了解南非机构对个人信息保护(POPI)法案的遵守程度

Prittish Dala, H. Venter
{"title":"了解南非机构对个人信息保护(POPI)法案的遵守程度","authors":"Prittish Dala, H. Venter","doi":"10.1145/2987491.2987506","DOIUrl":null,"url":null,"abstract":"Privacy entails controlling the use and access to place, location and personal information. In South Africa, the first privacy legislation in the form of the Protection of Personal Information (POPI) Act was signed into law on 26 November 2013. The POPI Act promotes the protection of personal information by South African public and private institutions and specifies the minimum requirements in twelve chapters, which includes eight conditions for lawful processing of personal information. In 2012, CIBECS as part of their State of Business Data Protection in South Africa survey assessed, amongst other aspects, how prepared South African institutions were to comply with the then forthcoming protection of personal information legislation. Since that survey, the POPI Bill progressed to an Act and, more recently, in 2015 processes commenced to appoint the Information Regulator (in terms of the legislation), who would be responsible for enforcing the POPI Act. Due to the aforementioned developments and looming enforcement date associated with the POPI Act, this paper assesses the level of understanding of the POPI Act by participants from South African institutions as well as the current level of compliance to the POPI Act. Specifically, the current level of compliance to Condition Seven of the POPI Act, relating to the confidentiality and integrity of electronic personal information, is explored. Furthermore, a view is provided of the financial value associated with electronic personal information maintained as well as the potential impact a data breach of electronic personal information may have on an institution.","PeriodicalId":269578,"journal":{"name":"Research Conference of the South African Institute of Computer Scientists and Information Technologists","volume":"185 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-09-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Understanding the Level of Compliance by South African Institutions to the Protection of Personal Information (POPI) Act\",\"authors\":\"Prittish Dala, H. Venter\",\"doi\":\"10.1145/2987491.2987506\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Privacy entails controlling the use and access to place, location and personal information. In South Africa, the first privacy legislation in the form of the Protection of Personal Information (POPI) Act was signed into law on 26 November 2013. The POPI Act promotes the protection of personal information by South African public and private institutions and specifies the minimum requirements in twelve chapters, which includes eight conditions for lawful processing of personal information. In 2012, CIBECS as part of their State of Business Data Protection in South Africa survey assessed, amongst other aspects, how prepared South African institutions were to comply with the then forthcoming protection of personal information legislation. Since that survey, the POPI Bill progressed to an Act and, more recently, in 2015 processes commenced to appoint the Information Regulator (in terms of the legislation), who would be responsible for enforcing the POPI Act. Due to the aforementioned developments and looming enforcement date associated with the POPI Act, this paper assesses the level of understanding of the POPI Act by participants from South African institutions as well as the current level of compliance to the POPI Act. Specifically, the current level of compliance to Condition Seven of the POPI Act, relating to the confidentiality and integrity of electronic personal information, is explored. Furthermore, a view is provided of the financial value associated with electronic personal information maintained as well as the potential impact a data breach of electronic personal information may have on an institution.\",\"PeriodicalId\":269578,\"journal\":{\"name\":\"Research Conference of the South African Institute of Computer Scientists and Information Technologists\",\"volume\":\"185 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-09-26\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Research Conference of the South African Institute of Computer Scientists and Information Technologists\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/2987491.2987506\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Research Conference of the South African Institute of Computer Scientists and Information Technologists","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2987491.2987506","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

隐私需要控制对地点、位置和个人信息的使用和访问。2013年11月26日,南非首部隐私立法《个人信息保护法》签署成为法律。POPI法案促进了南非公共和私人机构对个人信息的保护,并在12章中规定了最低要求,其中包括合法处理个人信息的8个条件。2012年,CIBECS作为其南非商业数据保护状况调查的一部分,评估了南非机构在遵守当时即将出台的个人信息保护立法方面的准备情况。自那次调查以来,POPI法案发展成为一项法案,最近,在2015年开始任命信息监管机构(就立法而言),负责执行POPI法案。鉴于上述与POPI法案相关的发展和迫在眉睫的执行日期,本文评估了来自南非机构的参与者对POPI法案的理解程度以及目前对POPI法案的遵守程度。具体来说,目前的水平符合条件七的POPI法案,有关电子个人信息的保密性和完整性,进行了探讨。此外,本文还阐述了与电子个人信息相关的财务价值,以及电子个人信息数据泄露可能对机构造成的潜在影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Understanding the Level of Compliance by South African Institutions to the Protection of Personal Information (POPI) Act
Privacy entails controlling the use and access to place, location and personal information. In South Africa, the first privacy legislation in the form of the Protection of Personal Information (POPI) Act was signed into law on 26 November 2013. The POPI Act promotes the protection of personal information by South African public and private institutions and specifies the minimum requirements in twelve chapters, which includes eight conditions for lawful processing of personal information. In 2012, CIBECS as part of their State of Business Data Protection in South Africa survey assessed, amongst other aspects, how prepared South African institutions were to comply with the then forthcoming protection of personal information legislation. Since that survey, the POPI Bill progressed to an Act and, more recently, in 2015 processes commenced to appoint the Information Regulator (in terms of the legislation), who would be responsible for enforcing the POPI Act. Due to the aforementioned developments and looming enforcement date associated with the POPI Act, this paper assesses the level of understanding of the POPI Act by participants from South African institutions as well as the current level of compliance to the POPI Act. Specifically, the current level of compliance to Condition Seven of the POPI Act, relating to the confidentiality and integrity of electronic personal information, is explored. Furthermore, a view is provided of the financial value associated with electronic personal information maintained as well as the potential impact a data breach of electronic personal information may have on an institution.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信