Expert Insights

RoPA (Record of Processing Activities): What Is It and Do You Need One?

“What personal data are we processing, why are we processing it, where does it go, and how are we protecting it?” What Should a RoPA Contain? Section 60(2) of the Data Protection Act sets out the information that a controller’s RoPA should contain. This includes: For processors, Section 60(3) requires records covering the processing activities carried out on behalf of each controller, together with the other information specified by the Act. How Do You Create and Maintain a RoPA? 1. Identify Your Processing Activities Start by identifying how your organisation uses personal data. Look across departments and business functions and consider activities such as: 2. Document the Purpose of Each Activity For every processing activity, clearly document why the organisation processes the information. For example, a healthcare organisation may process a patient’s identification and contact information to register the patient and manage their care. It is also good practice to document the applicable lawful basis and, where relevant, the condition permitting the processing of sensitive personal data. This helps connect each processing activity to the organisation’s wider compliance obligations. 3. Map Where the Data Goes A useful RoPA should tell you more than what information you hold. It should help you understand the journey that information takes. Mapping these flows can reveal risks that may otherwise be difficult to see, such as unnecessary access, excessive sharing, unknown third parties or international transfers that have not been properly documented. 4. Identify Recipients and Third Parties Organisations rarely process personal data entirely on their own. A healthcare organisation may share information with laboratories, insurers, pharmacies, technology providers, payment providers, consultants or other healthcare professionals. The RoPA should therefore capture the relevant categories of recipients and, where applicable, international recipients. This can also help organisations identify where appropriate data processing agreements, contractual safeguards or other privacy controls may be required. 5. Document Retention and Security Measures A RoPA should help an organisation understand how long personal data is expected to be retained and how it is protected. Section 60 requires the envisaged erasure time limits to be recorded where possible, and requires, where possible, a general description of the technical and organisational measures used to protect personal data. 6. Review and Update the RoPA Regularly A RoPA should never be treated as a document that is completed once and then forgotten. Organisations change. New systems are introduced, new service providers are engaged, new information is collected and existing processing activities change. Whenever there is a significant change to how personal data is collected, used, stored or shared, the RoPA should be reviewed and updated accordingly. Who Can Help You Create and Maintain a RoPA? The responsibility for creating and maintaining a RoPA rests with the organisation that processes personal data. With input from the different teams involved in processing activities, such as IT, HR, Finance, Marketing and Operations, a Data Protection Officer (DPO) can support this process by providing guidance, coordinating privacy activities, reviewing the RoPA and helping the organisation identify gaps or changes that need to be reflected in it. For organisations that do not have dedicated internal privacy expertise, DPO-as-a-Service can provide ongoing professional support with privacy governance, compliance monitoring, documentation and other data protection activities. Learn more about [DPO-as-a-Service] and how an outsourced Data Protection Officer can support your organisation.

RoPA (Record of Processing Activities): What Is It and Do You Need One? Read More »

DPO-as-a-Service: Why Your Organisation May Benefit from an Outsourced Data Protection Officer

Data protection is more than having a privacy policy on your website. Organisations that collect, use, store or share personal information need to understand their responsibilities and have the right processes, expertise and oversight in place to protect that information. For some organisations, maintaining this expertise internally can be challenging. This is where DPO-as-a-Service can offer a practical solution. Under Section 70(2) of Botswana’s Data Protection Act, 2024, a Data Protection Officer may be a member of an organisation’s staff or may fulfil the role under a service contract. This means organisations can access external DPO expertise without necessarily creating a full-time internal DPO position What Can a DPO-as-a-Service Provide? Data protection is more than having a privacy policy on your website. Organisations that collect, use, store or share personal information need to understand their responsibilities and have the right processes, expertise and oversight in place to protect that information. For some organisations, maintaining this expertise internally can be challenging. This is where DPO-as-a-Service can offer a practical solution. Under Section 70(2) of Botswana’s Data Protection Act, 2024, a Data Protection Officer may be a member of an organisation’s staff or may fulfil the role under a service contract. This means organisations can access external DPO expertise without necessarily creating a full-time internal DPO position. What Can a DPO-as-a-Service Provide? An external DPO can provide ongoing privacy expertise and practical support tailored to an organisation’s activities. Rather than treating data protection as a once-off compliance exercise, the DPO helps organisations build and maintain a privacy programme over time. 1. Strengthen Ongoing Compliance Data protection obligations do not end once policies have been written. A DPO can help an organisation monitor its compliance programme, identify gaps, review existing practices and provide guidance when new processing activities, technologies or business processes are introduced. Under Section 72, the DPO’s duties include advising the controller or processor on their obligations under the Act and monitoring compliance with the Act and the organisation’s data protection policies. 2. Access Specialist Privacy Expertise Data protection involves legal, operational, technical and organisational considerations. An outsourced DPO gives an organisation access to specialist knowledge without necessarily requiring it to build a dedicated internal privacy team. This can be particularly useful for organisations that process significant amounts of personal or sensitive personal data. 3. Create and Review Privacy Documentation A privacy programme requires more than a privacy notice. Depending on an organisation’s activities, a DPO may support the development and review of documentation such as: A Record of Processing Activities (RoPA) gives an organisation a structured view of how personal data is processed across its operations. It helps identify what personal data is processed, why it is processed, who receives it, where it is transferred and how it is protected. Not sure what a RoPA is or whether your organisation needs one? Read our guide: [RoPA (Record of Processing Activities): What Is It and Do You Need One?] 4. Support Staff Awareness and Training Employees are often involved in collecting, accessing, sharing or otherwise processing personal data. A DPO can help organisations build awareness by providing guidance and training on data protection responsibilities, appropriate handling of personal information and the organisation’s internal privacy procedures. This aligns with the DPO’s statutory responsibility under Section 72 to monitor awareness-raising and training among personnel involved in processing activities. 5. Support Privacy Risk Assessments New systems, technologies and processing activities can introduce new privacy risks. A DPO can advise on Data Protection Impact Assessments (DPIAs) and monitor their performance, as provided for under Section 72 of the Act. This allows privacy considerations to be addressed before a new process or technology creates unnecessary risk. 6. Provide an Independent Privacy Function The Act requires a DPO to have functional independence and provides that the DPO should not receive instructions regarding the exercise of their duties. The DPO is also required to report directly to the highest management level of the controller or processor. An outsourced DPO can therefore give an organisation an independent perspective on its privacy practices while working alongside management and operational teams. 7. Help Organisations Respond to Privacy Incidents When a privacy incident occurs, organisations need to know what happened, what information may have been affected, what actions need to be taken and whether regulatory or data subject communications may be required. Having an established DPO function means an organisation has an identified privacy resource that can help coordinate and advise on these matters. Who Can Benefit from DPO-as-a-Service? DPO-as-a-Service can be particularly useful for organisations that: For organisations required to designate a DPO under Section 69, the Act provides that the DPO may fulfil the role through a service contract. Organisations not required to designate a DPO may also choose to appoint one voluntarily. Frequently Asked Questions Privacy Expertise When You Need It

DPO-as-a-Service: Why Your Organisation May Benefit from an Outsourced Data Protection Officer Read More »

Why Privacy Matters in Healthcare Technology: Understanding Your Rights

You probably share your personal information every day without giving it much thought. You give your name and phone number when signing up for a service. You provide your identification number when completing a form. You share your address when making a delivery. You provide medical information when visiting a healthcare provider. You enter your details into websites and apps. But once you give an organisation your information, what happens to it? Who can access it? Why is it being collected? Where is it stored? How long will it be kept? Who else might receive it? These are some of the questions that data protection is designed to address. So, What is Data Protection? In simple terms, data protection is about making sure your personal information is handled responsibly. Personal data is information that identifies you or can be linked to you. This can include your name, telephone number, email address, identification number, address, financial information, photographs and health information. Health information is not just personal information. It is treated as sensitive personal data, which means healthcare providers must be extra careful with it. Your healthcare information may include: Whenever a healthcare provider collects, stores, uses, shares or otherwise handles this information about you, it is “processing” your personal data. Data protection makes sure this is done properly. It does not stop your doctor, clinic or health platform from using your information. It makes sure they have a good reason to use it, are honest about what they are doing, and take real steps to keep it safe. Whenever a healthcare provider collects, stores, uses, shares or otherwise handles this information about you, it is “processing” your personal data. Data protection makes sure this is done properly. Why Do We Have a Data Protection Act? Botswana’s Data Protection Act, 2024 sets the rules for how personal information must be protected. It came into effect on 14 January 2025. The Act places responsibilities on organisations that collect your information, including healthcare providers. It also gives you rights over that information. This matters more than ever in healthcare. We book appointments through apps. We consult with doctors over video calls. We receive lab results by message. We store our medical history digitally instead of in a paper file at one clinic. The more healthcare moves online, the more it matters to know who holds your health information, and what they do with it. What Does the Act Mean for You? This law is not just for lawyers, IT teams or hospital administrators. It is about you. The Act calls you a “data subject,” which simply means you are the person the information belongs to. As a patient, or as someone using a health platform, you have real rights over your own information. These rights include being told how your information is used, being able to see what a provider holds about you, and being able to ask for it to be corrected, deleted, or limited in certain cases. In plain terms, you have more say over your medical information than you might think, and that applies whether you are a patient, a caregiver booking on someone’s behalf, or a partner organisation handling patient data on a provider’s behalf. Who Protects your Data Protection Rights? Botswana’s Information and Data Protection Commission (IDPC) is the country’s data protection regulator. Under Section 12 of the Data Protection Act, 2024, the Commission is the national supervisory authority responsible for ensuring that the Act is effectively applied and complied with. In practical terms, the IDPC helps oversee how organisations handle personal data and whether they are meeting their responsibilities under the law. The Commission’s duties under Section 13 include: Your Five Key Rights 1. The Right to Know You have the right to be told how your information is used. When you register with a healthcare provider or book a consultation, you should not have to guess why they need your details. They should be able to tell you clearly why they are collecting your information and what they will do with it. The law requires this explanation to be given in simple, plain language, not buried in confusing medical or legal terms. 2. The Right to Access Your Information You can ask a healthcare provider whether it holds information about you, and to see that information, including your own medical record. You can also ask what it is being used for, what type of information they hold, and whether it has been shared with a lab, specialist, pharmacy or insurer. 3. The Right to Correct Mistakes What if a clinic has the wrong details about you? Maybe your allergy list is outdated, your phone number changed, or your name was recorded incorrectly. You have the right to ask them to fix it. This matters more in healthcare than almost anywhere else. Imagine a doctor treating you based on an outdated medical history, or a prescription sent to the wrong contact. Accurate information keeps you safe. 4. The Right to Ask for Deletion In some cases, you can ask a provider to delete your personal information. This is sometimes called the “right to be forgotten.” This does not mean a healthcare provider must delete everything you ask for. Medical records often need to be kept for legal, clinical or safety reasons, sometimes for years after your last visit. But you do have the right to make the request, and the provider must consider it fairly. 5. The Right to Limit How Your Information Is Used Sometimes you may not want your information deleted, just used less freely for a while. You can ask a provider to pause or limit how it uses your information, for example, while you are querying something about your record. This is different from asking them to delete it altogether.

Why Privacy Matters in Healthcare Technology: Understanding Your Rights Read More »