The Protection of Personal Information (POPI) Act has been promulgated in its final form. Compliance with the act is now a legal obligation.
POPIA will become enforceable against practices from 1 July 2021. It contains many requirements that practices must meet to ensure that they comply with POPIA and that their processing of personal information of not only patients, but also practice staff, referring practitioners and others (i.e. data subjects), is reasonable. POPIA contains extensive requirements related to disclosures that must be made to data subjects regarding the processing of their personal information.