Facebook Twitter LinkedIn RSS
    Trending
    • SEC proposes N1m Limit for retail digital asset investments
    • MTN’s acquisition of IHS gets FCCPC greenlight
    • TransmissionCo appoints Princess Chizoba-Israel as Head of Sales for West Africa
    • 50% of financial crime comes from tax and fraud – NFIU report
    • Sara Pinheiro gets Mota-Engil Nigeria appointment as head of treasury
    • The Government’s Crypto Problem, By Mela Claude Ake
    • ALTON and IXPN lead support for eWorld forum and Ukodie Book Launch
    • Rollout of 90,000km nationwide fibre-optic network begins October
    Facebook Twitter LinkedIn
    ITPulse.com.ngITPulse.com.ng
    • News
    • Interviews
    • Blogs
    • Analysis
    • Opinion
    • Videos
    • Press Releases
    • Pictures
    • Advertise
    ITPulse.com.ngITPulse.com.ng
    Home»Opinion»Why data protection must become part of an organisation’s culture, By Imraan Kharwa
    Opinion 4 Mins Read

    Why data protection must become part of an organisation’s culture, By Imraan Kharwa

    mmBy ITPulseJuly 27, 2022
    Facebook Twitter WhatsApp Pinterest LinkedIn Reddit Tumblr Email
    Imraan Kharwa
    Imraan Kharwa
    Share
    Facebook Twitter LinkedIn Pinterest Email

    For years the privacy sword of Damocles hung precariously over South African businesses, threatening severe consequences and penalties for non-compliance with the Protection of Personal Information Act, 2013 (“POPIA”). Now, nearly a year since it was activated in July 2021, organisations are settling into the reality of conducting business in alignment with its regulations and data protection best practices. While many organisations have placed compliance at the core of operations, there has sadly been a surge in data breaches impacting South African businesses in the same period, creating a climate that is ripe for POPIA enforcement.

    The first anniversary of POPIA

    POPIA governs the processing of personal information of individuals and juristic entities (“Data Subjects”) by organisations (“Responsible Parties”) in South Africa. regulates the processing of personal information of individuals by organisations from collection, aggregation and usage all the way through to retention and destruction.

    Encouragingly, the Information Regulator, empowered to monitor and enforce compliance with the provisions of POPIA, has been active in engaging with organisations that have experienced data breaches over the past 12 to 18 months. The added scrutiny means organisations must be far more cognisant of how they process personal information, ensuring that their security controls are adequate and effective.

    Gateway to the international arena

    While compliance has historically been viewed as an administrative burden, many organisations now realise that privacy enablement is no longer a ‘nice to have but a valuable necessity of being able to do business. In tandem, technology companies are ensuring privacy forms a key part of their offerings.

    The role of the Information Officer

    The mandatory appointment of an Information Officer in all organisations remains one of the more contentious aspects of POPIA. Without clear guidance on where this role needs to be positioned, organisations have adopted differing approaches. In practical terms, this is often driven by the size of the organisation, the resources at its disposal and the level of maturity of its data protection programme.

    Whereas smaller organisations are likely to appoint a multitasker, where the role of Information Officer will be added to the existing headcount in the business, larger  organisations are more likely to hire a full-time candidate who will be dedicated to the role and oversee a discrete data protection function.

    A seat in the boardroom

    As more organisations begin to recognise the impact of data protection, both fiscally and reputationally, –privacy has become a business imperative requiring executive input. This often becomes the preserve of Chief Information Officers, but there is an increased focus on appointing experienced Chief Privacy Officers with specialised skills in ensuring POPIA protocols are followed.

    Attention to third parties

    One of the biggest challenges for local organisations is the lack of attention to privacy risks associated with third parties. As operators in the POPIA relationship, they must also play their part in preventing security compromises. It is therefore imperative to consider the reputation of the third party, the maturity of their privacy programme and whether they employ suitably qualified and certified privacy and security personnel to oversee their operations.

    A final, overarching component of the compliance journey is ensuring that awareness of data protection obligations and privacy rights permeates all levels of the organisation through regular privacy training. Privacy training must be regularly conducted, departmental based and appropriate to the organisation. The adage “privacy is everyone’s responsibility” holds true, which is why organisations must improve accessibility to data privacy practices and ensure all employees are cognisant of the privacy regimes within their organisation. Data protection must become part of the living culture of all organisations.

    Imraan Kharwa, Data protection officer at Infobip

    data protection Imraan Kharwa Infobip Nigeria
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    mm
    ITPulse
    • Website
    • Facebook
    • Twitter
    • LinkedIn

    ITPulse is a wholly information technology communication (ICT) news website, with a special focus on the African continent. The website provides up-to-date biz-tech news, analysis and comprehensive and thorough insight into the continent's ICT terrain

    Related Posts

    The Government’s Crypto Problem, By Mela Claude Ake

    August 22, 2026

    Five practical holiday saving habits for Nigerian households 

    August 19, 2026

    Formidable is not about size: Why structure is the secret to scaling Nigerian businesses 

    August 17, 2026

    Leave A Reply Cancel Reply

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Latest Posts

    SEC proposes N1m Limit for retail digital asset investments

    August 24, 2026

    MTN’s acquisition of IHS gets FCCPC greenlight

    August 24, 2026

    TransmissionCo appoints Princess Chizoba-Israel as Head of Sales for West Africa

    August 24, 2026
    About
    About

    Itpulse.com.ng is a wholly information technology communication (ICT) news website, with special focus on the African continent. The website provides up-to-date biz-tech news, analysis and a comprehensive and thorough insight info the continent's ICT terrain.

    Contact us: editorial@itpulse.com.ng

    Facebook Twitter LinkedIn RSS
    Latest Posts

    SEC proposes N1m Limit for retail digital asset investments

    August 24, 2026

    MTN’s acquisition of IHS gets FCCPC greenlight

    August 24, 2026

    TransmissionCo appoints Princess Chizoba-Israel as Head of Sales for West Africa

    August 24, 2026
    Popular Posts

    Sara Pinheiro gets Mota-Engil Nigeria appointment as head of treasury

    August 22, 2026

    TransmissionCo appoints Princess Chizoba-Israel as Head of Sales for West Africa

    August 24, 2026

    PalmPay expands opportunities for Nigerians to earn more

    August 20, 2026
    © 2017 - 2026 Itpulse.
    • Terms & Conditions
    • Privacy Policy
    • Advertise
    • Contact Us

    Type above and press Enter to search. Press Esc to cancel.