrated technology services company, with the largest concentration of skills on the continent. As a Level 1 B-BBEE end-to-end ICT managed service provider and Cloud systems integrator, iOCO operates with over 20 years’ experience. Its team of more than 4500 specialists delivers Open Digital Integrator, Enterprise Applications, Data and Analytics, Compute and Platforms, and Manage and Operate solutions to over 1 000 customers.

    Inspired by digitally native internet organisations (iO) and creative organisations (CO) of the future, iOCO helps customers navigate the path to an exponential future. To achieve this vision, iOCO holds strategic OEM partnership agreements with more than 90 global leaders.

    The fourth industrial revolution brings not only exponential opportunity, but exponential challenges too. The key to succeeding in this two-speed world is finding a digital journey partner that has the expertise needed to drive unprecedented growth. iOCO offers modern solutions that meet the demands of the cloud economy and 4IR.

    For more information, please visit: www.ioco.tech.