Why a Strong PIIA Is Essential Before Applying for Prior Authorisation

Why a solid PIIA is essential before applying for prior authorisation

When a responsible party plans to carry out processing that requires prior authorisation under the Protection of Personal Information Act (POPIA), the quality of the supporting Personal Information Impact Assessment (PIIA) becomes critical. The Information Regulator does not treat the application as a mere notification. It investigates the lawfulness of the proposed processing. A weak or incomplete assessment increases the likelihood of delay, further investigation, or refusal.

Regulation 4(1)(b) already requires Information Officers to ensure that a PIIA is conducted so that adequate measures and standards exist to comply with the conditions for lawful processing. Where prior authorisation is also required, that assessment takes on additional practical importance. It becomes the foundation on which the application to the Regulator is built.

What the Regulator examines

On receiving an application, the Regulator records the request and issues an acknowledgement with a reference number. The responsible party may not proceed with the processing until the Regulator has completed its investigation or has indicated that a more detailed investigation will not be conducted. Within four weeks, the Regulator must inform the applicant whether it intends to conduct a more detailed investigation. If it does, that investigation may take up to thirteen weeks.

At the end of the process, the Regulator issues a written statement on the lawfulness of the processing. If the processing is found to be unlawful, an enforcement notice may follow. The notice can require the responsible party to take specified steps, refrain from certain actions, or stop the processing altogether.

Because the Regulator will examine whether the processing complies with POPIA’s conditions for lawful processing, the application must address those conditions clearly. This includes the purpose of the processing, its necessity and proportionality, the categories of personal information involved, the risks to data subjects, and the safeguards that will be applied. A thorough PIIA provides the structured analysis needed to support these points.

Why superficial assessments fall short

An assessment that remains high-level or generic offers limited assistance. It may confirm that a process was followed, yet fail to demonstrate that the specific risks associated with the proposed processing have been properly identified and addressed. In the context of prior authorisation — where the processing is already regarded as higher risk — this lack of depth becomes a liability.

This is particularly relevant for activities involving unique identifiers used for secondary purposes, information on criminal or objectionable conduct, credit reporting, or cross-border transfers of special personal information or children’s data. Many of these activities now occur within digital and artificial intelligence systems that involve complex data flows, automated decision-making, or reliance on foreign infrastructure. The assessment must engage with those realities rather than describing them in abstract terms.

Linking assessment quality to application success

A well-prepared PIIA does not guarantee approval. It does, however, significantly improve the quality of the submission. It shows that the responsible party has examined the processing carefully, identified foreseeable risks, evaluated existing controls, and determined what additional measures are required. This level of analysis aligns with the Regulator’s task of assessing lawfulness and reduces the likelihood of avoidable queries or extended investigation.

From a governance perspective, the same discipline supports accountability under King V. Boards are expected to oversee higher-risk data and technology activities with appropriate care. Evidence that a substantive impact assessment was completed before an application for prior authorisation was submitted strengthens the organisation’s ability to demonstrate that oversight.

Practical consequences

Organisations that treat the PIIA as a formality before submitting a prior authorisation request risk two related problems. First, the application may be delayed or refused because it does not adequately address the lawfulness of the processing. Second, if processing proceeds without proper authorisation or before the investigation is complete, the organisation may commit an offence and face significant penalties.

The more effective approach is to treat the assessment as real analytical work. It should examine the specific processing activity, the risks it creates for data subjects, and the measures required to mitigate those risks. Only then should the application be prepared and submitted.

Prior authorisation exists to protect data subjects from processing that carries particular risk. A strong Personal Information Impact Assessment is one of the most practical ways to show that those risks have been taken seriously before the Regulator is asked to consider the activity.