
Section 14 of the Constitution of the Republic of South Africa, 1996, provides that “everyone has the right to privacy”. The right to privacy includes a right to protection against the unlawful collection, retention, dissemination and use of personal information. The State has a duty to respect, protect, promote and fulfil the rights in the Bill of Rights. Hence the development and enactment of the Protection of Personal Information Act (POPIA) with the primary purpose of protecting the rights of data subjects. Compliance with POPIA means fulfilling the rights of data subjects.
POPIA provides the following rights for data subjects:
- The right to processing in accordance with the conditions, including:
- accountability for non-compliance
- lawfulness of the processing
- reasonable manner that does not infringe the privacy of the data subject
- given the purpose for which personal information is processed, it is adequate, relevant and not excessive
- valid legal basis
- collected directly from the data subject, except as otherwise provided for
- collected for a specific, explicitly defined and lawful purpose
- data subject is aware of the purpose of the collection of the information
- records of personal information are not be retained any longer than is necessary for achieving the purpose for which the information was collected
- further processing of personal information must be in accordance or compatible with the purpose for which it was collected
- taking reasonably practicable steps to ensure that the personal information is complete, accurate, not misleading and updated
- maintain the documentation of all processing operations under its responsibility
- secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures
- provide sufficient information to allow the data subject to take protective measures against the potential consequences of a compromise
- notified of the action taken as a result of a data subject request
- The right to be notified that personal information has been collected (i.e. transparency)
- The right to be notified of unauthorised access to personal information
- The right to establish whether a responsible party holds personal information
- The right of access to a record or request a description of the personal information about the data subject held by the responsible party
- The right to request information about the identity of all third parties, or categories of third parties, who have, or have had, access to the personal information of the data subject
- The right to receive the requested information in a reasonable manner and format, and in a form that is generally understandable.
- The right to correction
- The right to destruction or deletion (erasure)
- The right to object to processing
- The right to object to direct marketing
- The right to restrict processing
- The right to data transfer (portability)
- The right to assurance
- Rights in relation to automated decision making and profiling
- The right to submit a complaint to the regulator
- The right to institute civil proceedings.