Processing subject to prior authorisation
(1) The responsible party must obtain prior authorisation from the Regulator, in terms of section 58, prior to any processing if that responsible party plans to— (a) process any unique identifiers of data subjects— (i) for a purpose other than the one for which the identifier was specifically intended at collection; and (ii) with the aim of linking the information together with information processed by other responsible parties; (b) process information on criminal behaviour or on unlawful or objectionable conduct on behalf of third parties; (c) process information for the purposes of credit reporting; or (d) transfer special personal information, as referred to in section 26, or the personal information of children as referred to in section 34, to a third party in a foreign country that does not provide an adequate level of protection for the processing of personal information as referred to in section 72.
(2) The provisions of subsection (1) may be applied by the Regulator to other types of information processing by law or regulation if such processing carries a particular risk for the legitimate interests of the data subject.
(3) This section and section 58 are not applicable if a code of conduct has been issued and has come into force in terms of Chapter 7 in a specific sector or sectors of society.
(4) A responsible party must obtain prior authorisation as referred to in subsection (1) only once and not each time that personal information is received or processed, except where the processing departs from that which has been authorised in accordance with the provisions of subsection (1).
What this means for your estate
- This only bites on four specific high-risk activities (subsection (1)(a)-(d)), linking unique identifiers across responsible parties, processing criminal-behaviour/unlawful-conduct data on behalf of third parties, credit reporting, and transferring special/children's information to an inadequately-protected foreign country. Ordinary estate administration (visitor logs, levy records, CCTV) doesn't trigger it.
- Subsection (4) means this is a once-off gate, not a per-transaction one, once the Regulator has authorised the specific processing, you don't re-apply each time, unless the processing later departs from what was authorised.
- Subsection (3) is the escape hatch: if your sector already has an approved code of conduct in force under Chapter 7, prior authorisation under this section and s.58 falls away for that sector.
PopiGuard's risk screening flags the rare estate activity that actually needs prior authorisation, rather than leaving you to guess from the Act's text alone.