Ross Saunders — Data Security And Privacy, Identity Theft and the new POPIA Act
With Ross Saunders — Data Privacy and the big WhatsApp conspiracy
In short
Ross Saunders explains what South Africa's Protection of Personal Information Act means for businesses from 1 July 2020, with a year to comply by 30 June 2021. He covers the eight principles, the shift from opt-out to opt-in mailing lists, special personal information, how breaches and phishing actually happen, and why individuals hand over too much data.
How did Ross Saunders end up working in data privacy?
Two events pushed him into it after roughly 20 years in IT. While in management he handled a data breach at a company he worked with, and around the same time his own identity was stolen — a two-year process to recover, which built his passion for data privacy.
What actually happens when your identity is stolen?
His ID book was never physically stolen; someone created a false one and opened accounts everywhere. Clothing accounts, multiple cell phones, tablets and computers were taken out in his name, with SMS notifications of new debit orders arriving, and it took a good year or two to repair his credit rating through heavy red tape.
When does POPIA actually come into force, after all the delays?
The presidency announced enforcement from 1 July, with businesses given until 30 June 2021 to align. The law first arrived in 2013, and after regulations published in December 2018, calls from the regulator and the Department of Justice, and a missed 1 April date, many had developed what Ross calls POPIA fatigue.
Which businesses does POPIA affect?
Any business that deals with data, which effectively means every business. It covers marketing and everyday operations, and also employee information — processing a payroll counts as processing personal information and therefore requires compliance.
What are the eight principles of POPIA?
Accountability, specifying the purpose of data use, limiting processing, not using data for other purposes, keeping it up to date, having security in place, being open about collection, and allowing people to participate — for example removing themselves from a mailing list or asking where their information came from. They align closely with the OECD guidelines from the 1980s.
Does POPIA fix the problem of mailing lists you cannot escape?
Yes — the mechanism shifts from opt-out to opt-in. Previously anyone could be added provided an unsubscribe link sat at the bottom of the mailer; now someone must actively say they want the information, and companies need documented consent for everyone on the list. Those who ignore it risk the regulator and fines.
Does POPIA cover paper files, not just digital data?
Yes. Information includes files, notes and notebooks — in Europe anything forming part of a filing system, paper or not, is personal information. The security safeguards principle means an HR office holding group life forms, medical aid forms and bank details needs documented procedures, at minimum being locked when unattended.
Does POPIA apply to Google, Facebook and the government?
POPIA is a South African law applying to people and businesses within the borders, unlike the GDPR which applies extra-territorially — Google recently had a 50 million dollar fine upheld in the French courts. It does apply to government, and during Corona an independent judge was appointed to oversee tracking and tracing programmes.
How do most data breaches actually happen?
Mostly through negligence in a company, or targeted attacks in person — impersonating a lift technician, or as Ross puts it, a clipboard and a white coat gets you anywhere in a building. Phishing is the daily culprit, especially with remote work: someone takes over an email account and later requests a change of banking details.
Where should a small business start with compliance?
Take a risk-based approach and tackle the most difficult areas first rather than trying to do everything to the letter. Build awareness of what is required, then begin with policy — a privacy policy and a data protection policy. Ross offers training, courses, a 12-week programme and advisory consulting.
In their words
in the hacking space you just need a clipboard and a white coat and you can get anywhere in a building
a lot of the stuff that we see in in poppy and those eight principles, it's really just eight principles of doing good business.
risk-based approach, having that awareness of what's required of you, and then just starting, eat this elephant one bite at a time.
The fact that you're processing a payroll means you're processing information means that you need to comply with this regulation
Key takeaways
- POPIA's eight principles are largely eight principles of good business practice — accountability, security, openness and honesty about what data is used for.
- Compliance obligations extend to employee data, so anyone running a payroll is processing personal information.
- Mailing lists move from opt-out to opt-in, requiring documented consent for every subscriber.
- Personal information includes paper files and notes, meaning physical spaces such as an unlocked HR office are a compliance risk.
- Small pieces of data given away separately become dangerous when combined across multiple breaches into a profile.
- Information stolen now may only be used years later — Ross believes the data behind his identity theft was gathered three or four years beforehand.
Show notes
On this episode I chat with Ross about what data protection and privacy is, how the new act affects us and what can we do to ensure our data is kept private.
Frequently asked questions
What counts as special personal information?
Anything historically used, or usable, to discriminate: religion and philosophical beliefs, race and ethnic origin, trade union membership, political persuasion, health and sex life, criminal behaviour and biometrics. Overseas the category is expanding to include genetic information. It requires more control and consent.does llawful processing mean in practice?
What does lawful processing mean in practice?
Adhering to the principles: having a privacy policy and data protection policy, telling people why particular data is needed, only using it for the stated purpose, and not enriching other lists or selling it on. Consent, an employment contract or another legal requirement can each provide the lawful basis.
Why do those social media quizzes matter?
They gather data that can be used against you later. Ross describes a quiz asking what your surname would be if you took your mother's maiden name — the same detail long used as a password recovery question.
How would POPIA help South African companies doing business abroad?
The GDPR requires the country you deal with to have data protection laws, so South African software companies currently face model clauses and extra legal agreements. If POPIA receives an adequacy rating from the EU, many of those contracts fall away.
What does Ross do outside data privacy?
He enjoys advising people who have just moved from highly technical roles into management, having fumbled through that transition himself without a safety net. He also owns an Italian greyhound called Clio, who features heavily on Instagram.
Transcript
What's involved and a special guest second time on the show Which means you must have had a lot of value to add the first time around it is none other than Ross Saunders Ross you Welcome first of all Thank you for having me. It's good to be back Yeah, second time around Ross you are a speaker you're a consultant you're an advisor You're your whole gig What are you all about tell us a little bit in case somebody doesn't recognize the name Ross Saunders immediately? so from my side, I am a Specialist in the data privacy and cyber security space I've been a speaker and trainer in that space teaching companies about how data privacy works and cyber security works and hacking and all That kind of stuff But also consulting in that privacy space which is growing at a rapid rate with the legislations across the globe All right, fantastic now now tell me a little bit about About Ross how did you get into this whole data privacy thing? I mean on the one hand it sounds terrifying and on the other hand, it sounds like well, it'll never happen to me So what happened? How did you get there? Well, it happened to me
So I you know for a long time I've been in the IT space better part of 20 years and working from everything from your entry-level call desk working my way through networking got into programming went into management and while I was in management, I between two events actually I had a data breach that I was Dealing with at a company that that I worked with at the time, but then I also had my identity stolen around about the same time and that was a two-year process to get my identity back which bore this huge passion for Data privacy and making sure people take care of their stuff because I wouldn't wish either of those situations on anyone When you say somebody stole your your idea and it's a thing you hear about you peer on the news or you know There's these TV programs about it, etc, etc, but on the one end you go. Well, it can't be said that bad I mean, how did it impact you what actually happened when when they'd stolen your identity? I mean How does it impact you? I mean bank account what what happens? Yeah, well, I mean the one of the key things with it is is my ID book and things like that was actually not stolen I still am in possession of all of that, but someone fraudulently created a False ID book and things like that and they went around and started taking out accounts everywhere. So I had clothing accounts I had I don't know how many cell phones I had in my name tablets computers the whole shebang so I just kept getting SMS is saying that I've got a new debit order that's gone off and It was really a scary situation and it takes a good year two years to sort out your credit rating after that because you've Fraudulently taken out so much credit and there's so much red tape involved. It's just a it's a nightmare All right. So this is something and we touched on it briefly the last time we we chatted that South Africa is wanting to to deal with this this kind of thing and your personal information and security, etc, etc I believe it's called. Is it the Poppier Act?
Yes, so it was formerly known as the puppy act and it's still commonly known as that But that they have requested that we refer to it as Poppier. So the protection of personal information act All right. Now, what is what is that all about because I've heard about this before and it's it's been sort of one of those things For a couple of years now people going yeah. Yes protection of personal information act. It's coming. It's coming. It's coming. We're gonna do it So, where are we with Poppier? Well, so you say a couple of years it's more than a couple I was being polite in in 2013 the the law first came around and
Basically this law brings in a whole lot more protections for the consumer protection for businesses things like that when it comes to handling personal information, so 2013 it came about we've been waiting for it to be implemented And I think a lot of what we've seen is people have this this Poppier fatigue Because they've heard of it so many times and it's always been it's coming. It's coming. It's coming and every time we hear a date We end up as consultants as attorneys and all that advertising it and then we end up with egg on our faces when it doesn't come In but we got a little bit of hope in December 2018 when a number of the regulations got published December 2019 there was a call from the regulator to get things going March 2019 There was a call from the Department of Justice to say go ahead And then we were all set for April 1st, and then it kind of felt like a very bad April Fool's joke because the first came and went and no puppy But that that all changed now on Monday when the presidency announced that on July 1st, we'll have it enforced. So It's gonna be an exciting time All right. Now, what does that mean though? I mean, where are we now? It's gonna be enforced, you know And you've spoken about this this this poppy fatigue poppier fatigue But I mean enforced how when where what sort of you know How's it gonna impact me for example?
so the act itself has a number of provisions Stating how companies should be able should be looking after information Within their charge or what they've collected things like that now This a lot of people make the mistake thinking, you know Well, as long as you've asked for consent and you've got a privacy policy, you're good But the laws are a lot bigger than that So what they're enforcing as of the 1st of July is a number of the provisions that haven't been in place So there's eight principles to poppy and those are basically going to come in now Where you've got to adhere to those eight principles and you've got a year until the 30th of June 2021 To get your business in line with those principles
This is starting to sound a bit a bit ominous My business no, no, no when you say your business, what does this affect every kind of business? Any kind of business that deals with data. So basically that sums up every kind of business It's everything from your marketing to just your everyday day today And what we often often forget is also looking after your employees data The fact that you're processing a payroll means you're processing information means that you need to comply with this regulation
I'm getting nervous. Should I be nervous? Are you going to are you going to are you going to put my mind at ease in? In a little while are you gonna do that at least I'm gonna put your mind at ease in a little while I hope it really isn't the end of the world. In fact, it's quite an exciting space to be in because now we start playing with the global sense of this and In all honesty a lot of the stuff that we see in in poppy and those eight principles It's really just eight principles of doing good business It's it's it's accountability. It's having security in place. It's being open with what you're doing It's it's really good business practice and we can we can dive into those principles a bit. I think Maybe we should do that when we come back because I'm thinking, you know, we've got obviously what's involved Which is the radio show the podcast is the the website that is attached to that Is that something that's gonna then influence my website because I know a lot of small businesses are not trying to well Many people are not trying to make a living online and working remotely etc. Etc. Is it gonna it's gonna impact us I'm sure isn't it? Yeah, so your website is like basically your your storefront as it were and that's where you first Put out there that you are doing something good around data and all of that So there's a big trust factor and and that comes in beautifully with your websites and and your front-facing stuff that you do Fantastic it is what's involved. My special guest is Ross Saunders Ross does a whole bunch of things and always battle trying to try to get all of them out. He's a speaker He's a consultant. He's an advisor and he's got a whole bunch of letters behind his name What it basically means Ross knows his story when it comes to this new popular act He knows his story when it comes to you Personal information and protection of information that kind of thing when we come back We'll be chatting a bit about those eight principles that Ross just mentioned And we're back. It is what's involved my special guest Ross Saunders So before the break, we're gonna just discuss those those eight principles. So let's talk principles Ross Great. So, you know if I can give a bit of a history lesson on these I suppose the the eight principles that are in poppy really they come from something which was called the OECD guidelines which were guidelines put together back in the 80s as to how data should be looked after and The cool part with puppy is is they really align?
Sort of one-to-one with those principles. So so it's stuff that's been there for a while and we can work through them Well, and it's things that are well defined because of being around for a while. So I Mean we have these principles and the first one that we look at and this is the same across practically Every data protection law globally and that is accountability and holding yourself Accountable as a business that you're gonna comply with this kind of urges regulation that's out there Okay, that makes sense. It was a bit of a bit of a lag there. We'll sort that one out. That makes sense so accountability, but I mean, yeah, okay, this is starting to make some more sense for me because You talk about it being basically principles of good business practice Yeah, so if we list the the eight principles that we look at and we look at accountability We look at specifying our purpose of what we do with data We look at limiting the amount of processing we do on data Not using it for stuff other than what we've said. We're going to use it for we make sure it's up to date We make sure there's security in place. We make sure we're we're open with people that you know, we are collecting your data This is what we're going to do and then we allow people to participate as well saying, you know if someone doesn't want to be on a mailing list they can remove themselves if they want to know where you've got their Information from you have to be able to tell them things like that So so at a very high level those are those are the eight and then it comes down to how you implement your business process to align with those eight Those principles that that are there
Talking about this and as you said it, I mean I think about about mailing lists and I think about a small business like mine I've gotten onto you mailing lists that I have not in my life ever gone anywhere near Those people's websites and when you try and unsubscribe, I mean there's one particular guy and believe it or not He's actually based in South Africa. I know of him once you get on that means mailing list You cannot get off. Is this the kind of thing that that pop here is gonna help us with? Yeah, that's gonna change rapidly for folks who you can't get off their mailing list They're gonna end up falling foul of the regulator and and possibly fines and things like that So one of one of the things that puppy is going to look at is is really roping in that opt-in opt-out Mechanism previously we've had opt-out where you can add anyone to your mailing list and as long as you've got this little opt-out and subscribe at the bottom of your mailer, you're good and You've complied with everything now with poppy it changes around to opt-in. So Someone has to have gone and said yes I actually want to receive this information and then you can have them on the mailing list So there is going to be quite an interesting play within the next year I think on how companies are going to get that consent because you have to have some sort of documented consent For everyone on your mailing list, but again, it's not the end of the world. There are ways of doing this All right, but now when I think of of protection of information, etc. Etc I mean in some of the the larger companies that that I've worked for And and you know even a medium size company I think back to to when I did did some work with a couple of years ago They had all of these staff had these these Files etc on the staff with the payment data all of that was was in the HR office And however, the HR office was not always Occupied it wasn't always locked Is that something that that that poppy?
Does does it address that because anybody could have walked in there and stolen anything literally? Yeah, so very much so and this is where the I'm glad you brought that up because this is where the law starts getting A lot broader than what people think so when we talk about information we talk about data It's not just stuff in the virtual space. It is files. It is notes. It is notebooks In Europe, they talk about anything that forms part of a filing system whether it's paper or not Becomes personal information now one of those principles in the the poppy act is Is security safeguards and that means you have to safeguard the information that's in your command so if you've got an HR department that is that is sitting with all the group life forms and medical aid forms and Your employee onboarding and your bank account details and all of that. You have to as a company have Documented procedures and documented safeguards that say look even at the very least that HR office is locked and people don't have access when people Are not there or when the HR manager is not there very much comes into that now
Okay, this is this is sounding interesting But the thing is that I'm trying to put on two hats because as as as David Watts consumer. I'm going yeah, great I'm happy with this because then my informations are flying around all over the place David Watts, you know running his own businesses is going wow This is gonna be really difficult to sort out and get up-to-date and everything But I don't think it necessarily is I mean what is one of the things that you'd mentioned to me in a in a mail Is this lawful processing? What is lawful processing? So lawful processing basically means that you're adhering to those those principles So we talk about when we're going to process your data. We're going to process it lawfully That means that we you know on the accountability principle we have policies in place So you want to have a a privacy policy and a data protection policy This is how we look after data and that that's the first sort of layer that you have is that policy layer then you get down into your privacy policy things like that where you are Showing that you're processing lawfully by telling people, you know, this is why we need XYZ data and You know, we limit our processing by only doing what we say we're going to do in that purpose And then we don't use that information for other things for enriching other lists or selling it on or anything like that So all those things tie into processing lawfully and it also ties into you know If we're dealing with special information Do we have the consent of the person to do that if we're dealing with an employment relationship?
Do we have a contract in place that talks about this data? If we are complying with other laws like BEE have we specified, you know that we require this information to comply So each one of those three circumstances is a different way of processing lawfully But it's all making sure that we're above board with this information Hey I'm just I'm thinking now, you know in terms of This there's been so much hype over the last while about this this Protection of personal information, etc. Etc. There's been the whole thing with with Facebook What are they actually doing with the data? How much data have they you know mined and done weird and wonderful things with Google? the same thing They're not based in South Africa though, so so how does that African law would it apply to them still? So that's the interesting thing with papier. So papier one of the the exclusions there I suppose is that it's a South African law So for it to apply it has to apply to to people within the borders and businesses within the borders of South Africa But this is where we start looking at that broader global Context as well. So one of the gold standards privacy law-wise is the GDPR in Europe the the general data protection regulation and that Applies extra territorially and this is where you see Google and Facebook really getting slammed by the processes that they use Google just in this last week had a 50 million dollar fine upheld in the French courts Because of how they use data and they tried to get away from that fine by saying Oh, well, they're headquartered in Ireland not in France, but it's been upheld by the courts now that it doesn't matter So we're seeing these things applying extra territorially Canada has also applied their laws against the USA So and Facebook in the USA, so there's been a fine issued across the border there. I wouldn't be surprised if as this Regulation evolves we do start seeing it applying extra territorially as well Fantastic before we go into a break though one quick question Is this Poppier act designed as you say to to protect our personal information How much influence does government have on our on our personal information because that's the thing I'm more worried about you know, I'm one of the a little bit of a radical in terms of that I don't want the government spying on me either So that's the thing that a puppy applies to government to and we saw this start playing out already now with Corona in that with us building tracking programs and government building tracking and tracing programs for people the information regulated and and and the privacy space was was lit up because Government actually appointed an independent judge to look after the coronavirus stuff So we're already starting to see that space where you know government is going to be held accountable for this too and and I hope to see that as well because I also get very scared about What information gets handed over the counter at home affairs and where it goes? So I'm keen to see that Fantastic stuff. My special guest is Ross Saunders. This is what's involved when we come back I want to find out about if you've got any sort of special conditions in terms of your You know, we're talking about special personal information things like your race your gender your sexuality Where does that all fit in we'll talk more with Ross when we come back as I said, it is what's involved So good to have you along with us And we're back my special guest Ross Saunders So Ross the question posed before the break was how does special personal information fit in things like and I mean It's a very very sort of touchy subject at the moment race gender sexuality. This this impact us So this and you're right. It's it's a sticky situation and then sticky topics and all of that and that's exactly where the special personal information comes in the way I look at special and personal information is Any kind of information that has been historically or can be used to discriminate against someone Generally falls in the space of special personal information So between puppy between GDPR other laws generally these do follow the same lines as well So we talk about your religion and philosophical beliefs your race and ethnic origin your trade union membership Political persuasions the parties you support things like that your health and sex life sexuality Preferences things like that criminal behavior and biometrics those all fall into these categories of special personal information and and we're seeing overseas that it's It's moving along as well to start including genetic information and things like that become special and and this requires more Control and and more consent to use that information from people
Okay, I get it but I mean If I'm thinking about stuff now is this with the popular act? Yeah It's all good and well businesses need to to to get to the program make sure that they are conforming etc. Etc But as a member of the public, I mean Do I need to be terribly aware of this? I mean To a large degree and I don't know if it's a South African condition But we we tend to be very you know, somebody hands you something says fill out this form do this do that. Okay cool What's your address? Cool? No problem. I D number the whole lot. I mean we just handed out Is there an illness on us to become more aware and more responsible? I think you've just made every hair on the back of my neck stand up saying that
Yes, so there is an onus on people to really start Taking control of their information, you know I'm hyper aware of it because of having my identity stolen because of working in the space I work in working with ethical hacking and things like that I see what can be taken and how it can be used and we don't realize the breadth of How information can be used? It's it's not necessarily You know that I've given my name surname an email address to this place It's the concern is when that those three pieces of information get combined with those two pieces of information from another data breach combined with those four pieces from another breach and then suddenly The criminals the the hackers they get a profile of you and and they can do a lot more damage from that So I think we do need to really raise our own awareness on it And we've seen it in Europe with the implementation of their data protection laws as the laws progress So people are starting to realize their rights in it and people start enforcing their own rights, which is good to see I Would think so because yeah, and as I said South Africa we traditionally we just we don't we don't ask questions like that But as I'm sitting talking to you talk about the hairs on the back of your next day I'm thinking about you know, simple things, you know every day we go out there We spend a lot of time on the internet those those little quizzes that everybody Asks you about and found out this and found out that or what is your all of that stuff?
Is it's got data points hasn't it that people somewhere are recording? Yeah, it's it's interesting. Someone actually shared one of those things the other day with a big warning because It was one of these quizzes and the quiz asked questions in different ways Like oh, well if you had to have taken your mother's maiden name, what would your surname be now? Yeah, but one of those questions that we saw in the past and thankfully Sites are moving away from this now is well. What is your mother's maiden name to recover your password? So these quizzes are gathering all this data that can very well be used against you Further down the line and the thing is it might not happen immediately But the information could be taken now and then only acted on eight months ten months later My identity theft the information that they got hold of must have been gathered probably three or four years prior to the the Identity theft actually happening. So we do give away information too easily. I think Okay, now, let's just let's just talk a little bit about this because I still you know to tell a lot of people and Last time we tattered afterwards are speaking to some people. I was like, oh my lord This is so scary. And when is this gonna happen? I'm like Yeah, Ross, maybe maybe Ross's thing was just a Isolated incidents or something. Have you got any stories because you deal with this every single day Have you got you know any stories about it about breaches?
How can they happen can they happen easily? they can happen incredibly easily and it happened we we tend to think of breaches and hacking as being this Whole movie scene where you've got these guys in hoodies sitting behind a desk and coding away in a basement somewhere That's that's not really the case. Most of the breaches happen from either negligence in a company or if it's a targeted attack, it might happen in person where people come and impersonate a Lift technician in the building so that they get full access and things like that. So often I mean we talk about in the hacking space you just need a clipboard and a white coat and you can get anywhere in a building and That's that's kind of what happens So, you know But probably the easiest thing that we see happening all the time and it's it's breaches that happen daily Especially now with people working from home and with lockdown happening and remote work happening is phishing And we we we see phishing when our banks email us things like that But you know what actually happens in these situations is Somebody gets control of your email account and they don't necessarily do anything with it, but they can access your email account Now if they are accessing a director or something they can send an email to someone saying look Please change my banking details to this i've moved banks Suddenly payroll changes over the the cto's salary into someone else's account because it looked like the mail came from them So it's highly risky and it's so easy to fall into that trap where you just click on a link Oh, you need to sign into your email account again. You sign in and then boom you've got a breach of so much information Well, the most interesting one that's happened to me in the last week or two is um I got one that to all intents and purposes looked like it came from first national bank Telling me that I had I think it was 50 000 rounds worth of unclaimed e-backs And all you need to do is just contact us here click here, etc, etc, etc I knew that it was a scam for the simple reason that there was no way on this earth. I could have 50 000 rounds with e-backs You know how many people do that and they think that they they they're going to get lucky What amazed me is that they you know the the whole way this was put together and the fact that they managed to get my email Address, um, it it it speaks of a level of sophistication that I would not expect Yeah, and you know, there are varying degrees of sophistication as well and The bank emails are often really well um Uh impersonated to make it look like the bank and then you go there and maybe there's one letter missing in the domain so it looks like you're on the bank's website and then you put in your Card number your pin number or your password and email address and then that person on the other side has that information They can then go to the legitimate site and sign in and do stuff But it it it goes down to incredible levels. I i've dealt with a company that deals with a lot of high wealth investments And their directors are regularly targeted, but they are targeted like you wouldn't believe with the kind of emails where the emails will look like it's coming from uh, a cousin or or a son's friend or Things like that where it's really someone's done their research about someone to try and get further information That is Scary ross we we're starting to run out of time a little bit. Um, when we come back Let's let's do a bit of a wrap-up and then maybe we can also chat very quickly about you know, how how we compare sort of Globally and then just go over what you can do and how you can help because to me It sounds like if I want to go forward with this kind of thing Ross is the man I need to speak to to help me through this this potential minefield So we'll be chatting more about that when we come back
And we're back ross sonda is my special guest it is what's involved data privacy data protection the popular act How do we compare us? Internationally in terms of of where our law is This is probably the most exciting Part of I think us having the poppy act Is is now we are coming in line with where a lot of the world has gone I mean when poppy was was first proposed and first looked at and back in 2013 It was landmark and was great But in that seven years the world has moved on as well and and a lot of other regulations have been put in place And you know to to give a concrete example With the gdpr in europe one of the requirements of that law is that the country that you're dealing with? i.e. South africa or or whoever They need to have data protection laws in place if they don't there's a whole bunch of extra contracts that you have to fill in so I mean from my side, I work with software companies a lot and Software is global. You have hosting everywhere and South african software companies dealing with the eu have such a battle at the moment because There's data protection and agreements that have to be put in place. There's model clauses that have to be put in place There's extra legal agreements that have to be put in place Once we have poppy and if poppy gets what they call an adequacy Rating from the eu suddenly a lot of those contracts fall away because we're seen as adequate and and we can do business Easier with with the eu. So it's very very exciting times that we are now Getting on board with other regulations like the uk like the eu like canada brazil argentina Mauritius, I mean there's a whole bunch of data protection laws out there Okay, but again to me You know, it still seems like it could be a bit of a minefield. I must say i'm a little And easier about making sure that uh, you know in terms of what I do that we are compliant, etc, etc. I'm sure i'm not the only one Do you offer?
I know you do you you speak on this uh consulting, etc, etc What are you offering at this time for people in terms of of this popular act? I have a number of things that I do. So I I do training and awareness so you can Comply with this yourself see what the requirements are things like that So I have courses that I run as well as longer term programs coming up Which will be like a 12-week program on on how to do this yourself Um, but I also help with advisory consulting and things like that and the big thing is to start You've got a year to comply and if you take a risk-based approach and comply in the most difficult areas first You're going to get a lot further along than if you try to the letter do everything and all of that. So risk-based approach having that awareness of what's required of you And then just starting eat this elephant one bite at a time. Uh, you'll you'll definitely get there and you start with policy basically All right now, but this is the kind of thing, um, and I think where i'm angling for as you know I'm very very passionate about business about small medium businesses Um, is this the kind of thing if if somebody's listening and they they are a business owner small business And like I just I need some help. I need somebody to explain this to me. Um, preferably with pictures or whatever the case may be Can they contact you? Are you are you open for that? I'm absolutely open for it I even have pictures and we I do presentations regularly to small businesses to Small and medium companies basically that don't have their own legal departments don't have their own compliance departments That's where I like playing to help people out because it can be such a big process and and engaging attorneys can be very expensive And everyone has to comply. So so yes, I I definitely offer help in this space for smes Wonderful stuff now the best place to get hold of you. Um your website. Would that be would that be a great place to start?
Website is the best place to start for me russ g saunders.com Saunders spelled s-a-u-n-d-e-r-s spelled saunders Awesome rusk before I let you go. Um One of the things and I didn't actually get to ask you this last time. I mean, I know you Um as as the data protection guy, I know you as the public speaker, um What is one thing just one thing about russ g saunders? That people generally don't know tell me something interesting something additional because you know, you go the data protection guy But there's more to you than that. So tell me what that thing is Um, you know probably I have a very Soft spot for folks that have moved into management if we can put it that way. So I know from my career. I started out, uh in the technical space highly technical space and all of that and it was One of the most defining parts of my career was moving into management and not having any sort of safety net and totally fumbling and learning my own way So probably find something on the on the outskirts of the data privacy side for me is I I enjoy helping people Who who just started out in management and things like that and giving them A bit of a boost and advice and things like that It gives me a bit of a kick helping people who who've been in that same highly technical space suddenly having to look after people It's a different space for me, but I thoroughly enjoy it Wonderful and a very diplomatic answer So i'm going to have to nudge you a little bit more in in the direction. I wanted you to go for example clio Talk to me about clio Clio is our italian greyhound
So we we have a a little italian greyhound that that She she takes the space of our child in the house and uh, she ends up on instagram An incredibly large amount just simply because of how cute she is and how how demanding she can be in the household You see there's one thing that not many people know that a big animal lover is ross and i've got to tell you clio Is she's an amazing little animal. I I like the post the other day with uh With who's standing outside is the lounge window for an evening game of catch? Yes. Yes window game She even knows the word Ross thank you so much. So, uh, if people want to get hold of you, it's ross g saunders com Um, you're more than happy to help. Uh, if somebody just wants to go Help, I need just a bit of advice. You're happy to do that Obviously for you. This is a business. So Um, I know that you you're you're guarding your way to help people but you know There's going to be an investment and I think it's a worthwhile one Ross, uh, we wish you all the best and thank you so much for taking the time out and having a chat to us And thank you for having me. It's been great to be back
Keep listening
Ross Saunders — Data Privacy and the big WhatsApp conspiracy
On this episode I chat with Ross about data privacy and the storm in a teacup that is WhatsApp. We also look at Telegram and Signal and discuss the implications of WhatsApp for business. Ross specialises in data prote…
Ryan Johnson — Marine Scientist, Documentary Film Maker, Shark Researcher, Shark vs Whale
On this episode I chat with Ryan about the National Geographic Documentary called Shark vs Whale it's part of the National Geographic wild Shark Fest. What a great chat, personally I think Ryan is either incredibly pa…
Nevo Hadas — Entrepreneur, Business Owner, Passionate Digital Transformation Advocate
“Digital transformation is not just about inventing new business models or digitising your processes, it requires rethinking how a company's culture changes to enable new ways of working, and this is felt most strongl…
Tim Keys — Founder of The Sales Institute, Entrepreneur, Selling In Times Of Crisis
On this episode I chat with Tim about the impact Covid has had on sales people and we look at how you can adapt to these new rules of selling. https://salesinstitute.co.za/index.html www.wattsdigital.net