Enforcement of Popia Increases, but a Major Loophole Remains
You can also enjoy this podcast on iono.fm here.
JEREMY MAGGS: It appears that Popia [Protection of Personal Information Act] is entering a significantly stricter phase. The Information Regulator has levied R5 million fines against both the Justice and Basic Education departments, while highlighting that the frequency of data breaches in South Africa has reached an alarming level.
However, with major fines still contested in court, the question arises: is the enforcement truly altering behavior, or is it merely creating more headlines?
We are now joined by Advocate Pansy Tlakula, the chair of the Information Regulator of South Africa. Advocate, a warm welcome to you. Has Popia finally gained real authority, or are these fines largely symbolic?
PANSY TLAKULA: Popia has always had authority. The issue we face is that it provides private and public entities that breach it a grace period to comply. It is only once they fail to do so, or if they challenge our enforcement notice in court, that we can move forward with imposing fines.
Read: Third-party cyber risks emerge as weak link for banks following data breach issues.
This grace period poses a challenge for us. If we look at our global counterparts, once legislation has been breached or violated, they immediately enforce fines that must be paid.
So, that grace period is quite problematic for our situation.
ADVERTISEMENT
CONTINUE READING BELOW
JEREMY MAGGS: If this is a concern and government departments are challenging the regulator, does this not undermine your authority?
PANSY TLAKULA: Not necessarily, as there are two outcomes. One outcome is that after we conduct an investigation and issue an enforcement notice, there is compliance, which is positive.
On the other hand, some entities choose to challenge us in court rather than comply, which is their right.
However, we are considering amendments to Popia to eliminate that grace period.
Now that the legislation is enforced, the powers of the regulator have been effective since 2021.
What concerns us is that the SAPS (South African Police Service), which I can mention, was investigated for breaching Popia, we issued an enforcement notice, and they complied fully. Yet, a year later, they violated Popia again in the same way as before.
This indicates compliance followed by further violations, reinforcing our belief that the grace period needs to be abolished.
JEREMY MAGGS: Advocate, on a broader scale, I understand you have received over 8,000 data breach reports. Are breaches becoming more frequent, or are organizations simply reporting them more transparently?
PANSY TLAKULA: To clarify, the 8,000 figure represents cases since our enforcement powers began. In this financial year alone, we’ve seen nearly 1,700 reports, and the fiscal year has just begun five months ago. This suggests we could receive around 3,000 reports by year’s end.
I believe this is due to two primary reasons.
We’ve streamlined the notification process to be electronic for both public and private entities, but concurrently, there is a noticeable uptick in data breaches across the country.
ADVERTISEMENT:
CONTINUE READING BELOW
Read: Health data breaches loom as employers overlook new Popia regulations.
It is challenging to determine if we are investing sufficient resources into assisting public and private bodies, particularly in the public sector, to ensure robust security measures are implemented for personal information.
We find this to be problematic.
Additionally, we have to acknowledge that hackers are becoming increasingly sophisticated. Even organizations with advanced security measures in the private sector, like Standard Bank, have experienced major data breaches.
JEREMY MAGGS: That said, I want to highlight the public sector. It suggests they may be doing less than the private sector to safeguard information. Doesn’t that raise questions about why citizens should trust the government with their personal data when there are evident weaknesses?
PANSY TLAKULA: Indeed, that is a valid concern. The rationale is quite straightforward: for the private sector, a data breach carries significant ramifications for the business, including reputational damage and potential impacts on profitability.
In contrast, these considerations do not necessarily apply to government.
Government must enhance its efforts not only by allocating more resources to mitigate data breaches but also by fully implementing Popia and adopting privacy by default.
I emphasize this because we observe instances where laws are amended and systems developed without compliance to Popia.
There’s a lack of assurance that privacy by design is considered within the public sector when any new law or regulation is introduced or a system is created.
ADVERTISEMENT:
CONTINUE READING BELOW
Read: SA’s digital ID: Progress or privacy nightmare?
For example, I would have hoped that before any digital ID is piloted, the government would consult with us about the Popia implications of the proposed initiative.
However, that is not typically the case. We often need to raise our hands and say, ‘We are here. Popia is applicable; can we verify if what we are doing complies?’
JEREMY MAGGS: Finally, Advocate, how do you determine the appropriate fines for breaches? What differentiates a R100,000 breach from a R5 million breach?
PANSY TLAKULA: We use clearly defined criteria under Popia to assess each situation, considering factors such as the number of individuals affected, the severity of the breach, and its overall impact.
For instance, with the DoJ (Department of Justice) data breach, it nearly paralyzed the entire justice system because the system was encrypted and rendered inoperable.
Read:
SA’s government departments are sitting ducks for cyberattacks
State spends billions, IT systems still failing
It disrupted court operations, maintenance, and even affected our organization, as we relied on the Department of Justice’s systems at the time.
JEREMY MAGGS: Thank you very much, Advocate Pansy Tlakula. You are the chair of the Information Regulator of South Africa, and we appreciate your time.
