-
Quick Access
-
POPIA
-
-
-
- Section 26 Prohibition on processing of special personal information
- Section 27 General authorisation concerning special personal information
- Section 28 Authorisation concerning data subject’s religious or philosophical beliefs
- Section 29 Authorisation concerning data subject’s race or ethnic origin
- Section 30 Authorisation concerning data subject’s trade union membership
- Section 31 Authorisation concerning data subject’s political persuasion
- Section 32 Authorisation concerning data subject’s health or sex life
- Section 33 Authorisation concerning data subject’s criminal behaviour or biometric information
-
-
-
- Section 39 Establishment of Information Regulator
- Section 40 Powers, duties and functions of Regulator
- Section 41 Appointment, term of office and removal of members of Regulator
- Section 42 Vacancies
- Section 43 Powers, duties and functions of Chairperson and other members
- Section 44 Regulator to have regard to certain matters
- Section 45 Conflict of interest
- Section 46 Remuneration, allowances, benefits and privileges of members
- Section 47 Staff
- Section 48 Powers, duties and functions of chief executive officer
- Section 49 Committees of Regulator
- Section 50 Establishment of Enforcement Committee
- Section 51 Meetings of Regulator
- Section 52 Funds
- Section 53 Protection of Regulator
- Section 54 Duty of confidentiality
- Show all articles ( 1 ) Collapse Articles
-
-
- Section 60 Issuing of codes of conduct
- Section 61 Process for issuing codes of conduct
- Section 62 Notification, availability and commencement of code of conduct
- Section 63 Procedure for dealing with complaints
- Section 64 Amendment and revocation of codes of conduct
- Section 65 Guidelines about codes of conduct
- Section 66 Register of approved codes of conduct
- Section 67 Review of operation of approved code of conduct
- Section 68 Effect of failure to comply with code of conduct
-
- Section 73 Interference with protection of personal information of data subject
- Section 74 Complaints
- Section 75 Mode of complaints to Regulator
- Section 76 Action on receipt of complaint
- Section 77 Regulator may decide to take no action on complaint
- Section 78 Referral of complaint to regulatory body
- Section 79 Pre-investigation proceedings of Regulator
- Section 80 Settlement of complaints
- Section 81 Investigation proceedings of Regulator
- Section 82 Issue of warrants
- Section 83 Requirements for issuing of warrant
- Section 84 Execution of warrants
- Section 85 Matters exempt from search and seizure
- Section 86 Communication between legal adviser and client exempt
- Section 87 Objection to search and seizure
- Section 88 Return of warrants
- Section 89 Assessment
- Section 90 Information notice
- Section 91 Parties to be informed of result of assessment
- Section 92 Matters referred to Enforcement Committee
- Section 93 Functions of Enforcement Committee
- Section 94 Parties to be informed of developments during and result of investigation
- Section 95 Enforcement notice
- Section 96 Cancellation of enforcement notice
- Section 97 Right of appeal
- Section 98 Consideration of appeal
- Section 99 Civil remedies
- Show all articles ( 12 ) Collapse Articles
-
- Section 100 Obstruction of Regulator
- Section 101 Breach of confidentiality
- Section 102 Obstruction of execution of warrant
- Section 103 Failure to comply with enforcement or information notices
- Section 104 Offences by witnesses
- Section 105 Unlawful acts by responsible party in connection with account number
- Section 106 Unlawful acts by third parties in connection with account number
- Section 107 Penalties
- Section 108 Magistrate’s Court jurisdiction to impose penalties
- Section 109 Administrative fines
-
PAIA
-
Print
Section 14 Retention and restriction of records
- Subject to subsections (2) and (3), records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed, unless—
- retention of the record is required or authorised by law;
- the responsible party reasonably requires the record for lawful purposes related to its functions or activities;
- retention of the record is required by a contract between the parties thereto; or
- the data subject or a competent person where the data subject is a child has consented to the retention of the record.
- Records of personal information may be retained for periods in excess of those contemplated in subsection (1) for historical, statistical or research purposes if the responsible party has established appropriate safeguards against the records being used for any other purposes.
- A responsible party that has used a record of personal information of a data subject to make a decision about the data subject, must—
- retain the record for such period as may be required or prescribed by law or a code of conduct; or
- if there is no law or code of conduct prescribing a retention period, retain the record for a period which will afford the data subject a reasonable opportunity, taking all considerations relating to the use of the personal information into account, to request access to the record.
- A responsible party must destroy or delete a record of personal information or de-identify it as soon as reasonably practicable after the responsible party is no longer authorised to retain the record in terms of subsection (1) or (2).
- The destruction or deletion of a record of personal information in terms of subsection (4) must be done in a manner that prevents its reconstruction in an intelligible form.
- The responsible party must restrict processing of personal information if—
- its accuracy is contested by the data subject, for a period enabling the responsible party to verify the accuracy of the information;
- the responsible party no longer needs the personal information for achieving the purpose for which the information was collected or subsequently processed, but it has to be maintained for purposes of proof;
- the processing is unlawful and the data subject opposes its destruction or deletion and requests the restriction of its use instead; or
- the data subject requests to transmit the personal data into another automated processing system.
- Personal information referred to in subsection (6) may, with the exception of storage, only be processed for purposes of proof, or with the data subject’s consent, or with the consent of a competent person in respect of a child, or for the protection of the rights of another natural or legal person or if such processing is in the public interest.
- Where processing of personal information is restricted pursuant to subsection (6), the responsible party must inform the data subject before lifting the restriction on processing.