Conducting a Personal Information Impact Assessment under POPIA

A practical overview of the PIIA process, its stages, and why it is essential for responsible parties

The Protection of Personal Information Act No. 4 of 2013 (POPIA), which took effect on 1 July 2020, provides a comprehensive legal framework for protecting personal information in South Africa. It gives effect to the constitutional right to privacy by regulating how personal information is processed by both public and private bodies (with limited exceptions). Under POPIA, personal information refers to any data relating to an identifiable living natural person or an existing juristic person (such as a company). Responsible parties are obligated to comply with the Act's conditions for lawful processing and to enable data subjects to exercise their rights, including rights to access, rectification, and objection.

POPIA requires responsible parties to implement reasonable technical and organisational measures to safeguard the integrity and confidentiality of personal information, thereby preventing its loss, damage, unauthorised destruction, or unlawful access and processing. These measures must involve:

This approach must align with generally accepted information security practices and any relevant industry-specific regulations. Additionally, responsible parties must ensure that personal information remains complete, accurate, not misleading, and updated where necessary.

A key compliance mechanism under Regulation 4(1)(b) of the POPIA Regulations is the requirement to conduct a Personal Information Impact Assessment (PIIA). (Note: While sometimes referred to interchangeably with Privacy Impact Assessment or similar terms in other jurisdictions, it is specifically termed PIIA in the South African context.) The PIIA serves as an essential tool for identifying, analysing, and mitigating risks to data subjects' privacy arising from an organisation's processing activities, particularly those involving specific technologies, systems, or new initiatives.

Unlike general enterprise risk management, which primarily addresses organisational risks, the PIIA centres on the rights and freedoms of data subjects. It requires a thorough identification of all reasonably foreseeable risks to personal information, with the goal of eliminating unacceptable residual risk. Every act of processing constitutes an interference with privacy rights and must be justified as necessary and proportionate.

The PIIA process begins with a systematic description of the proposed processing activities and their purposes, including any reliance on legitimate interests under Section 11(1)(f) of POPIA. Where feasible, data subjects (or their representatives) should be consulted to provide input on the anticipated impacts, facilitating a robust evaluation of necessity and proportionality under Sections 10 and 11(1)(d).

A PIIA is considered complete when it incorporates specific measures to address identified risks, such as technical safeguards, security controls, compliance protocols, and procedures for notifying breaches as required under Section 22(1). Risk identification follows an objective standard of foreseeability: responsible parties may be held liable for negligence if they fail to anticipate risks that a reasonable person would have foreseen. This liability can extend to risks introduced by operators or service providers, with the burden on the responsible party to prove that risks were comprehensively assessed and mitigated.

The PIIA adopts a technology-neutral, structured approach divided into three overarching stages-Preparation, Evaluation, and Report and Safeguards-to produce reproducible and verifiable outcomes. This facilitates oversight by the Information Regulator, enables comparison of processing solutions, and supports adherence to POPIA's stringent data protection standards.

Safeguarding Personal Information

POPIA's core purpose is to protect the constitutional right to privacy by ensuring personal information is safeguarded during processing by responsible parties. It mandates appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information in the responsible party's possession or under its control, specifically to prevent:

Responsible parties must take reasonable steps to identify all reasonably foreseeable internal and external risks to personal information; establish and maintain appropriate safeguards against those risks; regularly verify the effectiveness of those safeguards; and update the safeguards as needed to address emerging risks or identified deficiencies.

Process to Conduct a Personal Information Impact Assessment

The PIIA follows a continuous improvement model designed to ensure that personal information processing respects data subjects' privacy rights while effectively mitigating risks. It is typically led by the responsible party, with input from the Information Officer (IO), project owners, and relevant stakeholders. The process is structured into four main stages: Context Study, Conditions for Lawful Processing Study, Data Protection Risks Study, and PIIA Validation. Each stage includes defined objectives, steps, and deliverables, often supported by standardised templates within a dedicated PIIA tool for consistent documentation.

1. Study of the Context

Objective: Develop a thorough understanding of the personal information processing operations to clearly define the PIIA's scope and focus.

Steps:

Deliverable: A clear scoping statement outlining the processing context, stakeholders, and assets, establishing a solid foundation for subsequent analysis.

2. Study of the Fundamental Principles

Objective: Verify compliance with POPIA's conditions for proportionality, necessity, lawfulness, and protection of data subjects' rights.

Steps:

Deliverable: A documented evaluation of controls ensuring adherence to POPIA's core conditions and data subject rights, complete with identified improvements.

3. Study of Information Security Risks

Objective: Identify and address security-related privacy risks, focusing on potential breaches and their effects on data subjects.

Steps:

Deliverable: A comprehensive risk report detailing controls, risks (with severity/likelihood estimates), and mitigation actions for unacceptable risks.

4. Validation of the PIIA

Objective: Consolidate findings, incorporate stakeholder input, and formally decide on the processing's acceptability.

Steps:

Deliverable: A fully validated PIIA report with action plans, stakeholder documentation, and a clear decision on proceeding with the processing.

Continuous Improvement and Monitoring

Key Features of the POPIA PIIA Process

Benefits

Automation

Utilising a dedicated PIIA tool streamlines collaboration, allowing multiple users to perform assessments with greater efficiency, accuracy, and consistency, thereby supporting ongoing compliance efforts.