Establish Privacy Governance
Establish accountability, leadership and the Information Officer.
Eighteen phases take you from establishing accountability to auditing and continually improving. Start with an assessment, get your maturity level, and work a prioritised plan.
Follow the line, or pick up a step to see what it covers.
Establish who is accountable, then find out what personal information the organisation actually holds and where it lives.
Establish accountability, leadership and the Information Officer.
Identify what personal information the organisation holds and where it resides.
Test the legal footing for every processing activity, including the information that leaves South Africa.
Determine why and under what legal basis personal information is processed.
Identify and manage transfers of personal information outside South Africa.
Close the gaps the assessment exposes: the notices people see, the rules staff follow, and how long you keep information.
Ensure data subjects are properly informed about how their information is collected and used.
Create the governance framework required to manage privacy consistently.
Determine how long information is retained and how it is securely disposed of.
Stand up the operating controls that carry the programme day to day, from requests and suppliers through to security and marketing.
Establish a process for handling access, correction, objection and other data-subject requests.
Ensure suppliers and service providers appropriately protect personal information.
Protect personal information against loss, damage, unauthorised access and disclosure.
Build privacy considerations into new systems, projects and business processes.
Ensure marketing, cookies and tracking activities comply with privacy requirements.
Address the organisation’s obligations under PAIA alongside POPIA.
Make privacy part of how people work, so the controls hold when nobody is watching.
Ensure employees understand their privacy and information-security responsibilities.
Watch for incidents and track performance, so problems surface early and the board sees the trend.
Ensure the organisation can detect, respond to and report privacy incidents.
Establish privacy metrics, risk monitoring and management reporting.
Keep the records that prove the controls exist and operate. Compliance you cannot evidence is compliance you cannot defend.
Maintain the records and evidence necessary to demonstrate that privacy controls exist and operate.
Reassess as the organisation changes, address what has drifted, and draw the line again.
Regularly assess the programme, address gaps and improve as the organisation evolves.