Comply with POPI Act – Step 1
Step 1 of compliance with POPI act is to register the Manager or owner of your business as an “Information Officer”.
POPIA requires every responsible party (i.e. a public or private body that determines the purpose of, and means for the processing of, personal information) to appoint and register an information officer with the Information Regulator.
Firstly, everybody has to comply with POPI, any business of any size. So what is an Information Officer? It is the person responsible for compliance of the POPI act in the business. Certain documents and strategies and training will be required for compliance which will be discussed in weeks to follow. Below is an article to give an indication of what will be required and what will be the responsibility of this person.
Policies, Guidance Notes and Notices
- Notice in terms of Section 61(2) of the Protection of Personal Information Act No 4 of 2013 (POPIA): Credit Bureau Association (CBA), Code of Conduct: Lawful Processing of Personal Information in credit Sector, 14 Apr 2021
In terms of the provisions of section 61 (2) of POPIA, the Information Regulator (South Africa) gives notice that the Regulator is in receipt of a Code of Conduct from the Credit Bureau Association (CBA) that deals with how personal information will be processed in the credit sector. Affected persons are invited to submit written comments to the Regulator (email address: Codes.IR@justice.gov.za) till the 30 April 2021. A notice will be published in the Government Gazette in compliance with Section 61(2) of POPIA on the 23 April 2021. - Guidance Note on Information Officers and Deputy Information Officers, 01 Apr 2021
The purpose of this Guidance Note is to provide guidance and procedures for the obligations and liabilities of Information Officers and Deputy Information Officers, registration of Information Officers with the Information Regulator, updating the details of Information Officers, designation of Deputy Information Officers and delegation of duties and responsibilities of the Information Officers to the Deputy Information Officers. - Guidance Note on applications for Prior Authorisation, 11 Mar 2021
This Guidance Note is issued to guide responsible parties who are currently processing or intend to process personal information which is subject to prior authorisation to ensure compliance with the relevant provisions of the Protection of Personal Information Act 4 of 2013 (POPIA).- Invitation for applications for Prior Authorisation, 11 Mar 2021
Responsible parties may submit their applications for prior authorisation by completing the Application Form for Prior Authorisation on applications for prior authorisation .
- Invitation for applications for Prior Authorisation, 11 Mar 2021
Registration of your POPIA Information Officer (1 May 2021)

By Priyanka Naidoo on March 25, 2021Posted in General
On 18 March 2021, the Information Regulator announced on Twitter that:
- the registration of information officers will commence on 1 May 2021;
- the Draft Guidelines will be finalised once all public comments are taken into consideration; and
- registration will be an on-going process to enable new entities to register and for existing one to update their details.
In our recent engagement with the Information Regulator, its office indicated that a notice inviting responsible parties to submit their applications for registration of information officer and deputy information officer will be published on the Information Regulator’s website and social media as soon as possible. It is expected that the precise mechanism and form of registration will be communicated through those notices.
What happens from 1 May 2021?
Under the Protection of Personal Information Act, 2013 (POPIA) and the Promotion of Access to Information Act, 2000 (PAIA), an information officer must perform duties and responsibilities as prescribed under POPIA and PAIA.
POPIA Regulation 4, which prescribes some of these duties and responsibilities, will take effect on 1 May 2021 but only be enforced from 1 July 2021. These duties include ensuring that:
- a compliance framework is developed, implemented, monitored and maintained;
- personal information impact assessments are done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information;
- a manual is developed, monitored, maintained and made available as prescribed in sections 14 and 51 of PAIA;
- internal measures are developed together with adequate systems to process requests for information or access thereto; and
- internal awareness sessions are conducted regarding the provisions of POPIA, regulations made in terms of POPIA, codes of conduct, or information obtained from the Information Regulator.
Given that compliance with POPIA will only be enforceable from 1 July 2021, some of these duties and responsibilities practically cannot be performed, for example monitoring a compliance framework. As these duties and responsibilities involve a number of measures being implemented to ensure compliance with POPIA, it is recommended that companies start now getting ready for POPIA compliance by 1 July 2021.
Online registration form for Information Officers:


