The Protection of Personal Information Act is technical and complex, with far too many requirements for an organisation to address and therefore a risk-based approach must be adopted.