Principals, fines & penalty discussion points (September 2021) In today’s working environment, dealing with data subject information and compliance with local and international regulations is challenging. To add to the challenge of understanding the local and international rules, we face the challenge of laws from other countries and understanding their role locally. The GDPR, in particular, is one of those regulations which has a long international arm that impacts local operations in respect of how operators and processors handle EU citizens data of the EU. This article aims to introduce the basic principles and data subjects rights of the GDPR and the POPIA conditions. With this in mind, we want to create awareness of the local regulations and introduce some international rules that will impact how we handle offshore data subjects information and the possible issues related to such data breaches. In future articles, we will explore more of these crucial points in detail. GDPR Principles and Data Subject rights The GDPR came into operation at the end of May 2018 and stood successfully applied across all EU member states. The impact of the regulation on data handling by controllers and processors has been extensive. In particular, the onus on third-party data processors outside of the EU. The responsibility of these third-party processors is significant as the GDPR applies in all aspects in the handling and processing of EU citizens data. Therefore it is critical to ensure that if you are processing EU citizens data that you comply with the GDPR. The GDPR principles and the data subjects rights stand set out in Article 5 of the GDPR. The six principles that should apply when collecting or processing personal data must stand read in conjunction with data subjects rights. Six Principles:

  1. Personal data must be processed lawfully, fairly and transparently.
  2. Personal data can only stand collected for specified, explicit and legitimate purposes.
  3. Personal data must be adequate, relevant and limited to what is necessary for processing.
  4. Personal data must be accurate and kept up to date.
  5. Personal data must be kept in a form such that the data subject can stand identified only as long as necessary for processing.
  6. Personal data must stand processed in a manner that ensures its security.

Eight Rights

  1. The right to be Informed
  2. The right of Access
  3. The right to Rectification
  4. The right to Restrict processing
  5. The right to Data Portability
  6. The right to Object
  7. Rights concerning automated decision making and Profiling

It is worth noting that the data controller is responsible for demonstrating that the principles and data subject rights stand implemented, and they must ensure the same for any third-party data processors with whom they contract. Guide to GDPR penalties tier 1 and tier 2 infringement Some of the GDPR Articles’ if found to have stood violated, carry the maximum administrative penalty as noted, being up to four percentage points of annual global turnover or €20 million, whichever is the higher. NOTE: Infringements of the requirements concerning international transfers are also subject to this higher penalty. The higher penalties apply to the following Articles;

  • 5 – Principles relating to the processing of personal data
  • 6 – Lawfulness of processing
  • 7 – Conditions for consent
  • 9 – Processing of special categories of personal data
  • 12 – Transparent information, communication and modalities for the exercise of the rights of the data subject
  • 13 – Information to stand provided where personal data stand collected from the data subject
  • 14 – Information to stand provided where personal data have not stood obtained from the data subject
  • 15 – Right of access by the data subject
  • 16 – Right to rectification
  • 17 – Right to erasure (‘right to stand forgotten’)
  • 18 – Right to restriction of processing
  • 19 – Notification obligation regarding rectification or erasure of personal data or restriction of processing
  • 20 – Right to personal data
  • 21 – Right to object
  • 22 – Automated individual decision-making, including profiling

The lower tier of penalty for infringing other Articles of the Regulation, which stands calculated at up to two percentage points of global annual turnover or €10 million – again, whichever is the higher. The penalty will apply to the following Articles;

  • 8 – Conditions applicable to child’s consent concerning information society services
  • 11 – Processing which does not require identification
  • 25 – Data protection by design and by default
  • 26 – Joint controllers
  • 27 – Representatives of controllers or processors not established in the Union
  • 28 – Processor
  • 29 – Processing under the authority of the controller or processor
  • 30 – Records of processing activities
  • 31 – Cooperation with the supervisory authority
  • 32 – Security of processing
  • 33 – Notification of personal data breach to the supervisory authority
  • 34 – Communication of a personal data breach to the data subject
  • 35 – Data protection impact assessment
  • 36 – Prior consultation
  • 37 – Designation of data protection officer
  • 38 – Position of the data protection officer
  • 39 – Tasks of the data protection officer
  • 42 – Certification
  • 43 – Certification bodies

POPIA In contrast to the GDPR, the POPIA only has eight conditions (or so-called principles) to be adhered to when processing data subjects information. The eight conditions for the lawful processing of Personal Information by or for a responsible party are the following:

  1. ‘‘Accountability’’, as referred to in section 8;
  2. ‘‘Processing limitation’’, as referred to in sections 9 to 12;
  3. ‘‘Purpose specification’’, as referred to in sections 13 and 14;
  4. ‘‘Further processing limitation’’, as referred to in section 15;
  5. ‘‘Information quality’’, as referred to in section 16;
  6. ‘‘Openness’’, as referred to in sections 17 and 18;
  7. ‘‘Security safeguards’’, as referred to in sections 19 to 22; and
  8. ‘‘Data subject participation’’, as referred to in sections 23 to 25.

The conditions stand further expanded in the various sections of the Act. The table below is a quick guide to the related sections found in POPIA concerning the eight conditions for lawfully processing personal information.

  1. Personal data must be processed lawfully, fairly and transparently.
    1. POPI Act: Condition 2 – Lawfulness of processing section 9 to 12
    2. POPI Act: Condition 6 – Openness section 17 and 18
  2. Personal data can only stand collected for specified, explicit and legitimate purposes.
    1. POPI Act: Condition 3 – Purpose specific sections 13 and 14
    2. POPI Act: Condition 4 – Further processing limitation section 15
  • Personal data must be adequate, relevant and limited to what is necessary for processing.
    1. POPI Act: Condition 2 – Purpose specific section 9 to 12.
    2. POPI Act: Condition 3 – Purpose particular sections 13 and 14
    3. POPI Act: Condition 5 – Information quality section 16
  1. Personal data must be accurate and kept up to date.
    1. POPI Act: Condition 8 – Data subject participation section 23 to 25
  2. Personal data must be kept in a form such that the data subject can stand identified only as long as necessary for processing.
    1. POPI Act:
  3. Personal data must stand processed in a manner that ensures its security.
    1. POPI Act: Condition 7 – Security Safeguards section 19 to 22

Guide to POPIA Penalties As with the GDPR, the POPI Act also provides for any infringement of personal data. Such offences or failure of a ‘Duty of Care’ to provide data protection can result in various penalties or fines. Below is an extract of the sections within the POPI Act of offences, penalties, and administrative fines, which may apply if a responsible person processing personal data breaches the regulation.

  1. Obstruction of Regulator
  2. Breach of confidentiality
  3. Impediment or obstruction of execution of a warrant
  4. Failure to comply with enforcement or information notices
  5. Offences by witnesses
  6. Unlawful acts by the responsible party in connection with an account number
  7. Unlawful acts by third parties in connection with an account number
  8. Penalties
  9. Magistrate’s Court jurisdiction to impose penalties
  10. Administrative fines

Expanding on section 109 Administrative fines to highlight what possible penalties may stand applied for data breaches.

  • If a responsible party stands alleged to have committed an offence in terms of this Act, the Regulator may cause to be delivered by hand to that person (from now on referred to as the infringer) an infringement notice which must contain the particulars contemplated in subsection (2).
  • A notice referred to in subsection (1) must
    • specify the name and address of the infringer;
    • specify the particulars of the alleged offence;
    • specify the amount of the administrative fine payable, which amount may, subject to subsection (10), not exceed R10 million;
    • inform the infringer that, not later than 30 days after the date of service of the infringement notice, the infringer may
      • pay the administrative fine;
      • make arrangements with the Regulator to pay the administrative fine in instalments; or
      • elect to be tried in court on a charge of having committed the alleged offence referred to in terms of this Act; and
    • state that a failure to comply with the requirements of the notice within the time permitted will result in the administrative fine becoming recoverable as contemplated in subsection (5).
  • When determining an appropriate fine, the Regulator must consider the following factors:
    • The nature of the personal information involved;
    • the duration and extent of the contravention;
    • the number of data subjects affected or potentially affected by the contravention;
    • whether or not the contravention raises an issue of public importance;
    • the likelihood of substantial damage or distress, including injury to feelings or anxiety suffered by data subjects;
    • whether the responsible party or a third party could have prevented the contravention from occurring;
    • any failure to carry out a risk assessment or a failure to operate good policies, procedures and practices to protect personal information; and
    • whether the responsible party has previously committed an offence in terms of this
  • If an infringer elects to be tried in court on a charge of having committed the alleged offence in terms of this Act, the Regulator must hand the matter over to the South African Police Service and inform the infringer accordingly.
  • If an infringer fails to comply with the requirements of a notice, the Regulator may file with the clerk or registrar of any competent court a statement certified by it as correct, setting forth the amount of the administrative fine payable by the infringer, and such statement thereupon has all the effects of a civil judgment lawfully given in that court in favour of the Regulator for a liquid debt in the amount specified in the statement.
  • The Regulator may not impose an administrative fine contemplated in this section if the responsible party concerned has been charged with an offence in terms of this Act in respect of the same set of
  • No prosecution may be instituted against a responsible party if the responsible party concerned has paid an administrative fine in terms of this section in respect of the same set of facts.
  • An administrative fine imposed in terms of this section does not constitute a previous conviction as contemplated in Chapter 27 of the Criminal Procedure Act, 1977 (Act No. 51 of 1977).
  • A fine payable in terms of this section must be paid into the National Revenue Fund referred to in section 213 of the Constitution.
  • The Minister may, from time to time and after consultation with the Regulator, by notice in the Gazette, adjust the amount referred to in subsection (2)(c) in accordance with the average of the consumer price index, as published from time to time in the Gazette, for the immediately preceding period of 12 months multiplied by the number of years that the amount referred to in subsection (2)(c) has remained the same.

Numerous organisations and people responsible for handling personal data remain unclear of the impact of the regulation if they suffer a breach. Many of these organisations are still working through the – How, What, When and Why’s of the Act. In closing, we trust that this brief introduction was helpful. The main point is to provide an essential awareness of local and international data privacy regulations. In our next article, we will explore the various sections of the regulation how they impact your organisation or personal information. Later we will discuss how to manage and control the data process and flow within your organisation to be compliant with local and international regulations, whichever may apply. “For more about this subject, please see my next article coming soon.”