POPI Newsflash

Are you tired of feeling like your personal information is being mishandled by companies and organisations?

Are you tired of feeling like your personal information is being mishandled by companies and organisations?

 

Well, you’re not alone! In fact, the Information Regulator of South Africa is taking a stand and cracking down on those who violate the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA).

 

But don’t just take our word for it. The Regulator has released some pretty eye-opening details about their investigation and assessment process. Did you know they’ve received over 895 POPIA complaints in the last financial year alone, representing a 30% increase from the previous year?

 

The Regulator can investigate a complaint submitted by any person or initiate an investigation. Most complaints are resolved through settlement or mediation, but the matter will be referred for a full investigation if necessary. After the investigation report is referred to the Enforcement Committee for a finding, an enforcement notice is issued, which affects a court order.

 

And that’s not all. They’ve also conducted 96 assessments of public and private bodies, including regulatory bodies, banks, insurance companies, and municipalities.

 

But get this: none of the assessed municipalities were 100% compliant with PAIA. The POPIA division received 895 complaints, a 30% increase from the previous financial year.

 

During the financial year 2022-2023, the PAIA Division of the Regulator received over 300 complaints; of these, 209 were resolved. The Regulator conducted 96 assessments of public and private bodies, including regulatory bodies, banks, insurance companies, and municipalities. None of the assessed municipalities was 100% compliant with PAIA, and some needed to be compliant.

 

The POPIA division received 895 complaints in the same period, and 616 were resolved. This represents a 30% increase from the previous financial year. The Regulator found that much work must be done to ensure compliance with PAIA.

 

They’ve also conducted 96 assessments of public and private bodies, including regulatory bodies, banks, insurance companies, and municipalities. And get this: none of the assessed municipalities were 100% compliant with PAIA. The Regulator provided a snapshot of the enforcement work done over the previous twelve months by referencing a few examples of complaints.

 

One case involved the distribution of personal information of the victims of sexual assault in the Krugersdorp area. The South African Police Service (SAPS), responsible for the breach, distributed the victims’ names, addresses, and ID numbers via WhatsApp to some members of the SAPS. The victim’s personal information was then circulated on social media platforms, such as Facebook, after a leak from the members of the SAPS. The Regulator found that SAPS had interfered with the protection of the personal information of the data subjects and issued an enforcement notice against them.

 

The right of access to records pertaining to payment distribution of royalties collected from broadcasters is an issue that is crucial to the livelihood of most musicians in South Africa. This was highlighted in a complaint received by the Information Regulator from Hardwick Trading Pty Ltd, who were denied access to the records by the head of Risa Audio Visual Licensing NPC (RAV). The complaint was made against RAV, which had refused to grant access to records relating to payment distribution made to any third party in respect of license fees or copyright royalties received by RAV from broadcasters and other users for the public broadcast of music videos created by Bula Records.

 

Mr. Clive Martin Hardwick, the director of Hardwick Trading Pty Ltd and a co-founder of Bula Records, submitted the complaint on behalf of the company, stating that Bula Records had become one of the biggest independent labels in South Africa. The nature of the complaint was such that it affected the majority of musicians in South Africa, leading the Regulator to conduct a public hearing on 2 and 3 August 2022. During the investigation, the Regulator heard evidence from different music industry players and the Group Chief Executive Officer of the SABC.

 

Following the investigation, an investigation report was referred to the Enforcement Committee, which made findings and recommendations to the Regulator. Based on these recommendations, the Regulator issued an Enforcement Notice against the CEO of Risa Audio Visual Licensing NPC as the head of the private body. The Enforcement Notice directed the CEO to set aside his decision and grant access to the complainant the complete and accurate records of payment distributions made to any third party in respect of license fees or copyright royalties received by the private body from broadcasters and other users for the public broadcast of music videos created by Bula Records (Pty) Ltd, in respect of the broadcast usage reports for the periods October 2009 to October 2014 or any prior periods in respect of which distribution payments were made from 2014 to the date of submission of the PAIA request. The CEO was also directed to ensure compliance with the Enforcement Notice within thirty-one (31) days from the date of receipt of the Notice.

 

This case underscores the importance of transparency and accountability in the music industry, particularly with regard to the payment of royalties. The decision of the Information Regulator to conduct a public hearing and issue an Enforcement Notice demonstrates their commitment to protecting the rights of producers and musicians and ensuring that they are able to access the information they need to safeguard their interests.

 

The Information Regulator of South Africa, in addition to resolving other cases through conciliation and mediation, has resolved a number of noteworthy complaints. One such case involved a complaint against the South African Police Service (SAPS), where the complainant had opened two criminal cases against third parties. Still, the National Prosecuting Authority (NPA) declined to prosecute. The complainant was refused access to the dockets, which prevented him from pursuing his rights. However, the Regulator’s intervention granted access to the dockets.

 

Another notable complaint was lodged against the South African Music Rights Organisation (SAMRO). The complainant, a music producer, alleged that SAMRO had collected his royalties from Lesedi FM (SABC) for the usage of his songs as radio jingles. SAMRO refused to provide access to the payment records for royalties collected from the SABC for the period from March 2011 to March 2020. The Regulator intervened, and SAMRO cooperated by granting access to the requested records.

 

The Department of Mineral Resources and Energy (DMRE) also received a complaint from a person who had requested access to several records relating to the mineral rights status reports for each of the several farms across the country. The Regulator intervened, and the department granted access to the records.

 

Lastly, the Regulator received 57 complaints against the Eastern Cape Department of Health regarding the alleged deemed refusal of access to hospital records for road accident victims, which are required to lodge a claim with the Road Accident Fund (RAF). The Regulator intervened, and access to the hospital files was granted for 47 complaints, while the intervention for the remaining complaints was ongoing.

 

But the Regulator isn’t just all talk. They’ve resolved most complaints through settlement or mediation processes. And if a complaint can’t be resolved, they’ll refer the matter for a full investigation. After the investigation report is referred to the Enforcement Committee for a finding, an enforcement notice is issued, which can even result in a court order.

 

And if you think that your personal information is safe just because you’re not in South Africa, think again! The Regulator has even dealt with cases involving the distribution of personal information of victims of sexual assault and issues pertaining to the payment distribution of royalties collected from broadcasters.

 

Whether you’re worried about identity theft, online tracking, or data breaches, Labournet is here to help you take proactive measures to safeguard your personal information. Don’t wait another minute – reach out to us via email at popi@labournet.com today and regain control of your personal information.

 

Link attached for the full media statement: Information Regulator Media Statement