Skip introduction and take me to checklist
POPIA: An introduction
What is POPIA?
The Protection of Personal Information Act (POPIA) is South Africa’s data privacy law that empowers citizens with enforceable rights over their personal information, requires websites, companies and organizations to live up to minimum conditions for lawful processing, and establishes the Information Regulator to supervise and enforce compliance with POPIA.
What is personal data under POPIA?
POPIA has a very broad definition of personal information, basically any kind of information relating to an identifiable, living natural person, company or similar legal entity, including but not limited to –
- names, addresses, telephone numbers, email addresses,
- information about age, race, gender, appearance, characteristics, sexual orientation, political convictions, religious beliefs, language,
- health data such as physical or mental health, well-being, disabilities,
- online identifiers such email addresses, IP addresses, cookies, unique IDs, search and browser history, location data.
POPIA’s broad personal information definition covers activities that happen on most websites in the world, such as first- and third-party cookies collecting IP addresses, search and browser history, trackers setting unique IDs and more.
Who is required to comply with POPIA?
If your website processes personal information from inside South Africa, e.g. through the use of cookies and similar trackers, you must comply with POPIA.
How to be compliant with South-African law?
Compliance with POPIA means asking for and obtaining the prior consent of end-users before any processing of their personal information. Compliance also means meeting several minimum requirements for lawful processing, such as documentation, security and confidentiality and ensuring that end-users can exercise their right to access, correct and have deleted already collected data.
Want to know more about POPIA?
Check out our blog post: South Africa’s Protection of Personal Information Act
POPIA: A Cookiebot checklist
This guide is focusing solely on providing the tools needed to make your website’s use of cookies and online tracking compliant with POPIA. Other aspects of POPIA are therefore not covered or addressed in the checklist.
The checklist is not intended as legal advice - if in doubt, seek advice from a trusted legal source or your Data Protection Authority.
Step 1: Add your domain
- Log into the Cookiebot Manager and navigate to the Domains tab.
- Enter the domain name (excluding https://-part, for example: domain.com)
Step 2: Configure your banner type
- Navigate to the "Dialog" pane
- Make sure you selected "explicit consent" under "Method"*
- Select your banner type - note that POPIA states that an opt-in button is required and that the user needs the right to opt-in on a purpose level. In order to do so, you can select the "Multilevel" or "Inline multilevel" banner type.
- Select your buttons - note that POPIA states that an opt-in button is required, so each of our 3 button setups work in this case (as they all include an "allow all" option).
- Do not pre-check the category boxes.*
*According to Section 1 of POPIA consent is any voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information. This means that consent can not be implied, it requires an actual action of the data subject.
Geo location settings (optional)
If you wish to only display a banner to visitors in South-Africa, you can do so by configuring "geotargeting" at the bottom of the page:
Step 3: Configure your widget
You have to provide the user the option to withdraw their consent, based on Section 11 of POPIA. This means that after they have given their consent, the users must have the option to withdraw the consent at any point. You can simply enable the widget on your website and have this option easily and visibly available for your users at all time: The Cookiebot CMP widget.
Step 4: Configure your Cookie Declaration
Section 18 of POPIA mentions the requirements to inform the data subjects and all the information which need to be provided in the privacy policy. You can easily use the cookie declaration script we provide for this purpose and add it under your own website's Privacy Policy. The script for it can be found on the tab ‘Your scripts’ (it’s the second of the 2 scripts). For more information: What is included in the Cookie Policy.
Step 5: Get your scripts
- Navigate to the "Your scripts" pane
- Choose the correct blocking mode you want to use: automatic cookie blocking or manual cookie blocking.*
- Follow the instructions to insert your banner and cookie declaration on your website.
If you intend to implement Cookiebot CMP by other means than manually adding the script(s) to your template, please refer to our implementation section in the Help Center.
*According to Section 11, data can only be processed if the data subject has given their consent. This means that cookies and other trackers, which do not fall under legitimate interest, need to be blocked.
Sources:
Comments
0 comments
Article is closed for comments.