If your company has customers in South Africa and you collect or process personal information, you need to comply with the Protection of Personal Information Act (POPIA). Configure POPIA.
Understanding POPIA
What is POPIA?
POPIA is South Africa’s primary data privacy law, governing how personal information is processed. It was signed into law in 2013, came into full effect in July 2020, and enforcement began in July 2021.
POPIA sets out eight conditions for the lawful processing of personal information – accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation – and grants data subjects enforceable rights over their own personal information. It is enforced by the Information Regulator of South Africa.
What is personal information under POPIA?
POPIA defines personal information as information relating to an identifiable, living natural person and – unusually among data privacy laws – to an identifiable, existing juristic person such as a company.
This includes anything from names, contact details, identity numbers and location data to information on race, gender, health, biometrics, beliefs and personal opinions, as well as online identifiers such as IP (Internet Protocol) addresses, cookies, browser and search history. POPIA also defines a category of "special personal information" – including religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information and criminal behaviour – which may only be processed under specific conditions.
Who is required to comply with POPIA?
POPIA applies to any "responsible party" – the party that determines the purpose of and means for processing personal information – that is domiciled in South Africa. It also applies to responsible parties that are not domiciled in South Africa but make use of automated or non-automated means located in the Republic, unless those means are used only to forward the information through South Africa.
In practice, this means that websites and organizations outside South Africa that place cookies and trackers on the devices of users inside South Africa will typically be required to comply with POPIA.
How can my website become compliant with POPIA?
Your website must have a lawful basis for processing personal information from individuals inside South Africa, and may only process it for a specific, explicitly defined and legitimate purpose that has been clearly communicated to the data subject.
Where you rely on consent, POPIA requires it to be a voluntary, specific and informed expression of will – so you might need to ask for and obtain the clear and unambiguous consent of your users before legally being allowed to process any personal information, e.g. through cookies and trackers in operation on your website. Data subjects may object to processing or withdraw their consent at any time, and you must be able to demonstrate that valid consent was obtained.
Our solution simplifies these requirements for you by allowing you to easily manage consent and log proof of consent for each of your website users.
Want to know more about POPIA?
Check out our blog post: South Africa’s Protection of Personal Information Act (POPIA): an overview
Configure your CMP for POPIA
This guide focuses solely on the tools needed to make your website's use of cookies and online tracking compliant with POPIA. It doesn't cover other aspects of POPIA compliance.
These steps aren't intended as legal advice — if you're in doubt, seek advice from a trusted legal source or your data protection authority.
Setting up your CMP for POPIA compliance is straightforward — it's ready to use out of the box. Follow these steps to configure it.
First time set up
If you are setting up Cookiebot for the first time, you can select the POPIA preset. This will automatically configure the banner to comply with POPIA. You can still make some changes to suit your needs though.
Adding POPIA as an additional legislation
If you already have a CMP set up for another region, add POPIA as a separate domain group so the two configurations don't conflict.
Follow the following steps to create the additional domain group.
-
Add a new domain group.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
-
If you already have multiple domain groups: click "Manage" at the top of the domain group section in the left-hand menu.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
-
Click the "+ Create group" button
- Name the new group "POPIA" and click "Create group." You'll see it added to your list of domain groups.
-
Click the "Configure CMP" icon next to your new POPIA group to open its settings.
-
Click "Legislation presets" on the right side of the screen and select the POPIA preset.
- Click "Save changes." Your POPIA domain group is now active and ready to use.
Comments
0 comments
Please sign in to leave a comment.