How POPIA and King V together raise the bar for governance of personal information and technology
King V places clearer expectations on governing bodies when it comes to data, information and technology. Boards are required to govern these areas in a way that supports the organisation's strategy and objectives, while ensuring that the use of technology remains ethical, accountable and appropriately controlled. This includes emerging technologies such as artificial intelligence.
These expectations sit alongside the existing obligations under the Protection of Personal Information Act (POPIA). Together, they reinforce a simple point: protecting personal information is not only a legal compliance matter. It is also a governance responsibility.
Under POPIA, responsible parties must process personal information lawfully and take reasonable technical and organisational measures to safeguard it. Information Officers are specifically required to ensure that a Personal Information Impact Assessment (PIIA) is conducted. The purpose of the assessment is to confirm that adequate measures exist to comply with the conditions for lawful processing.
King V adds a further layer. It expects governing bodies to oversee how data and technology are used, to understand the associated risks, and to ensure that accountability is clear. A board that relies only on high-level policies or generic statements of intent will find it difficult to demonstrate that these expectations are being met in practice.
This is where the quality of the underlying work becomes important. A PIIA that is treated as a formality produces limited evidence of actual risk consideration. By contrast, a structured assessment that examines the nature of the processing, the necessity of the data involved, the risks to data subjects, and the adequacy of controls creates a clearer record of decision-making. That record is useful not only for regulatory purposes, but also for board oversight.
When AI systems or other advanced technologies are introduced, the stakes increase. These systems often process larger volumes of personal information, operate with greater complexity, and can produce outcomes that significantly affect individuals. In such cases, boards need more than assurance that a policy exists. They need confidence that the privacy implications have been properly examined and that residual risks have been considered.
A well-conducted PIIA supports this. It provides a practical mechanism for identifying foreseeable risks, evaluating existing safeguards, and recording the decisions taken to address gaps. It also creates a foundation that can be revisited when systems change, when new purposes emerge, or when risk profiles shift. This ongoing discipline is more consistent with King V's emphasis on effective governance than a one-off compliance exercise.
Accountability, in this context, is not abstract. It is demonstrated through the quality of the processes organisations put in place and the evidence those processes produce. Policies set direction. Assessments, controls and documented decisions show whether that direction is being applied.
South African organisations operating under both POPIA and King V therefore face a practical question. Are privacy assessments being used to complete a requirement, or are they being used to understand and manage the real implications of processing personal information? The second approach requires more careful work, but it aligns more closely with the expectations now placed on both Information Officers and governing bodies.
Protecting personal information is part of responsible corporate conduct. King V makes the governance dimension of that responsibility more explicit. Meeting it depends less on the existence of documents and more on the quality of the work those documents reflect.