How to turn privacy policy into repeatable project processes - especially for AI and digital initiatives
Most organisations subject to the Protection of Personal Information Act (POPIA) have privacy policies in place. These documents typically set out principles of lawful processing, data minimisation, security and respect for data subject rights. Policies are necessary. They establish direction and create a common reference point. They do not, however, ensure that those principles are applied when new systems and digital projects are designed and delivered.
Operationalising POPIA means turning policy commitments into repeatable processes that shape how work is done. In the context of artificial intelligence and other digital initiatives, this is particularly important. These projects often involve the collection and use of personal information at scale, complex data flows, and outcomes that can significantly affect individuals. Without a clear process for assessing privacy implications, policy statements remain disconnected from project decisions.
A Personal Information Impact Assessment (PIIA) provides one practical mechanism for bridging that gap. Under Regulation 4(1)(b), Information Officers must ensure that such an assessment is conducted so that adequate measures exist to comply with the conditions for lawful processing. When integrated into project lifecycles, the assessment becomes part of how systems are developed rather than an activity completed after key decisions have already been made.
In practice, this requires clarity at several points. Project teams need to understand when a PIIA is expected. The scope of the processing activity must be defined early enough to influence design. The assessment should examine purpose, necessity, data minimisation, and the risks to data subjects. Findings should be recorded, and any required controls should be assigned and tracked. When these steps are embedded in existing project governance, privacy considerations become operational rather than exceptional.
AI projects illustrate the value of this approach. Decisions about training data, model inputs, retention periods, human oversight and third-party processing all have privacy implications. Addressing these issues through a structured assessment during design is more effective than attempting to retrofit controls after deployment. It also creates a clearer record of how privacy risks were considered - a record that supports both compliance and accountability.
King V reinforces the importance of moving beyond policy. Governing bodies are expected to oversee data, information and technology in a way that maintains control and accountability. Boards gain limited assurance from the existence of a privacy policy alone. They gain more from evidence that processes exist to assess and manage the privacy implications of specific systems and projects.
The shift from policy to process is organisational as much as technical. It requires defined roles, consistent methods, and the discipline to apply them. Information Officers play a central part in ensuring that assessments are conducted with appropriate care. Project and technology teams need sufficient understanding to engage with the process constructively. Together, these elements turn abstract requirements into practical routines.
POPIA does not reward the existence of documentation for its own sake. It requires responsible parties to process personal information lawfully and to implement reasonable safeguards. Meeting those obligations in complex digital environments depends on processes that are actually used. A structured approach to Personal Information Impact Assessment helps organisations embed privacy into the way AI and digital projects are delivered.
Policies describe what should happen. Processes determine whether it does. Organisations that invest in the latter are better placed to manage privacy risks, to demonstrate accountability, and to align their day-to-day project work with the requirements of POPIA and the governance expectations of King V.