Business OS
Governance & ComplianceCompany Policies

POPIA Privacy Policy Pack

A comprehensive privacy policy pack designed for South African SMEs to comply with the Protection of Personal Information Act (POPIA).

Updated 15d ago
POPIAPrivacy PolicyData ProtectionSouth AfricaSMEComplianceLegal Document

Company Letterhead

{{company_name}}

{{company_address}}

Phone: {{phone}}

Email: {{email}}

POPIA Privacy Policy

This Privacy Policy outlines how {{company_name}} collects, uses, discloses, and protects the personal information of its customers, employees, and other stakeholders, in compliance with the Protection of Personal Information Act (Act 4 of 2013) (POPIA) of South Africa.

By engaging with {{company_name}}, you consent to the processing of your personal information as described in this policy.

Definition of Personal Information

Personal information, as defined by POPIA, includes information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person. This includes, but is not limited to: names, ID numbers, contact details, financial information, and any other information that can identify an individual or juristic entity.

Collection of Personal Information

{{company_name}} collects personal information directly from individuals or juristic persons through various means, including: application forms, contracts, correspondence, website interactions, and service agreements. We ensure that the collection of personal information is for a specific, explicitly defined, and lawful purpose related to our functions or activities.

Sources of information may also include publicly available records or third parties with your consent or where legally permissible.

Use of Personal Information

Your personal information is used for the following purposes:

1. To provide and manage services offered by {{company_name}}.

2. To process transactions and fulfil contractual obligations.

3. To communicate relevant information, updates, and marketing materials (with consent).

4. For internal record keeping, statistical analysis, and business improvement.

5. To comply with legal and regulatory obligations as required by SARS, CIPC, and other relevant bodies.

6. To ensure the safety and security of our premises and digital platforms.

Disclosure of Personal Information

{{company_name}} may disclose personal information to third parties under the following circumstances:

1. With your explicit consent.

2. To service providers and partners who assist us in delivering our services (e.g., couriers, IT support, payment processors), under strict confidentiality agreements.

3. To regulatory bodies, law enforcement agencies, or other government entities when required by law (e.g., SARS for tax compliance, CIPC for company registrations).

4. In the event of a business transfer, merger, or acquisition, personal information may be disclosed to the acquiring entity.

Security Measures

{{company_name}} implements appropriate technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. This includes secure servers, encryption, access controls, and regular security audits.

We strive to maintain the integrity and confidentiality of your personal information at all times.

Data Subject Rights (POPIA Section 5)

Under POPIA, you have the right to:

1. Access your personal information held by {{company_name}}.

2. Request the correction, deletion, or destruction of your personal information.

3. Object to the processing of your personal information, subject to legal provisions.

4. Lodge a complaint with the Information Regulator regarding the processing of your personal information.

5. Request restriction of processing.

To exercise these rights, please contact our Information Officer at {{information_officer_email}}.

Retention of Personal Information

{{company_name}} will retain personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law (e.g., BCEA for employee records, SARS for financial records). Once no longer required, personal information will be securely destroyed or de-identified.

Cookies and Website Tracking

Our website may use cookies and similar tracking technologies to enhance user experience, analyse website traffic, and personalise content. You can manage your cookie preferences through your browser settings. For detailed information, please refer to our Cookie Policy [Link to Cookie Policy, if applicable].

Changes to this Privacy Policy

{{company_name}} reserves the right to update or amend this Privacy Policy at any time. Any changes will be posted on our website and, where appropriate, notified to you directly. It is your responsibility to review this policy periodically for any updates.

Contact Information (Information Officer)

For any questions or concerns regarding this Privacy Policy or the processing of your personal information, please contact our Information Officer:

Name: {{information_officer_name}}

Email: {{information_officer_email}}

Phone: {{information_officer_phone}}

Signature

_____________________________

Name: {{authorised_signatory_name}}

Title: {{authorised_signatory_title}}

Date: {{date}}

Related templates