CISA
2 CPD points
6 modules
This course can be customised to align with your organisation’s privacy policy, internal procedures, information officer details, consent approach, cross-border transfer rules, breach reporting process and data-handling practices.
For employees who only need a shorter POPIA overview, POPIA in a Nutshell may be the better fit. For more comprehensive POPIA awareness, ask about POPIA General Awareness. For IT teams and technical professionals, POPIA for IT focuses more specifically on systems, security and information handling.
overview
Understand POPIA where privacy crosses borders
POPIA regulates how South African public and private bodies process personal information. The Information Regulator monitors and enforces compliance and may investigate complaints, conduct assessments, issue enforcement notices and impose significant administrative fines where organisations fail to comply. The Information Regulator has already used these enforcement powers in practice.
Employees are involved whenever personal information is collected, accessed, used, corrected, retained, shared, secured or transferred. Their awareness therefore forms part of the organisation’s wider privacy controls, particularly where information moves between teams, service providers, group companies or countries.
South African employees may also encounter GDPR terminology in international contracts, group policies and client requirements. This course explains POPIA with relevant GDPR reference points, helping learners understand the South African rules that govern their work without treating the two legal regimes as interchangeable.
The course
Apply POPIA principles to information handling
The course introduce POPIA and deals with purposeful, transparent, authorised, accurate and secure processing.
Learners examine defined processing purposes, further processing, access to personal information, consent, prior authorisation, cross-border transfers, data quality, retention, reasonable security measures, security breaches and notification responsibilities.
Scenario-based examples connect these requirements to the ways employees may collect, use, share, store and transfer personal information at work.
POPIA remains the principal legal framework covered, with GDPR used to provide context where organisations face wider international privacy expectations.
The privacy risk
Personal information does not stop being the organisation’s responsibility when it moves to another team, supplier or country.
Course distinction
POPIA first, with GDPR in context
GDPR does not automatically apply to every South African organisation that handles information internationally. Its territorial reach depends on specific circumstances, including whether an organisation has an establishment in the European Union or conducts certain activities involving people in the Union.
POPIA separately regulates transfers of personal information from South Africa to recipients in foreign countries. Section 72 of POPIA sets conditions for these transfers.
The value of this course is the combination of substantive POPIA awareness and enough GDPR context to help employees understand international privacy language and recognise when a question should be escalated for specialist guidance.
Help employees understand POPIA where privacy responsibilities cross borders.
The course is suitable for employees and managers who collect, use, store, share, secure or otherwise work with personal information. It is particularly relevant to organisations with international clients, multinational group structures, cross-border information flows or privacy requirements influenced by GDPR.
This course provides substantive POPIA awareness together with GDPR reference points. POPIA in a Nutshell is the shorter introductory option, POPIA General Awareness provides broader South African privacy awareness, and POPIA for IT focuses on the responsibilities associated with systems, security and technical information handling.
No. It is a POPIA course that refers to GDPR where broader privacy principles and international information handling are relevant. It should not be used as a substitute for specialist GDPR legal advice, professional training or a GDPR compliance programme.
No. GDPR applicability depends on the organisation’s circumstances and the territorial-scope rules in Article 3. Having an overseas client, using GDPR language in a contract or transferring information internationally does not, by itself, settle whether GDPR applies.
GDPR is often used as a reference point in privacy policies, group standards, supplier requirements, client contracts and international data protection discussions. Employees may not need a full GDPR course, but they may need to understand why GDPR language appears in POPIA-related work. This course helps employees understand POPIA first, with GDPR context where broader privacy expectations or cross-border information handling matter.
POPIA and GDPR training should not be treated as a once-off exercise where employees continue to handle personal information. Refresher training is useful when employees join, change roles, work with new systems, handle new categories of information, or need to revisit updated privacy procedures. The right frequency depends on the organisation’s processing activities, risk exposure and internal compliance approach.
e-learning library
Related courses
These employee awareness topics may also be relevant to your industry.
Fill in your details below to receive a quote.