SciELO - Scientific Electronic Library Online

 
vol.32 issue1A survey of automated financial statement fraud detection with relevance to the South African context author indexsubject indexarticles search
Home Pagealphabetic serial listing  

Services on Demand

Article

Indicators

Related links

  • On index processCited by Google
  • On index processSimilars in Google

Share


South African Computer Journal

On-line version ISSN 2313-7835
Print version ISSN 1015-7999

Abstract

ZENDA, Benson; VORSTER, Ruthea  and  VIEGA, Adele Da. Protection of personal information: An experiment involving data value chains and the use of personal information for marketing purposes in South Africa. SACJ [online]. 2020, vol.32, n.1, pp.113-132. ISSN 2313-7835.  http://dx.doi.org/10.18489/sacj.v32i1.712.

South Africa enacted the Protection of Personal Information Act 4 of 2013 (POPI) in an effort to curb the misuse of customers' personal information by organisations. The aim of this research was to establish whether the South African insurance industry is adhering to certain prescripts of POPI, focusing on direct marketing requirements. An experiment was utilised to monitor the flow of personal information submitted to 20 insurance companies requesting short-term insurance quotations, using new e-mail addresses and phone numbers. The results of the experiment indicate that 92% of the marketing communication received did not have prior consent from the researcher. Contact was made by companies outside the sample, indicating third-party sharing. 86% of the unsolicited short message service (SMS) communication received required customers to pay for unsubscribing from SMSs, which is not in line with regulatory requirements. The non-compliance evident in this experiment acts as an early warning to the insurance industry and South Africa, prompting a more concerted effort towards preparation of compliance with POPI. A personal information processing management framework is proposed to aid the insurance industry in understanding how personal information can be processed in line with the requirements of the Act.CATEGORIES: Security and privacy ~ Privacy protections

Keywords : direct marketing; personal information; privacy; Protection of Personal Information Act (POPIA); privacy framework; personal information processing management framework (PIPMF).

        · text in English     · English ( pdf )

 

Creative Commons License All the contents of this journal, except where otherwise noted, is licensed under a Creative Commons Attribution License