Acts Online
GT Shield
POPIA — POPIA Standard / Guideline: Guidelines to Develop a Code of Conduct (source: https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-Guidelines-DevelopCodeOfConduct-22Feb2021.pdf) Address: Braampark Forum 3, 3rd Floor 33 Hoofd St, Braampark Office Park P.O. Box 31533 Braamfontein, Johannesburg, 2017 Tel: 010 023 5200 Fax: 0865003351
 INFORMATION REGULATOR PROTECTION OF PERSONAL INFORMATION ACT, 2013 (ACT NO. 4 OF 2013) The Information Regulator advises as follows: 1.The Guideline to Develop Codes of Conduct in terms of Section 65 of the Protection of Personal Information Act, 2013 (No.4 of 2013) will be published in two official languages in the Government Gazette. It will be effective as at the 1 March 2021. 2. The Guideline to Develop Codes of Conduct that will be published in the Government Gazette is also available on our website to enable relevant bodies to begin developing their Codes. 3. Codes will only be received by the Regulator for consideration after the publication in the Government Gazette. 4. A notice will appear in the Government Gazette proclaiming the commencement of the Regulations issued in terms of Section 112(2) of the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) as follows: a) Regulation 4 will be effective on 1 May 2021; b) Regulation 5 will be effective on 1 March 2021 and c) the residual Regulations will be effective on 1 July 2021. Adv.P.Tlakula Chairperson By order of the Chairperson of the Information Regulator GUIDELINES TO DEVELOP CODES OF CONDUCT Issued under the Protection of Personal Information Act 4 of 2013 (POPIA) Table of Contents PART 1 – INTRODUCTION: THE LEGISLATIVE FRAMEWORK ............................ 4 1 Purpose of POPIA and the need for a code of conduct ................................. 4 2 Objectives of the guidelines ............................................................................ 5 3 Definitions ......................................................................................................... 5 4 Who should use these guidelines ................................................................... 7 5 Purpose of these guidelines ............................................................................ 7 6 Reasons for developing a code of conduct .................................................... 8 7 Criteria for developing a code of conduct ...................................................... 9 8 Understanding of POPIA .................................................................................. 9 9 Administrative mechanisms ............................................................................ 9 10 Resource requirements .................................................................................. 10 11 Notice of intention to develop a code of conduct ........................................ 10 12 Code of conduct requirements under POPIA ............................................... 10 PART 2 – ISSUING OF A CODE OF CONDUCT BY THE INFORMATION REGULATOR (Regulator) ...................................................................................... 11 13 General principles applicable to issuing of a code of conduct................... 11 14 Other matters that may be included in a code of conduct .......................... 12 15 Drafting style ................................................................................................... 12 16 Process for issuing of code of conduct ........................................................ 12 17 Openness and transparency .......................................................................... 14 18 Notice of consideration for a code of conduct ............................................. 14 19 Notification ...................................................................................................... 15 20 Register for approved codes of conduct ...................................................... 15 PART 3 – CODE GOVERNANCE ........................................................................... 16 21 Governance arrangements ............................................................................. 16 22 Bodies bound by a code of conduct ............................................................. 16 23 Identifying relevant bodies bound by a code of conduct ............................ 16 24 Monitoring compliance with a code of conduct ........................................... 16 25 Reporting on compliance with a code of conduct ....................................... 17 PART 4 – COMPLAINTS HANDLING ..................................................................... 18 26 Purpose of a complaints handling procedure .............................................. 18 27 Who may submit a complaint......................................................................... 19 28 The complaints process ................................................................................. 19 29 Responsibilities of the Independent Adjudicator ......................................... 20 PART 5 – REVIEWING, VARYING AND REVOCATION OF AN APPROVED CODE OF CONDUCT ......................................................................................................... 20 30 Review of the operation of an approved code of conduct .......................... 20 31 Variations to an approved code of conduct.................................................. 21 32 The form and manner of the application to vary an approved code of conduct ............................................................................................................ 22 33 Revocation of an approved code of conduct................................................ 22 34 The form and manner of the application to revoke an approved code of conduct ............................................................................................................ 23 35 Review.............................................................................................................. 23 PART 1 – INTRODUCTION: THE LEGISLATIVE FRAMEWORK 1 Purpose of POPIA and the need for a code of conduct 1.1 The purpose of POPIA is, amongst others, to give effect to the constitutional right to privacy by safeguarding personal information when processed by a responsible party. 1.2 POPIA applies to the processing of personal information: 1.2.1 entered in a record by or for a responsible party by making use of automated or non-automated means provided that when the recorded personal information is processed by non-automated means, it forms part of a filing system or is intended to form part thereof; and 1.2.2 where the responsible party is: 1.2.2.1 domiciled in the Republic; or 1.2.2.2 not domiciled in the Republic but makes use of automated and non-automated means in the Republic unless those means are used only to forward personal information through the Republic. 1.3 Chapter 3 of POPIA regulates the processing of personal information by or for a responsible party through compliance with the eight (8) conditions for the lawful processing of personal information, the processing of special personal information and the processing of personal information of children. 1.4 POPIA empowers the Regulator to: 1.4.1 issue, from time to time, codes of conduct, amend and revoke codes; 1.4.2 make guidelines that would assist bodies to develop or to apply codes; 1.4.3 approve codes; and 1.4.4 consider afresh, upon application the determinations by adjudicators under approved codes. 1.5 The purpose of a code is to establish a voluntarily accountability tool and to promote transparency for relevant bodies on how personal information should be processed. A code does not replace the relevant provisions in POPIA but operates in support of the requirements in POPIA. A code cannot limit a data subject’s right to privacy, which can only be done as provided for in POPIA. 1.6 The relevant bodies bound by an issued code of conduct must refrain from performing an act or engaging in a practice that breaches the code. A breach of an issued code is deemed to be a breach of the conditions for the lawful processing of personal information referred to in Chapter 3 and shall be dealt with in terms of Chapter 10 of POPIA. 1.7 A code should limit itself to the provisions which outline the specific obligations of relevant bodies bound by a code. A code should comply with all the conditions for the lawful processing of personal information or meet the functional equivalent standard of lawful processing of personal information. A code must also include, but is not limited to, governance and administrative provisions in these guidelines as applicable to specific relevant bodies. 1.8 In deciding whether to issue a code, the Regulator will consider whether a code meets the requirements set out in Chapter 7 of POPIA and the requirements set out in these guidelines. 1.9 The guidelines encourage different sectors to develop codes within an established framework and harmonise the code with POPIA. 2 Objectives of the guidelines 2.1 The objective of these guidelines is to serve as an explanatory aid to Chapter 7 of POPIA. 2.2 These guidelines will further serve as a practical guide that outlines minimum criteria and provides a framework to ensure that codes are evaluated in a standard manner. This will foster transparency relating to requirements and processes that will enable the approval of codes. 3 Definitions Any term used in these guidelines would bear the same meaning as in POPIA unless the contrary is indicated in these guidelines. 3.1 “Annually” means calendar year which runs from the date on which the code was issued; 3.2 ‘‘Automated means’’ for the purposes of these guidelines, means any equipment capable of operating automatically in response to instructions given for the purpose of processing information; 3.3 ‘‘Body’’ means public or private body as defined in POPIA; 3.4 ‘‘Code of conduct’’ means a code of conduct issued in terms of Chapter 7 of POPIA; 3.5 ‘‘Constitution’’ means the Constitution of the Republic of South Africa, 1996; 3.6 “Data subject’’ means the person to whom personal information relates; 3.7 ‘‘Information matching programme’’ means the comparison, whether manually or by means of any electronic or other device, of any document that contains personal information about ten or more data subjects with one or more documents that contain personal information of ten or more data subjects, for the purpose of producing or verifying information that may be used for the purpose of taking any action regarding an identifiable data subject; 3.8 ‘‘Person’’ means a natural person or a juristic person; 3.9 ‘‘Personal information’’ means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to– (a) information relating to the race, gender, sex, pregnancy, marital status, national, ethnic, or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language, and birth of the person; (b) information relating to the education or the medical, financial, criminal or employment history of the person; (c) any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier, or other assignment to the person; (d) the biometric information of the person; (e) the personal opinions, views, or preferences of the person; (f) correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence; (g) the views or opinions of another individual about the person; and (h) the name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person; 3.10 ‘‘Prescribed’’ means prescribed by regulation or by a code of conduct; 3.11 ‘‘Regulator’’ means the Information Regulator established in terms of section 39 of POPIA; 3.12 ‘‘Regulations’’ means Regulations made in terms of Section 112(2) of POPIA; 3.13 ‘‘Relevant body/bodies’’ refers to any specified body or class of bodies, or any specified industry, profession, or vocation or class of industries, professions, or vocations that in the opinion of the Regulator which has sufficient representation; 3.14 ‘‘Relevant stakeholders’’ means stakeholders, affected stakeholders or a body representing such stakeholders. 3.15 ‘‘Republic’’ means the Republic of South Africa; and 3.16 ‘‘Responsible party’’ means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information. 4 Who should use these guidelines These guidelines should be used by: 4.1 relevant bodies that are considering developing a code for approval; 4.2 stakeholders considering a proposed code developed by a relevant body; 4.3 stakeholders and relevant bodies in considering a proposed code developed on the Regulator’s own initiative; and 4.4 the Regulator in developing a code on its own initiative. 5 Purpose of these guidelines The primary purpose of these guidelines is to outline how all the conditions for the lawful processing of personal information are to be applied or complied with by relevant bodies. These guidelines: 5.1 assist relevant bodies to decide whether it is appropriate for them to develop a code; 5.2 clarify when the Regulator will develop a code on its own initiative or when relevant bodies may develop a code; 5.3 provide for stakeholder consultations when a code is being considered; 5.4 outline matters that need to be addressed in the issuing and registration of approved codes; 5.5 clarify when notifications will be issued by the Regulator on the availability of a proposed code for inspection; 5.6 outline the procedures that may be prescribed in a code for dealing with complaints; 5.7 outline matters relating to the reviewing, amendment, or revocation of an issued code; 5.8 apply to any specified personal information or class of personal information, activities, industry, profession or vocation, or class of industries, professions, or vocations that in the opinion of the Regulator has sufficient representation; 5.9 afford an opportunity to develop a framework that will support the lawful application of POPIA in a transparent and cost-effective manner; 5.10 foster the lawful and reasonable processing of personal information in accordance with POPIA which is beneficial to all sectors, encompassing the needs and rights of relevant bodies and data subjects; 5.11 assist relevant bodies that process personal information to comply with POPIA; 5.12 encourage relevant bodies, when developing a code, to ensure that such code builds trust amongst data subjects and stimulates transparent processing of personal information; and 5.13 create the opportunity to develop best practices and ultimately attain improved compliance with POPIA. 6 Reasons for developing a code of conduct The reason for developing a code may include: 6.1 providing clarity on how the conditions for lawful processing of personal information are to be applied and complied with given the features of a relevant body; 6.2 providing a functionally equivalent means of fulfilling the obligations related to the conditions for the lawful processing of personal information; 6.3 promoting an organisational paradigm shift in a relevant body relating to the lawful processing of personal information; 6.4 stipulating conditions for the lawful processing of personal information for any specified information or classes of information; 6.5 stipulating conditions for the lawful processing of personal information for any specified activity or class of activities; 6.6 outlining rules and procedures for information matching programmes if such programmes are used within a specific sector; 6.7 outlining how the legitimate interests of data subjects are to be protected insofar as automated decision making affect them; 6.8 providing details regarding the expiry of a code; and 6.9 providing a procedure of dealing with complaints. 7 Criteria for developing a code of conduct In deciding to develop a code, relevant bodies should consider the following: 7.1 whether the relevant bodies that will be bound by a code meet the resource requirements set out in par 10 below; and 7.2 whether POPIA, the Regulations or an issued code already cover the same matters which may negate the need to develop a code. 8 Understanding of POPIA A relevant body that is considering the development of a code must understand POPIA, in particular the application of the conditions for the lawful processing of personal information. 9 Administrative mechanisms A relevant body which is considering developing a code should have adequate administrative capacity to develop a code. This may include the establishment of a code development committee or some other administrative mechanism to manage the development of a code. The mechanism should include consultations with relevant stakeholders. 10 Resource requirements A relevant body should ensure that it has sufficient resources for the development and implementation of a code. Resources may need to be allocated for: 10.1 investigating the need for the development for a code; 10.2 establishing an administrative mechanism responsible for developing a code; 10.3 drafting and scoping of a code; 10.4 seeking legal or professional advice; 10.5 involving stakeholders in effective consultations on the draft code; 10.6 obtaining the necessary authorisation; 10.7 establishing sufficient representation; 10.8 establishing a body to oversee the operation of a code and reporting on its operation; 10.9 establishing a procedure for the making and dealing with complaints if any; and 10.10 maintaining information about a code on the website, including a list of relevant bodies bound by a code. 11 Notice of intention to develop a code of conduct 11.1 A relevant body should notify the Regulator of its intention to develop a code and keep the Regulator informed throughout the process of the development of a code. 12 Code of conduct requirements under POPIA 12.1 POPIA sets out the minimum requirements to be included in a code and how a code should apply. 12.2 Any failure to comply with an issued code is deemed to be a breach of the conditions for the lawful processing of personal information. 12.3 A code should limit itself to provisions which outline the specific obligations of relevant bodies bound by a code and any mandatory requirements under POPIA; 12.4 Any matters unrelated to the conditions for the lawful processing of personal information should not form part of a code to be approved by the Regulator. 12.5 A code does not replace the relevant provisions of POPIA. PART 2 – ISSUING OF A CODE OF CONDUCT BY THE INFORMATION REGULATOR (Regulator) The Regulator may from time to time issue a code on its own initiative or on application in the prescribed manner and form as contained in Regulation 5 and Form 3. 13 General principles applicable to issuing of a code of conduct 13.1 A code of conduct must: 13.1.1 be in writing; 13.1.2 incorporate all the conditions for the lawful processing of personal information or set out obligations that provide a functional equivalent of all the obligations set out in those conditions; and 13.1.3 prescribe how the conditions for the lawful processing of personal information are to be applied or complied with, given the features of the sector or sectors in society in which the relevant responsible parties are operating. 13.2 A code may apply to any one or more of the following: 13.2.1 any specified information or class of information; 13.2.2 any specified body or class of bodies; 13.2.3 any specified activity or class of activities; or 13.2.4 any specified industry, profession, or vocation or class of industries, professions, or vocations. 13.3 A code must also specify appropriate measures: 13.3.1 for information matching programmes if such programmes are used within a specific sector; 13.3.2 for protecting the legitimate interests of data subjects insofar as automated decision making is concerned; 13.3.3 to provide for the review of the code by the regulator; and 13.3.4 to provide for the expiry of the code within a minimum five (5) year period. 14 Other matters that may be included in a code of conduct 14.1 A code may: 14.1.1 provide for exemptions granted by the Regulator; 14.1.2 consider a process for dealing with complaints by all relevant bodies bound by a code and provide for the reporting to the Regulator about those complaints; and 14.1.3 provide for the reporting of and deal with any other matters relating to the processing of personal information provided for in POPIA. 15 Drafting style 15.1 The Regulator and affected stakeholders must be able to easily understand and interpret a code. 15.2 Codes should be written in plain English language that is clear and concise. 15.3 The code may be translated in any other two official languages as determined by the relevant body. 15.4 The obligations should be set out in a code in a logical order. For example, the conditions for the lawful processing of personal information should be aligned with the heading of each condition and in the order in which they appear in POPIA. 16 Process for issuing of code of conduct The Regulator may issue a code of conduct after consultation with relevant stakeholders or on application by relevant bodies. The period of consultations with relevant stakeholders should not be less than 30 days. 16.1 Codes issued by the Regulator on own initiative 16.1.1 The Regulator may issue a code of conduct on own initiative after consultation with relevant stakeholders. 16.1.2 The consultation with the relevant stakeholders may take the following forms: 16.1.2.1 a notice in the Gazette that the issuing of a code is being considered; 16.1.2.2 a draft of a code made publicly available, for example on the Regulator’s website; or 16.1.2.3 an invitation to the public to make written submissions to the Regulator within specified period. 16.1.2.4 the Regulator must consider any submissions made within the specified period. 16.1.3 When conducting a consultation, the Regulator must ensure that participation in the consultation is accessible to all affected persons. 16.1.4 Consideration will be given to the comments raised by the affected persons and stakeholders consulted. 16.2 Codes issued by the Regulator on application by relevant bodies The Regulator may also issue a code of conduct on application by relevant bodies. 16.2.1 The application for the issuing of a code must be made in the form and manner prescribed by the Regulator in the Regulations. 16.2.2 The application must amongst others be accompanied by the following documentation: 16.2.2.1 a copy of the proposed or draft code being applied for; 16.2.2.2 submissions received during consultations; 16.2.2.3 the period that the proposed code was available for consultation; 16.2.2.4 the relevant bodies which will be affected by the code; 16.2.2.5 the methods that were employed by the relevant body to consult with relevant stakeholders; 16.2.2.6 a list of relevant stakeholders, relevant bodies and affected persons who made submissions to the code; 16.2.2.7 details of the changes made to a code following consultations; 16.2.2.8 a summary of issues received through the consultation with relevant stakeholders, relevant bodies, and affected persons; and 16.2.2.9 reasons why a particular submission was not incorporated into the final document. 16.2.3 A statement of consultation with the application to issue a code should contain the following details: 16.2.3.1 a copy of the explanatory material that has been prepared in relation to the code; 16.2.3.2 if all the requirements in these guidelines are not met, reasons as to why those requirements have not been met or why they are not relevant; and 16.2.3.3 any other material document or information that may be relevant to the Regulator’s decision to issue a code. 16.2.4 The Regulator must acknowledge receipt of the application within a reasonable time which should not exceed a period of 14 days. 16.2.5 The decision of the Regulator on the application to issue a code of conduct must be made in a reasonable time that does not exceed 13 weeks from the date of publication of the notice in the Gazette. 17 Openness and transparency 17.1 In line with an issued code of conduct a member of a relevant body must develop policies on how personal information is managed. This includes information about how a data subject may complain about a breach of the conditions for the lawful processing of personal information, and how the relevant body will deal with such a complaint. 17.2 These policies must be made easily available on the website of a member of a relevant body. Hard copies must be made available where necessary. 18 Notice of consideration for a code of conduct The Regulator must: 18.1 give notice in the Gazette that the issuing of a code is being considered. 18.2 The said notice must contain a statement that: 18.2.1 the proposed code of conduct being considered and a copy thereof may be obtained from the Regulator, and 18.2.2 written submissions on the proposed code may be submitted to the Regulator within a period specified in the notice. 18.3 The Regulator may not issue the code of conduct unless it has considered all the submissions made and is satisfied that all affected persons have been given a reasonable opportunity to make submissions. 18.4 The appropriate way to bring a code to the attention of affected persons will depend on the circumstances of each case, but may include: 18.4.1 placing a code or information about a code on the website of the Regulator; 18.4.2 public notices in newspapers or industry publications; 18.4.3 direct engagement with relevant stakeholders and relevant bodies; or 18.4.4 consultation with relevant Regulators to assess any other legal issues associated with a code. 19 Notification 19.1 The Regulator will notify relevant bodies of a decision to issue a code in writing. The decision will include the date when the issuing of a code will take effect. Upon issuing of a code the Regulator will publish an explanatory statement outlining the reasons for approving a code. 19.2 The Regulator will also notify relevant bodies of a decision not to issue a code and the notice will include reasons for such decision. 19.3 The Regulator will publish, within 30 days of its decision to issue a code, a notice in the Gazette that a code has been issued. 19.4 The Regulator will publish a notice within 30 days of its decision to issue a code on its website and/or by any other means. 20 Register for approved codes of conduct 20.1 The Regulator must keep a register of approved codes. Where the Regulator approves a variation to a code, the register will include the relevant code as varied. The register will not include any code that the Regulator has removed from the register. 20.2 The register, including the full content of any approved code will be made publicly available on the website of the Regulator. PART 3 – CODE GOVERNANCE 21 Governance arrangements 21.1 POPIA does not state how a code should be administered. However, there are several matters regarding governance arrangements in a code to consider when deciding whether to develop a code. 21.2 The Regulator will consider the governance arrangements in a code upon receiving an application for registration of a code. 22 Bodies bound by a code of conduct 22.1 A code must clearly state the relevant bodies that are bound by a code, or establish a way of identifying the relevant bodies bound by a code. 22.2 Once a code has been issued it is in force and legally binding on relevant bodies. 23 Identifying relevant bodies bound by a code of conduct 23.1 A code must identify the bodies which are bound by a code, for example by listing the affected bodies in a code itself. 23.2 If any of the bodies are subject to more than one code, each code must list the bodies which are bound by that code. 23.3 Failure to clearly identify bodies bound by a code, either through listing the bodies that will be bound or by clearly describing the way in which bodies bound by a code can be identified, may constitute a reason not to issue a code or to remove a code from the register of approved codes. 24 Monitoring compliance with a code of conduct 24.1 The Regulator should, put mechanisms in place to monitor the effectiveness of a code in achieving compliance. 24.2 Relevant bodies must have processes in place that outline how complaints or enquiries from data subjects will be handled. 24.3 Relevant bodies must assess compliance with the code. 25 Reporting on compliance with a code of conduct 25.1 The relevant bodies should submit an annual report to the Regulator which should also be made available on the relevant body’s website. 25.2 The annual report must be submitted one (1) year after a code has been issued by the Regulator. 25.3 The report should include the following: 25.3.1 accurate, up to date and sufficient information on how a body has monitored compliance with a code. This includes information received in reports from bodies bound by a code and from assessments or investigations; 25.3.2 aggregate information about systemic issues or serious or repeated interference with the conditions for the lawful processing of personal information that occurred during the reporting period; 25.3.3 if information regarding the effectiveness of a code in achieving compliance has significantly changed from the last report, a description of the change and any proposed process or practice to address the change; 25.3.4 the number of complaints in relation to a code received annually; 25.3.5 the average time taken to resolve the complaints; 25.3.6 statistical information about the nature of the complaints; 25.3.7 statistical information about the outcomes of the complaints; and 25.3.8 information about the remedies awarded in resolving the complaint. 25.4 If the reports are not provided to the Regulator or they indicate a lack of compliance with a code, this shall inform a decision by the Regulator to review, vary or revoke a code. 25.5 The relevant bodies bound by a code should also report systemic issues or serious violations of a code to the Regulator as soon as they become aware of them. 25.6 A code of conduct may prescribe procedures for making and dealing with complaints alleging a breach of a code. 25.7 If a code sets out procedures for making and dealing with complaints the Regulator must be satisfied that a code meets the standards prescribed by the Regulator and these guidelines. PART 4 – COMPLAINTS HANDLING 26 Purpose of a complaints handling procedure 26.1 The purpose of a complaints handling procedure is to: 26.1.1 ensure that the prescribed standard procedure is complied with; 26.1.2 ensure that complainants are aware of the procedure that will be utilised in handling complaints; 26.1.3 ensure that the procedure is fair, transparent, impartial and responsive; 26.1.4 enable the expedient resolution of complaints; 26.1.5 promote effective decision making; 26.1.6 ensure that complaints are first raised with the responsible party that has allegedly compromised personal information. 26.1.7 ensure that the responsible party is afforded the opportunity to respond to the complaint; 26.1.8 ensure that the data subject who is aggrieved by the decision of the responsible party submits the complaint to an independent adjudicator; and 26.1.9 ensure that the responsible party or data subject who is aggrieved by the decision of the independent adjudicator submits the complaint to the Regulator. 26.2 The complaint can be escalated directly to the Regulator in instances where the complaint warrants the attention of the Regulator, including and not limited to the following circumstances: 26.2.1 the complainant will be disadvantaged if the complaint is directed to the responsible party directly; 26.2.2 a systemic violation of the protection of personal information has occurred; 26.2.3 the responsible party has a history of habitual violation of the protection of personal information; 26.2.4 complainants represent a class of individuals against the same responsible party; or 26.2.5 the complaints arise out of similar circumstances and there is a common issue of law or fact. 27 Who may submit a complaint? 27.1 a data subject; 27.2 a person acting on behalf of a data subject; 27.3 a competent person acting on behalf of a minor; 27.4 a relevant person appointed by a court of law to manage the affairs of a data subject; or 27.5 a responsible party or a data subject who is aggrieved by the decision of the independent adjudicator. 28 The complaints process 28.1 A code of conduct may prescribe procedures for making and dealing with complaints alleging a breach of a code without limiting or restricting the provisions of Chapter 10 of POPIA. 28.2 Once a code issued under Section 60 of POPIA is in force, failure to comply with such a code is deemed to be a breach of the conditions for the lawful processing of personal information referred to in Chapter 3 of POPIA and dealt with in terms of Chapter 10 of POPIA. 28.3 If a code sets out procedures for making and dealing with complaints the Regulator must be satisfied that the code meets the prescribed standards in line with POPIA and the guidelines issued by the Regulator in terms of Section 65 of POPIA. 28.4 If a code sets out procedures for making and dealing with complaints, the code must provide for the appointment of an independent adjudicator by the relevant body with whom the complaints may be lodged. 28.5 A code must provide for the details of the independent adjudicator. 28.6 A responsible party or data subject who is aggrieved by a determination, including any declaration, order or direction that is included in the determination, made by an adjudicator after having investigated a complaint relating to the protection of personal information under an approved code of conduct, may submit a complaint in terms of section 74(2) with the Regulator, against the determination upon payment of a prescribed fee. 29 Responsibilities of the Independent Adjudicator 29.1 The adjudicator when exercising his/her powers must have due regard to Section 44 of POPIA. 29.2 The adjudicator must utilise a process that is impartial, accessible, flexible, and efficient and must also observe the principles of natural justice and procedural fairness. 29.3 The adjudicator must prepare and submit a report, in a form satisfactory to the Regulator, within five (5) months of the end of a financial year of the Regulator on the operation of a code during that financial year. The financial year end of the Regulator is the 31st of March of each year. 29.4 The annual report must specify the number and nature of complaints made to an adjudicator under a code during the relevant financial year. 29.5 The adjudicator’s determination continues to have effect unless and until the Regulator makes a determination under Chapter 10 of POPIA relating to the complaint or unless the Regulator determines otherwise. PART 5 – REVIEWING, VARYING AND REVOCATION OF AN APPROVED CODE OF CONDUCT 30 Review of the operation of an approved code of conduct 30.1 The Regulator may on its own initiative review the operation of an approved code within a five (5) year period or as and when deemed necessary. 30.2 The review may occur when the Regulator becomes aware of, amongst others, the following: 30.2.1 a change in industry practices, technology or expectations of affected persons that may impact the effective operation of a code; or 30.2.2 the lack of compliance with an approved code. 30.3 The Regulator will notify the relevant body in writing of the decision to review the code. The Regulator will undertake a consultation during the review process. 30.4 If the Regulator decides to review an approved code, the Regulator must publish a notice of the review on its website requesting comments from affected persons. 30.5 The outcome of the review of a code may inform a decision by the Regulator to revoke an approved code. 31 Variations to an approved code of conduct 31.1 The Regulator may approve, in writing, a variation of an approved code. A variation may occur: 31.1.1 when a relevant body bound by the approved code applies for variation; or 31.1.2 on the Regulator’s own initiative. 31.2 Where the Regulator decides to vary an approved code on its own initiative, the variation cannot include provisions that deal with exemptions. 31.3 Before deciding whether to approve a variation, the Regulator may undertake a consultation which may include: 31.3.1 making available a copy of the variation sought on the Regulator’s website; 31.3.2 consulting any affected persons the Regulator considers appropriate for the variation sought; and 31.3.3 publish a notice of the variation sought in the Gazette. 31.4 In deciding whether to consult regarding a variation, the Regulator may consider the extent to which relevant bodies bound by a code and affected persons have been afforded the opportunity to comment on the variation. 31.5 In deciding whether to approve a variation, the Regulator will consider the matters specified in these guidelines. The decision will be informed by whether the proposed variation effectively addresses the issues it seeks to resolve. 31.6 If the Regulator decides to vary an approved code, the Regulator must: 31.6.1 notify the relevant body of its decision including the date on which the variation will occur; 31.6.2 publish a notice of the variation on the Regulator’s website. The variation must be published as soon as practicably possible to ensure that relevant bodies have sufficient time to implement same; 31.6.3 add the varied code to the register and remove the original approved code from the register; and 31.6.4 publish a notice on the Regulator’s website and in the Gazette stating that the original approved code has been varied. 31.7 The relevant body must publish the varied code on its website within 14 days from the date of publication of the varied code in the Gazette. 32 The form and manner of the application to vary an approved code of conduct 32.1 An application to vary an approved code must take the form of a letter addressed to the Regulator setting out the following: 32.1.1 the title of the approved code; 32.1.2 the name of the relevant body bound by the code that is applying for variation; 32.1.3 the details of the proposed variation; 32.1.4 the reasons for the variation; 32.1.5 any potential consequences resulting from the variation, including the impact on relevant bodies bound by the approved code; and 32.1.6 details of any consultation carried out with relevant bodies bound by the approved code along with other affected stakeholders. 32.2 The application must also include: 32.2.1 a copy of the proposed variation clearly marked on the current approved code. 32.2.2 submissions received on any consultation undertaken on the variation; and 32.2.3 if all the requirements in these guidelines are not met, a statement explaining why those requirements have not been met or why they are not relevant, and any other material that may be relevant to assist the Regulator’s decision to issue a code as varied. 33 Revocation of an approved code of conduct 33.1 The Regulator may revoke an approved code and thereafter remove from the register. In deciding whether to revoke an approved code, the Regulator will consider the following: 33.1.1 a change in industry practices, technology or expectations of affected persons that may impact the effective operation of a code; or 33.1.2 the lack of compliance with an approved code. 33.2 The Regulator may revoke an approved code: 33.2.1 on application by one or more relevant bodies representing one or more bodies bound by a code; 33.2.2 on application of any relevant body bound by a code; or 33.2.3 on the Regulator’s own initiative. 33.3 In revoking an approved code, the Regulator will undertake a consultation in a similar process as for a variation of an approved code. 33.4 If an approved code is revoked, the Regulator must: 33.4.1 notify the relevant body that applied for the revocation of the decision to revoke the approved code, including the date of the revocation; 33.4.2 publish a notice relating to the revocation of the approved code on the Regulator’s website and in the Gazette; and 33.4.3 remove the approved code from the register. 34 The form and manner of the application to revoke an approved code of conduct 34.1 An application to revoke an approved code must take the form of a letter addressed to the Regulator setting out the following: 34.1.1 the title of the relevant approved code; 34.1.2 the name of the relevant body bound by the code, or the industry representing one or more of the relevant bodies bound by the code, that is applying for revocation; 34.1.3 the reasons for the revocation; 34.1.4 any potential consequences resulting from the revocation, including the impact on relevant bodies bound by the approved code; 34.1.5 details of any consultation carried out with relevant bodies bound by the approved code along with other relevant stakeholders; 34.1.6 any submissions received during the consultation on revocation of the code; and 34.1.7 if these submissions were not considered, the reasons thereto must be provided. 35 Review Any person has the right to review the decision of the Regulator to approve, vary or revoke a code in the High Court having jurisdiction.