Duties and responsibilities of Information Officer
(1) An information officer's responsibilities include, (a) the encouragement of compliance, by the body, with the conditions for the lawful processing of personal information; (b) dealing with requests made to the body pursuant to this Act; (c) working with the Regulator in relation to investigations conducted pursuant to Chapter 6 in relation to the body; (d) otherwise ensuring compliance by the body with the provisions of this Act; and (e) as may be prescribed.
(2) Officers must take up their duties in terms of this Act only after the responsible party has registered them with the Regulator.
What this means for your estate
- Someone must be formally appointed and registered with the Regulator before they can lawfully act as your estate's Information Officer (subsection (2)), a title on an org chart isn't enough.
- The role isn't just “answer POPIA requests when they come in”, subsection (1) makes the IO responsible for actively encouraging conditions-for-processing compliance across the whole scheme, not just reacting to complaints.
- If the Regulator ever investigates your estate under Chapter 6, the IO is the person expected to work directly with them, make sure whoever holds this role actually has the standing and time to do it.
PopiGuard tracks Information Officer registration and the day-to-day duties s.55 assigns them, so the role is documented, not just appointed.
There's a formal step: section 55(2) requires the responsible party to register its Information Officer with the Regulator before that person may take up their POPIA duties, an internal title alone isn't sufficient.
Section 55(1) lists five duties: encouraging the body's compliance with the lawful-processing conditions, handling POPIA-related requests, working with the Regulator on Chapter 6 investigations, ensuring the body's overall compliance, and any further prescribed duties.