Your Personal Information and Privacy

Updated: 4 days ago
Learn how to protect your personal information and what to do if you have a privacy concern.
You give a business your cellphone number and start receiving marketing messages. You submit a copy of your identity document for an application, then wonder who can access it. Or a company tells you that its customer information has been exposed. What can you do to protect your personal information?
South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA) sets requirements for how public and private bodies process personal information. Processing includes activities such as collecting, storing, using and sharing information. POPIA also gives you rights concerning information held about you.
What counts as personal information?
Personal information is information relating to an identifiable person. It can include your name, identity number, contact details, address, financial information and information about your health. A combination of details may identify you even if your name is not included.
Think about the information you provide when applying for a job, opening an account, using an app or registering for a service. Before sharing it, consider who is asking for it and why they need it.
Can an organisation collect or use your information without your consent?
Consent is not the only lawful basis for processing personal information. Depending on the circumstances, POPIA may permit processing for reasons such as performing a contract, complying with a legal obligation or pursuing a legitimate interest recognised by the Act. An organisation must still comply with POPIA’s other requirements, including collecting information for a lawful, defined purpose and taking appropriate steps to protect it.
For example, a business may need your delivery address to send you something you ordered. That does not automatically mean it can use your details for any unrelated purpose.
When an organisation collects your information, it must generally provide information about matters such as what is being collected, why it is needed and who is collecting it, subject to the Act’s exceptions. If you are unsure, ask for its privacy notice or an explanation.
Can you find out what information an organisation has about you?
Yes. POPIA gives you the right, subject to its requirements, to ask an organisation whether it holds your personal information. Confirmation of whether it holds information about you is free. You may also request access to the information itself, although applicable fees and lawful grounds for refusing access may apply. You will generally need to provide adequate proof of your identity.
If information about you is inaccurate, outdated, excessive or was obtained unlawfully, you may be entitled to request its correction or deletion. You can also request deletion of a record that the organisation is no longer authorised to retain. These rights are subject to the Act’s conditions; an organisation may, for example, be legally required to keep certain records.
Practical step: Contact the organisation’s information officer or the privacy contact identified in its privacy notice. Explain what information you are asking about or want corrected, and keep a copy of your request.
What if you keep receiving unwanted marketing messages?
POPIA places restrictions on direct marketing, including marketing sent by email, SMS and other electronic communications. Such marketing generally requires your consent unless a specific exception applies, including certain communications to existing customers. You also have rights to object to direct marketing.
If you receive marketing you do not want:
Use a genuine unsubscribe or opt-out option, where one is provided.
If necessary, contact the organisation directly and ask it to stop sending you marketing.
Keep records of your request and any further messages you receive.
Be careful with suspicious messages. Do not click an unfamiliar link merely to unsubscribe; use the organisation’s verified website or contact details instead.
What if your personal information has been exposed?
A security compromise may involve personal information being accessed or acquired by someone who is not authorised to have it. Where POPIA’s notification requirements are triggered, the organisation responsible for the information must notify the Information Regulator and the affected people as soon as reasonably possible after discovering the compromise, subject to the Act’s provisions.
If you receive a notice that your information may have been exposed, read it carefully and identify what information is involved. The steps you take will depend on the risk. For example:
Change a password if an affected account may have been compromised, and avoid reusing that password elsewhere.
Contact your bank promptly through its official channels if your banking information or access credentials may be at risk.
Watch for unexpected account activity and messages asking you to disclose passwords, PINs or one-time passwords.
Keep the organisation’s notice and any related correspondence.
If you suspect that someone is misusing your identity or accessing your accounts, act promptly and seek assistance from the relevant institution.
How can you protect your information in everyday life?
A few precautions can reduce the risk of your information falling into the wrong hands:
Share only what is needed. Ask why someone requires a copy of your identity document or other sensitive details.
Check who you are dealing with. Use verified contact details before sending personal information or making payments.
Protect your accounts. Use strong, distinct passwords and enable additional account security where available.
Review privacy settings. Check what information your apps and social media profiles make visible to others.
Think before forwarding someone else’s details. A photograph, document or message may contain information that person would not want shared.
These precautions are useful, but the responsibility to comply with POPIA rests with organisations and other persons to whom the Act applies. Protecting your own information does not replace their legal obligations.
What if you believe your personal information has been misused?
Start by contacting the organisation involved. Explain what happened, what concerns you and what you would like it to do. Keep copies of your messages and any responses.
You can lodge a POPIA complaint with the Information Regulator if you believe your information has been processed unlawfully, disclosed without proper authority or inadequately protected, or if an organisation has failed to address a request concerning your rights. The Regulator provides a complaints process and an online service for submitting complaints.
Remember:
Ask why information is needed. Protect what you share. Speak up if something seems wrong.
Official Resources and Further Reading
Protection of Personal Information Act 4 of 2013: Read POPIA, including the rights relating to access, correction, security compromises and direct marketing.
POPIA Forms: Find the Information Regulator’s official forms for objecting to processing and requesting correction or deletion of personal information.
Information Regulator: Complaints: Learn when and how to lodge a POPIA complaint.
Information Regulator: eServices Portal: Access the online complaints service.
Information Regulator: Fact Sheet on Security Compromises: Learn about the notification requirements when personal information is compromised.
Disclaimer: This article provides general information about South African law and does not constitute legal advice. The information may not apply to your particular circumstances. If you need advice about your situation, consult a qualified legal practitioner or an appropriate legal advice service.
Comments