POPI Act Policy

PRIVACY & COMPLIANCE

Protection of Personal Information Policy

This policy sets out how the Company collects, processes, stores, protects and disposes of personal information in accordance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA).

1. Introduction

1.1 The Company is committed to protecting the privacy of personal information of clients, employees, suppliers, and other stakeholders in accordance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA), which came into full effect on 1 July 2021.

1.2 POPIA regulates the processing of personal information and requires responsible parties to take reasonable steps to ensure the confidentiality, integrity, and availability of personal information.

1.3 This policy applies to all employees, contractors, and third parties who handle personal information on behalf of the Company.

2. Purpose

2.1 The purpose of this policy is to:

  • 2.1.1 Set out how the Company collects, uses, stores, and disposes of personal information.
  • 2.1.2 Ensure compliance with POPIA and applicable legislation.
  • 2.1.3 Protect individuals from harm arising from misuse of personal information.
  • 2.1.4 Maintain transparency and accountability in the processing of personal information.

3. Definitions

3.1 Personal Information means any information relating to an identifiable, living individual, including but not limited to:

  • Race, gender, sex, pregnancy, marital status, age, religion, culture, sexual orientation and disability.
  • Physical or mental health, medical, criminal, financial, or employment history.
  • Contact information including phone numbers, email addresses and physical addresses.
  • Biometric information, personal opinions, preferences and identifying details.

3.2 Processing means any operation performed on personal information, including collection, storage, retrieval, use, disclosure, dissemination, or destruction.

3.3 Data Subject means the person to whom the personal information relates.

3.4 Responsible Party means the Company or individual who determines the purpose and means of processing personal information.

3.5 Operator means a person or entity who processes personal information on behalf of the Company.

4. Policy Statement

4.1 The Company will:

  • Comply with POPIA and good information management practices.
  • Collect personal information lawfully and for a specific purpose.
  • Keep personal information accurate, complete, and up to date.
  • Implement technical and organizational measures to safeguard personal information.
  • Respect the rights of data subjects, including access, correction, and deletion.
  • Maintain records of processing activities and monitor compliance regularly.

5. Information Officer

5.1 The Company has appointed an Information Officer responsible for:

  • Developing, maintaining, and reviewing this policy annually.
  • Ensuring staff receive POPIA training and awareness.
  • Ensuring Privacy Notices are issued to data subjects.
  • Handling data subject access requests and complaints.
  • Approving exceptional or sensitive disclosures.
  • Implementing security measures and maintaining records.
  • Reporting personal information breaches to the Information Regulator and affected individuals.

5.2 A Deputy Information Officer may be appointed to assist where necessary.

5.3 The appointment of the Information Officer is approved by the CEO or Managing Director and is reviewed annually.

6. Consent and Lawful Processing

6.1 Personal information may only be collected with the informed, voluntary, and specific consent of the data subject, unless required or authorized by law.

6.2 Consent can be withdrawn at any time, and processing must cease immediately.

6.3 The Company will keep proof of consent for all personal information collected.

7. Purpose Specification

7.1 Personal information must be collected for a specific, legitimate purpose.

7.2 Data subjects must be informed of the purpose and scope of collection, including the consequences of withholding information.

7.3 Further processing is allowed only if compatible with the original purpose, or if one of the exemptions in POPIA applies.

8. Information Quality

8.1 The Company will ensure personal information is complete, accurate, and up to date.

8.2 Controls and validation checks will be implemented to maintain quality throughout the lifecycle of the information.

8.3 Data subjects will be requested to verify their information periodically.

9. Openness and Transparency

9.1 Data subjects will be informed about:

  • The identity and contact details of the Company as the responsible party.
  • The purpose of processing.
  • Categories of recipients of personal information.
  • Rights to access, correct, delete, or object to processing.
  • Procedures for lodging complaints with the Information Regulator.

9.2 The Company maintains a Privacy Notice available to all data subjects.

10. Security Safeguards

10.1 The Company will implement reasonable technical and organizational measures to secure personal information against:

  • Loss, damage, or unauthorized destruction.
  • Unlawful access, processing, or disclosure.

Technical Measures

  • Firewalls, antivirus, and anti phishing software.
  • Strong, unique passwords and access controls.
  • Disk encryption for sensitive files.

Organizational Measures

  • Access restrictions based on role.
  • Staff training and awareness programs.
  • Documented processes for handling personal information.
  • Regular audits of compliance.

11. Data Subject Rights

11.1 Data subjects have the right to:

  • Access their personal information.
  • Request correction, deletion, or de identification of information.
  • Object to processing where applicable.
  • Withdraw consent at any time.
  • Lodge a complaint with the Information Regulator.

11.2 All requests must be responded to within reasonable timeframes, and the Company will maintain a record of all such requests.

12. Processing of Special Personal Information

12.1 Personal information revealing race, health, sex life, biometric information, religious or philosophical beliefs, trade union membership, or political persuasion is sensitive.

12.2 Such information may only be processed with explicit consent or if legally authorized.

12.3 Additional safeguards are required for sensitive data.

13. Retention and Destruction

13.1 Personal information will only be retained as long as necessary for the purpose it was collected.

13.2 When no longer required, information will be securely destroyed or anonymized.

13.3 Retention periods for different categories of personal information will be documented.

14. Trans Border Data Flows

14.1 Personal information may only be transferred outside South Africa if:

  • The recipient ensures an adequate level of protection.
  • The data subject consents to the transfer.
  • The transfer is necessary for contractual or legal obligations.
  • The transfer benefits the data subject.
  • The transfer is for research, statistical, or historical purposes with safeguards.

14.2 Records of trans border transfers will be maintained.

15. Breach Notification

15.1 Any breach of personal information that is likely to cause harm or distress to data subjects must be reported:

  • Without delay to the Information Regulator.
  • To affected data subjects as soon as reasonably practicable.

15.2 Breaches will be investigated, documented, and mitigated.

16. Training and Awareness

16.1 All staff handling personal information will receive POPIA training during onboarding and periodic refresher training.

16.2 Employees must acknowledge and sign this policy to confirm understanding and acceptance of responsibilities.

17. Policy Review

17.1 This policy will be reviewed annually by the Information Officer and updated as needed.

17.2 Changes will be communicated to all employees and relevant stakeholders.

COMPLIANT TODAY. PROFITABLE TOMORROW.

Partner with URM and turn compliance into a competitive advantage,