Section 20 Information processed by operator or person acting under authority

  1. An operator or anyone processing personal information on behalf of a responsible party or an operator, must—
    1. process such information only with the knowledge or authorisation of the responsible party; and
    2. treat personal information which comes to their knowledge as confidential and must not disclose it,

unless required by law or in the course of the proper performance of their duties.

Section 21 Security measures regarding information processed by operator

  1. A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19.
  2. The operator must notify the responsible party immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person.

Section 22 Notification of security compromises

  1. Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, the responsible party must notify—
    1. the Regulator; and
    2. subject to subsection (3), the data subject, unless the identity of such data subject cannot be established.
  2. The notification referred to in subsection (1) must be made as soon as reasonably possible after the discovery of the compromise, taking into account the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of the responsible party’s information system.
  3. The responsible party may only delay notification of the data subject if a public body responsible for the prevention, detection or investigation of offences or the Regulator determines that notification will impede a criminal investigation by the public body concerned.
  4. The notification to a data subject referred to in subsection (1) must be in writing and communicated to the data subject in at least one of the following ways:
    1. Mailed to the data subject’s last known physical or postal address;
    2. sent by e-mail to the data subject’s last known e-mail address;
    3. placed in a prominent position on the website of the responsible party;
    4. published in the news media; or
    5. as may be directed by the Regulator.
  5. The notification referred to in subsection (1) must provide sufficient information to allow the data subject to take protective measures against the potential consequences of the compromise, including—
    1. a description of the possible consequences of the security compromise;
    2. a description of the measures that the responsible party intends to take or has taken to address the security compromise;
    3. a recommendation with regard to the measures to be taken by the data subject to mitigate the possible adverse effects of the security compromise; and
    4. if known to the responsible party, the identity of the unauthorised person who may have accessed or acquired the personal information.
  6. The Regulator may direct a responsible party to publicise, in any manner specified, the fact of any compromise to the integrity or confidentiality of personal information, if the Regulator has reasonable grounds to believe that such publicity would protect a data subject who may be affected by the compromise.

Section 23 Access to personal information

  1. A data subject, having provided adequate proof of identity, has the right to—
    1. request a responsible party to confirm, free of charge, whether or not the responsible party holds personal information about the data subject; and
    2. request from a responsible party the record or a description of the personal information about the data subject held by the responsible party, including information about the identity of all third parties, or categories of third parties, who have, or have had, access to the information—
      1. within a reasonable time;
      2. at a prescribed fee, if any;
      3. in a reasonable manner and format; and
      4. in a form that is generally understandable.
  2. If, in response to a request in terms of subsection (1), personal information is communicated to a data subject, the data subject must be advised of the right in terms of section 24 to request the correction of information.
  3. If a data subject is required by a responsible party to pay a fee for services provided to the data subject in terms of subsection (1)(b) to enable the responsible party to respond to a request, the responsible party—
    1. must give the applicant a written estimate of the fee before providing the services; and
    2. may require the applicant to pay a deposit for all or part of the fee.
  4.  
    1. A responsible party may or must refuse, as the case may be, to disclose any information requested in terms of subsection (1) to which the grounds for refusal of access to records set out in the applicable sections of Chapter 4 of Part 2 and Chapter 4 of Part 3 of the Promotion of Access to Information Act apply.
    2. The provisions of sections 30 and 61 of the Promotion of Access to Information Act are applicable in respect of access to health or other records.
  5. If a request for access to personal information is made to a responsible party and part of that information may or must be refused in terms of subsection (4)(a), every other part must be disclosed.

Section 24 Correction of personal information

  1. A data subject may, in the prescribed manner, request a responsible party to—
    1. correct or delete personal information about the data subject in its possession or under its control that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully; or
    2. destroy or delete a record of personal information about the data subject that the responsible party is no longer authorised to retain in terms of section 14.
  2. On receipt of a request in terms of subsection (1) a responsible party must, as soon as reasonably practicable
    1. correct the information;
    2. destroy or delete the information;
    3. provide the data subject, to his or her satisfaction, with credible evidence in support of the information; or
    4. where agreement cannot be reached between the responsible party and the data subject, and if the data subject so requests, take such steps as are reasonable in the circumstances, to attach to the information in such a manner that it will always be read with the information, an indication that a correction of the information has been requested but has not been made.
  3. If the responsible party has taken steps under subsection (2) that result in a change to the information and the changed information has an impact on decisions that have been or will be taken in respect of the data subject in question, the responsible party must, if reasonably practicable, inform each person or body or responsible party to whom the personal information has been disclosed of those steps.
  4. The responsible party must notify a data subject, who has made a request in terms of subsection (1), of the action taken as a result of the request.

Section 26 Prohibition on processing of special personal information

  1. A responsible party may, subject to section 27, not process personal information concerning—
    1. the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject; or
    2. the criminal behaviour of a data subject to the extent that such information relates to—
      1. the alleged commission by a data subject of any offence; or
      2. any proceedings in respect of any offence allegedly committed by a data subject or the disposal of such proceedings.

Section 27 General authorisation concerning special personal information

  1. The prohibition on processing personal information, as referred to in section 26, does not apply if the—
    1. processing is carried out with the consent of a data subject referred to in section 26;
    2. processing is necessary for the establishment, exercise or defence of a right or obligation in law;
    3. processing is necessary to comply with an obligation of international public law;
    4. processing is for historical, statistical or research purposes to the extent that—
      1. the purpose serves a public interest and the processing is necessary for the purpose concerned; or
      2. it appears to be impossible or would involve a disproportionate effort to ask for consent,
      3. and sufficient guarantees are provided for to ensure that the processing does not adversely affect the individual privacy of the data subject to a disproportionate extent;
    5. information has deliberately been made public by the data subject; or
    6. provisions of sections 28 to 33 are, as the case may be, complied with.
  2. The Regulator may, subject to subsection (3), upon application by a responsible party and by notice in the Gazette, authorise a responsible party to process special personal information if such processing is in the public interest and appropriate safeguards have been put in place to protect the personal information of the data subject.
  3. The Regulator may impose reasonable conditions in respect of any authorisation granted under subsection (2).

Section 28 Authorisation concerning data subject’s religious or philosophical beliefs

  1. The prohibition on processing personal information concerning a data subject’s religious or philosophical beliefs, as referred to in section 26, does not apply if the processing is carried out by—
    1. spiritual or religious organisations, or independent sections of those organisations if—
      1. the information concerns data subjects belonging to those organisations;
      2. or
      3. it is necessary to achieve their aims and principles;
    2. institutions founded on religious or philosophical principles with respect to their members or employees or other persons belonging to the institution, if it is necessary to achieve their aims and principles; or
    3. other institutions: Provided that the processing is necessary to protect the spiritual welfare of the data subjects, unless they have indicated that they object to the processing.
  2. In the cases referred to in subsection (1)(a), the prohibition does not apply to processing of personal information concerning the religion or philosophy of life of family members of the data subjects, if—
    1. the association concerned maintains regular contact with those family members in connection with its aims; and
    2. the family members have not objected in writing to the processing.
  3. In the cases referred to in subsections (1) and (2), personal information concerning a data subject’s religious or philosophical beliefs may not be supplied to third parties without the consent of the data subject.

Section 29 Authorisation concerning data subject’s race or ethnic origin

  1. The prohibition on processing personal information concerning a data subject’s race or ethnic origin, as referred to in section 26, does not apply if the processing is carried out to—
    1. identify data subjects and only when this is essential for that purpose; and
    2. comply with laws and other measures designed to protect or advance persons, or categories of persons, disadvantaged by unfair discrimination.