The protection and management of data, and especially personal information, is becoming an issue of critical importance in both the business environment and in general society. Various institutions have justifiable reasons to gather the personal information of individuals but they are required to comply with any legislation involving the processing of such data. Organisations thus face legal and other repercussions should personal information be breached or treated negligently. Most countries have adopted privacy and data protection laws or are in the process of enacting such laws. In South Africa, the Protection of Privacy Information Act (POPIA) was formally adopted in 2013 but it is yet to be implemented. When the implementation of the Act is announced, role players (responsible parties and data subjects) affected by POPIA will have a grace period of a year to become compliant and/or understand how the Act will affect them. One example of a mandate that follows from POPIA is data breach notification. This paper presents the development of a prototype ontology on POPIA to promote transparency and education of affected data subjects and organisations including government departments. The ontology provides a semantic representation of a knowledge base for the regulations in the POPIA and how it affects these role players. The POPIA is closely aligned with the European Union’s General Data Protection Regulation (GDPR), and the POPIA ontology is inspired by similar ontologies developed for the GDPR.
Reference:
Jafta, Y., Leenen, L. and Chan, K.F.P. 2020. An ontology for the South African Protection of Personal Information Act. Proceedings of the 19th European Conference on Cyber Warfare and Security, a Virtual Conference Hosted by the University of Chester, United Kingdom, 25-26 June 2020, pp 158-166.
Jafta, Y., Leenen, L., & Chan, K. F. P. (2020). An ontology for the South African Protection of Personal Information Act. ACPIL. http://hdl.handle.net/10204/11711
Jafta, Y, L Leenen, and Ka Fai P Chan. "An ontology for the South African Protection of Personal Information Act." (2020): http://hdl.handle.net/10204/11711
Jafta Y, Leenen L, Chan KFP, An ontology for the South African Protection of Personal Information Act; ACPIL; 2020. http://hdl.handle.net/10204/11711 .