Looking for something specific?
Subscribe to
The Bloc Journal
Stay in the loop of what’s happening and how it affects YOUR website.
In just 7 Days
You could have your own website that will be found by Google, seen by Ai and is compliant!
Excellent rating
Based on 1 reviewsTrustindex verifies that the original source of the review is Google. The Bloc Studio continues to be one of our strongest partnerships my company has ever made. We have been working together for over 5 years and it is such a pleasure. We continue to grow together and I love that I am able to empower my clients to see the value of a phenomenal website knowing the Bloc Studio deliver every time. The team is knowledgable, collaborative, flexible and are always keeping up with what's happening in their world so you know you are in good hands. Could not recommend them more. Lauren Palmer
Latest Articles
What is a Privacy Policy?
A privacy policy is a public statement of what personal information you (personally and as a business) collect, why you collect it, who you share it with, how long you keep it, how you protect it, and what rights people have over it.
It is not your terms and conditions for use of your website. Let’s just clear that up first and foremost. This is a totally separate document. While your Ts & Cs cover your commercial relationship, a privacy policy governs that data you collect from your users/clients/customers. Combining these two documents together is common mistake, especially amoung smaller businesses.
The Privacy Policy is also not your Cookie Banner although the two do need to agree with each other.
And for South Africans, it is not your PAIA manual either. PAIA governs access to records held by your business while your privacy policy (which should be POPIA compliant) governs how you handle personal information. Both are required, and both are enforced by the same Information Regulator.
And lastly, a privacy policy is not optional. Your privacy policy is legally binding and it can be help against you should poop hit the fan. Whatever you have stated (whether you thought through it or not) is legally binding.
Why Does the Law Require a Privacy policy?
You can’t consent or object to something you were never told about. These laws help you to do that. The privacy policy helps with your rights within your country and what happens with your data.
United States
A notice of collection and a yearly update of your policy is required by the US CCPA/CPRA. On top of that you have to explicitly state whether the information you are gathering from your users is going to be shared with third-parties or sold.
United Kingdom & Europe
Articles 13 and 14 in the UK and EU’s GDPR states that a “concise, transparent, intelligible and easily accessible form, using clear and plain language” is expected. Regulators have actually fined companies for having unclear or unreadable policies.
South Africa
POPIA’s Section 18 requires you to let your users know what you’re collecting. This will include (but not limited to), why you’re collecting this data, who you are, whether collection of this data is voluntary or mandatory, and the consequences of not supplying it.
A Minimum Consent Checklist
Since the privacy policy is the only place where those getting ready to submit data on your website can actually see, this is definitely where the regulators are going to look first.
The following checklist is applicable to all the above policies. Make sure you have the following in your policy:
- Who you are and how to contact you (plus your Information Officer / DPO)
- What categories of personal information you collect
- Where you got it, if not directly from the person
- Why you collect it — the purpose, and the lawful basis
- Who you share it with, including third-party processors and cross-border transfers
- How long you keep it
- How you secure it
- What rights the person has, and exactly how to exercise them
- How to complain to the relevant regulator
- When the policy was last updated
Penalties & Fines
While the GDPR and the CCPA/CRPA are most likely just to fine you with non-compliance, South Africa has taken the go big or go home approach and will simply jail you for up to 10 years!
I’m being dramatic. They warn you… and THEN jail you for up to 10 years for non-compliance. It’s that or a R10mil fine (about $617 000).
In a nutshell, in EU, UK and USA just take your money. In SA it’s a criminal offence.
We love a good table. Here’s one to keep you up at night:
POPIA (South Africa) |
GDPR (EU/EEA) |
CCPA/CPRA (California) |
|
|---|---|---|---|
|
Max penalty |
R10m + 10 yrs prison |
€20m or 4% of global annual turnover, whichever is higher |
$7,988 per violation, per consumer |
|
Legal basis needed to process? |
Yes, consent or another lawful ground |
Yes, one of six lawful bases |
No, opt-out model, not opt-in |
|
Core consumer right |
Access, correction, deletion, objection |
Access, erasure, portability, objection |
Know, delete, correct, opt out of sale/sharing |
|
Who it protects |
Data subjects (incl. juristic persons. A POPIA quirk) |
Data subjects in the EU/EEA |
California residents |
|
Breach notification |
To Regulator and data subjects, as soon as reasonably possible |
To supervisory authority within 72 hours |
Varies; private right of action attaches |
But I’m Just a Tiny Home Business
It still applies to you, Felicia.
POPIA has no revenue threshold. If you process personal information in South Africa, it applies. Klaar! A single person business with a Mailchimp list is a responsible party.
GDPR follows the customer, not the company. Article 3 extends it to any business anywhere that offers goods/services or monitors the behaviour of people in the EU. One EU client or customer that is being tracked makes you eligible.
You’ve got about 172 jurisdictions that now have either something of or a comprehensive list of data laws. That makes about 85% of the world.
About 172 jurisdictions now have comprehensive data protection laws, covering roughly 85% of the world’s population. Operating “outside” privacy law is no longer a real option.