Abstract
Data protection and cybersecurity is a growing concern for public higher education institutions in South Africa. One of the most valuable assets for a public higher education institution is undoubtedly its personal information, and with this comes increased responsibilities in protecting this asset. During 2013 the Protection of Personal Information Act of 2013 (the Protection of Personal Information Act) was promulgated, becoming the first comprehensive data protection legislation in South Africa. This Act will impact how public higher education institutions in South Africa collect and process personal information. The Protection of Personal Information Act is not yet fully operational, and therefore its full impact on the higher education environment is still unknown. This paper aims to provide a broad contextual overview of the governance structure of a public higher education institution. Furthermore, it considers public higher education institutions responsibilities relating to data protection and security when collecting and processing personal information in terms of the Protection of Personal Information Act. It also contemplates some of the critical aspects of the Protection of Personal Information Act and highlights various issues of concern relating to data protection compliance that must be considered to achieve compliance. Moreover, it provides some context regarding the Fourth Industrial Revolution and how it can assist public higher education institutions with becoming compliant with the Protection of Personal Information Act.