EMPACT GROUP DATA PROTECTION POLICY Policy Owner: Legal Counsel
Policy No: 2021/126
Version: 1
Approved By: CEO
Approval Date: 30.10.2021
Effective Date: 30.10.2021
Review Date: 30.10.2023

1.     PURPOSE OF THE DATA PROTECTION POLICY#

1.1
This Data Protection Policy (“Policy”) has been developed to provide clear guidance to all directors, employees and those who process personal information on behalf of Empact Group (Proprietary) Limited (Registration Number: 1989/005005/07) together with its subsidiaries Supercare Services Group (Proprietary) Limited (Registration Number: 1985/060217/07), Supercare Hygiene (Proprietary) Limited (Registration Number: 1997/008284/07), KKS Daluxolo Food Services (Registration Number: 2003/009722/07) and Isikhonyane Cleaning (Proprietary) Limited (Registration Number: 1989/070403/07) (“Empact Group”) to ensure a lawful, transparent and consistent approach to the processing of personal information .
1.2
The requirements within this Policy are primarily based upon the Protection of Personal Information Act, No. 4 of 2013, as that it is the key piece of legislation covering security and confidentially of personal information.
1.3
Any violation of this Policy will result in swift corrective action and violators will be held accountable.
1.4

Appointed Information Officer for Empact Group:
Alan Brian Quinn (Alan.Quinn@empactgroup.co.za)
22 Milkyway Avenue, Linbro Park 2090
Tel: 011 209 2400 / 011 709 8100

Appointed Deputy Information Officer for Empact Group:
Stephen David Lewis Rushton (Stephen.Rushton@empactgroup.co.za)
22 Milkyway Avenue, Linbro Park 2090
Tel: 011 209 2400 / 011 709 8100

2.     BACKGROUND TO PERSONAL INFORMATION#

The protection of individuals and legal entities personal information is a fundamental constitutional and human right.

2.1     Personal Information processing laws#

In Southern Africa, legislators have defined under various data protection laws, certain data processing principles and related standards, for the protection of personal information , some laws which apply to natural persons only, and some, such as the South African law known as the Protection of Personal Information Act, 14 of 2013 (“POPIA”), which applies to both natural and legal persons, including the requirement that such personal information may only be transferred to other countries if the local law applicable at the place of destination provides for similar levels or standards of data protection, as that afforded by the territory or country from where the personal information is transferred.

2.2     Areas where Empact Group processes personal information#

2.2.1
Empact Group is an integrated facilities management services entity operating in the areas of catering, cleaning, hygiene and pest services.
2.2.2
Inherent in the provision of services, Empact Group continually has access to and is required to process personal information and information relating to individuals and legal entities, which processing takes place in Southern Africa and Namibia, Lesotho and Botswana (where processing may take place from time to time).
2.2.3
Failure to comply with the data protection laws, may have severe consequences for Empact Group, including criminal sanctions, civil claims and damages and potential administrative fines of up to R10 000 000.00 (Ten Million Rand).
2.2.4
This Policy sets out how Empact Group is required to process personal information in order to meet the data protection standards of Empact Group and in order to comply with the legal standards which apply in the territory/ies where such processing takes place.

2.3     Definitions#

Automated processing any form of processing (including profiling) that is undertaken by automated means to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning their performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
Consent any freely given, specific, informed and unambiguous indicationof the data subject's wishes by which they, by a statement or by a clear positive action, signifies agreement to the processing of personal information about them
Criminal convictions and offences personal information relating to criminal convictions, the commission or alleged commission of an offence, proceedings for the commission or alleged commission of an offence and sentencing
Data privacy laws /dataprotection laws The Protection of Personal Information Act, 14 of 2013 (POPIA)
The Promotion of Access to Information Act 2 of 2000 (PAIA)
Data subject an individual or legal entity to whom personal information relates and who can be identified or is identifiable from personal information
Explicit consent a higher standard of consent that requires a very clear and specific statement rather than an action which is suggestive of consent
Information Officer (IO) a person required to be appointed under POPIA and who must have expert knowledge of data protection law and practice, being Empact Group ’s main representative on data protection matters (note: each entity of Empact Group will require an appointed IO/DIO)
Processing notices a notice setting out information that must be provided to data subjects before collecting personal information from them, including notices aimed at a specific group of individuals or notices that are presented to a data subject on a ‘just- in-time’ basis (also known as ‘privacy notice’ or ‘data protection notice’)
Personal Information any information identifying a data subject or information relating to a data subject that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. Personal information includes criminal convictions and offences data, special categories of personal information and pseudonymised personalinformation but excludes anonymous data or data that has had the identity of an individual permanently removed. Personalinformation can be factual (for example, a name, email address,location or date of birth) or an opinion about that person's actionsor behaviour
Personal information breach a breach of security lead to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information transmitted, stored or otherwise processed and which compromises the confidentiality, integrity, availability and/or security of the personal information.
Privacy notices see processing notices above
Process, processes, processing any activity or set of activities which involves personal information including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or making available, alignment or combination, restriction, erasure or destruction
Processing Area South Africa
Namibia, Lesotho and Botswana (where processing may take place from time to time)
Pseudonymised, pseudonymisation replacing information that directly or indirectly identifies an individual with one or more artificial identifiers (for example, a numerical identifier or other code) or pseudonyms so that the data subject cannot be identified without combining the identifieror pseudonym with other information which has been keptseparately and securely. Personal information that has been pseudonymised is still treated as personal information (unlike personal information which has been anonymised)
Responsible Party (POPIA) the person or organisation that determines the purposes and means of processing personal information
Special personal information means information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data, and, for the purposes of this policy personal information relating to criminal offences and convictions.

2.4     Categories of Data Subjects and their Personal Information#

2.4.1
Empact Group may possess records relating to suppliers, shareholders, contracted service providers, employees and clients.
Entity Type Personal Information Processed
Clients: Natural Persons Names, contact details, physical and postal addresses, date of birth, Identity Number, tax related information, nationality, gender, confidential correspondence
Clients: Juristic Persons/ Entities Name of contact persons, name of legal entity, physical and postal address and contact details, financial information, registration number, founding documents, tax related information, authorised signatories, beneficiaries, ultimate beneficial owners, shareholding information, BBBEE information
Employees/Directors Gender: pregnancy, marital status, color, race, age, language, education information, financial information, employment history, Identity Number, physical and postal address, contact details, opinions, criminal record, well-being

3.     APPLICATION AND SCOPE OF THIS POLICY#

3.1 This Policy applies to the following persons:

3.1.1
all Empact Group employees, who for the purposes of this Policy will include permanent, fixed term and temporary employees, directors, interns, third party representatives, agents, sponsors and representatives who are carrying out work for or on behalf of Empact Group (hereinafter referred to as “employees”); and
3.1.2
all operators, service providers, contractors and agents acting for or on behalf of Empact Group, provided they have been made aware of this Policy.
3.2
The rules and standards set out in this Policy applies to all personal information processed by Empact Group in an automated or non-automated manner, and regardless of how stored or recorded i.e.,stored electronically, digitally, on paper or on other materials or through other methods.
3.3
All employees who process personal information on behalf of Empact Group, are expected to comply with Empact Group ’s legal obligations in so far as they relate to the handling and processing of personal information, which has to be done in order to protect Empact Group from the risk of non-compliance, and the consequences of such non-compliance, including loss of data, investigators, administrative penalties, criminal charges and fines, civil claims and damages, as well as the reputational risk.
3.4
All employees who process personal information on behalf of Empact Group must read, understand and comply with this Policy when processing personal information in the course of performing their tasks and must observe and comply with all personal information controls, practices, protocols and training to ensure such compliance.
3.5
Compliance with this Policy and related company policies and procedures is mandatory.
3.6
Any breach of this Policy and related policies and procedures may result in disciplinary action and the necessary corrective action.

4.     DATA PROTECTION PRINCIPLES#

The data processing laws are based on a set of core principles that Empact Group must observe and comply with at all times from the moment that personal information is collected by the particular entity, until the moment that the personal information is archived, deleted or destroyed.

These principles are detailed below:

4.1     Accountability#

4.1.1
Empact Group is responsible for and must be able to demonstrate compliance with the data protection principles and Empact Group’s other obligations under the applicable data processing laws. This is known as the ‘accountability principle’.
4.1.2
Empact Group must ensure that it has adequate resources, systems and processes in place to demonstrate compliance with its data processing obligations, including:
4.1.2.1
appointing a suitably qualified and experienced Information Officer and Deputy Information Officer under POPIA and providing them with adequate support and resources;
4.1.2.2
ensuring that at the time of deciding how Empact Group will process personal information, and throughout its processing, implementing appropriate technical and organisational measures that are designed to ensure compliance with the data protection principles (known as ‘Data Protection by Design’);
4.1.2.3
ensuring that, by default, only personal information that is necessary for each specific purpose is processed both in relation to the nature, extent and volume of such personal information, the period of storage and the accessibility of the personal information (known as ‘Data Protection by Default’);
4.1.2.4
ensuring that where any intended processing presents a high risk to the rights and freedoms of data subjects, Empact Group has carried out an assessment of those risks and is taking steps to mitigate those risks, by undertaking a ‘Data Protection Impact Assessment’;
4.1.2.5
integrating data protection into Empact Group’s internal procedures and documents, by way of privacy policies and processing notices;
4.1.2.6
regularly training of Empact Groups’ directors, employees and those who process personal information on behalf of Empact Group in terms of POPIA, this Policy and Empact Group’s related policies and procedures, and maintaining a record of all such training; and
4.1.2.7
regularly testing the measures implemented by Empact Group and conducting periodic reviews to assess the adequacy and effectiveness of this Policy, and Empact Group’s related personal information policies and procedures which are applicable to Empact Group.

4.2     Lawfulness, fairness and transparency#

4.2.1
Empact Group must only process personal information in a lawful, fair and in a transparent manner.

4.3     Purpose limitation#

4.3.1
Empact Group must only collect and process personal information for a specified, explicit and legitimate purpose.

4.4     Data minimisation#

4.4.1
Empact Group must ensure that personal information which is processed by it is adequate, relevant and limited to what is necessary in relation to the purposes for which it is to be processed.

4.5     Accuracy#

4.5.1
Empact Group must ensure that personal information which is processed by it is accurate and where necessary kept up to date.

4.6     Storage limitation#

4.6.1
Empact Group must ensure that personal information which is processed by it is not kept in a form which permits identification of data subjects for longer than is necessary for the purposes for which the data is processed.

4.7     Security, integrity and confidentiality#

4.7.1
Empact Group must ensure that personal information which is processed by it is done in a manner that ensures its security using appropriate technical and organisational measures to protect the data against unauthorised or unlawful processing and against accidental loss,destruction or damage.

4.8     Transfers of personal information outside the Processing territories#

4.8.1
Empact Group must ensure that personal information which is processed by it is not transferred outside the borders of South Africa (if any), to another country without appropriate safeguards being in place.

4.9     Data subject rights and requests#

4.9.1
Empact Group must allow data subjects to exercise their rights in relation to their personal information.

5.     PROCESSES IMPLEMENTED BY EMPACT GROUP IN ORDER TO ENSURE THAT THE DATA PROTECTION PRINCIPLES ARE GIVEN EFFECT TO#

5.1     Lawfulness and consent to process under certain circumstances#

5.1.1
In order to collect and process personal information for any specific purpose, Empact Group must always have a lawful basis and purpose for doing so.
5.1.2
Consent to process a data subject’s personal information will not always be required. Empact Group in terms of the data processing laws will be allowed to lawfully process a data subject’s personal information without the data subject’s consent under the following circumstances:
5.1.2.1
The processing is necessary for conclusion of the performance of a contract to which the data subject is a party (for instance a contract of employment or registration with Empact Group as a vendor);
5.1.2.2
The processing is necessary in order for Empact Group to comply with certain legal obligations (for instance, to comply with the labour laws);
5.1.2.3
The processing is in order to protect the legitimate or vital interests of the data subject,or of Empact Group or another person (this will equate to a situation where the processing is necessary to protect the individual’s life); or
5.1.2.4
The processing is in order to perform a public duty or to perform tasks carried out in the public interest or the exercise of official authority.
5.1.3
Where the processing of a data subject’s personal information is required for purposes which are not detailed under section 5.1.2 above, then in such circumstances, in order to legitimise and ensure that such processing is lawful, the data subject has to agree to such processing, i.e., it has to provide consent to the processing of its personal information. In this regard it is important to note that where the processing is taking place in South Africa, the consent can be implied – i.e. consent can be done by way of a gesture or simple indication.
5.1.4
Furthermore, where consent is required from the data subject, then such consent must be freely and genuinely given (there must not be any imbalance in the relationship between Empact Group and the data subject and consent must not be a condition for the provision of any product or service).
5.1.5
Where, in terms of the data processing laws, consent to process a data subjects’ personal information is required, such consent may at any time be withdrawn by the data subject.
5.1.6
If consent is withdrawn, then Empact Group will no longer be allowed to continue processing such personal information from the date of such withdrawal and so it will be important to advise the data subject of the consequences of the withdrawal, i.e. that Empact Group will not be able to continue its relationship with the data subject.
5.1.7
Where a third party provides Empact Group with another’s personal information (for example,CV’s housing a job applicant’s personal information provided by a recruitment agent or credit bureau records housing personal information about a creditor which is provided by a credit bureau in relation to a data subject’s credit worthiness or where personal information pertaining to a service provider’s employee is provided by a service provider) Empact Group must obtain confirmation that it was collected by the third party in accordance with the data privacy law requirements and that such personal information was lawfully processed, and that the sharing of the personal information with Empact Group was clearly explained to the data subject by such third party and where required, permission to process including the passing on or the sharing of information was obtained from the owner thereof.
5.1.8
The data processing laws distinguish between personal information and “special personal information” which is also known as “sensitive personal information”. Special personal information concerns the data subject’s race, ethnicity, politics, religion, trade union membership, genetics, biometrics, health, sex life or sexual orientation.
5.1.9
Under POPIA, in order to process special personal information, being the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject; or the criminal behaviour of a data subject to the extent that such information relates to the alleged commission by a data subject of any offence; or any proceedings in respect of any offence allegedly committed by a data subject or the disposal of such proceedings, the following has to be shown in relation to such processing:
5.1.9.1
the processing is carried out with the consent of a data subject;
5.1.9.2
the processing is necessary for the establishment, exercise or defence of a right or obligation in law;
5.1.9.3
the processing is necessary to comply with an obligation of international public law;
5.1.9.4
the processing is for historical, statistical or research purposes, to the extent that the purpose serves a public interest and the processing is necessary for the purpose concerned; or it appears to be impossible or would involve a disproportionate effort to ask for consent, and sufficient guarantees are provided for to ensure that the processing does not adversely affect the individual privacy of the data subject to a disproportionate extent;
5.1.9.5
the information has deliberately been made public by the data subject;
5.1.9.6
permission has been received from the Information Regulator to process special personal information if such processing is in the public interest and appropriate safeguards have been put in place to protect the personal information of the data subject;
5.1.9.7
where the processing concerns religious or philosophical beliefs, and such processing has been done and is necessary to protect the spiritual welfare of the data subjects, unless they have indicated that they object to the processing, and provided that such information is not supplied to third parties without the consent of the data subject;
5.1.9.8
where the processing concerns race or ethnic origin, and such processing is carried out to identify data subjects and only when this is essential for that purpose; and to comply with laws and other measures designed to protect or advance persons, or categories of persons, disadvantaged by unfair discrimination;
5.1.9.9
where the processing concerns trade union membership, and such processing is carried out by the trade union because it is necessary to achieve the aims of the trade union or trade union federation and provided that such information is not supplied to third parties without the consent of the data subject;
5.1.9.10

where the processing concerns one’s health orsex life, and such processing is carried out by:

(a) medical professionals, healthcare institutions or facilities or social services, if such processing is necessary for the proper treatment and care of the data subject, or for the administration of the institution or professional practice concerned;

(b) insurance companies, medical schemes, medical scheme administrators and managed healthcare organisations, ifsuch processing is necessary for – (i) assessing the risk to be insured by the insurance company or covered by the medical scheme and that data subject has not objected to the processing; (ii) the performance of an insurance or medical scheme agreement; or (iii) the enforcement of any contractual rights and obligations;

(c) schools, if such processing is necessary to provide special support for pupils or making special arrangements in connection with their health or sex life;

(d) any public or private body managing the care of a child if such processing is necessary for the performance of their lawful duties;

(e) any public body, if such processing is necessary in connection with the implementation of prison sentences or detention measures; or

(f) administrative bodies, pension funds, employers or institutions working for them, if such processing is necessary for – (i) the implementation of the provisionsof laws, pension regulations or collective agreements which create rights dependent on the health or sex life of the data subject; or (ii) the reintegration of or support for workers or persons entitled to benefit in connection with sickness or work incapacity, and provided that such information is kept confidential;

5.1.9.11
where the processing concerns a person’s criminal behaviour or biometric information, such processing is carried out by bodies charged by law with applying criminal law or by responsible parties who have obtained that information in accordance with the law, and where the processing concerns employees such processing is done in accordance with the rules established in compliance with labour legislation;
5.1.9.12

where the processing concerns a person under the age of 18, such processing is carried out with the prior consent of a competent person; or is necessary for the establishment, exercise or defence of a right or obligation in law; or is necessary to comply with an obligation of international public law; or for historical, statistical or research purposes to the extent that –

(i) the purpose serves a public interest and the processing is necessary for the purpose concerned; or (ii) it appears to be impossible or would involve a disproportionate effort to ask for consent, and sufficient guarantees are provided for to ensure that the processing does not adversely affect the individual privacy of the child to a disproportionate extent; and

5.1.9.13
where the processing concerns special personal information which has deliberately been made public by the child with the consent of a competent person.
5.1.10
Directors, employees and others processing personal information on behalf of Empact Group must only process special personal information if it is able to justify such processing as described above. Processing special personal information without the data subjects’ consent, or where such processing cannot be justified, may result in disciplinary action and incertain circumstances, may constitute a criminal offence, give rise to civil liability or administrative penalties.

5.2     Purpose specific#

5.2.1
Empact Group including directors, employees and others processing personal information on behalf of Empact Group must only collect and process personal information for specified, explicit and legitimate purposes that have been communicated to data subjects before the personal information is collected.
5.2.2
When collecting and using a data subject’s personal information, Empact Group, including its directors, employees and others processing personal information on behalf of Empact Group, have a duty to inform the data subject why the information is required and what will be done with it whilst under Empact Group’s control. Without a lawful basis and purpose for processing,such processing will be unlawful and unfair and may also have an adverse impact on the affected data subjects. No data subject should be surprised to learn that their personal information has been collected, consulted, used or otherwise processed by Empact Group. In other words, any use or processing of a data subject’s personal information must be purpose specific, and the data subject must be told about such processing and how such data will be used, before the intended use of the data. This accords with the universal data protection principles referred to under clause 4 above, which states that the processing of a data subject’s personal information will only be lawful if the data subject has been provided with anexplanation for the processing, including the purpose, which has to be:
5.2.2.1
specific (not given in respect of multiple unrelated purposes);
5.2.2.2
informed (explained in plain and accessible language);
5.2.2.3
unambiguous and given by a clear affirmative action (meaning opt-in; silence, inactivity or pre-ticked boxes will not be sufficient); and
5.2.2.4
separate and unbundled from any other terms and conditions provided to the data subject.
5.2.3
Empact Group, it’s directors, employees and other processing personal information on behalfof Empact Group must ensure that they do not process any personal information obtained for one or more specific purposes for a new purpose that is not compatible with the original purpose. If Empact Group, or its directors, employees and others processing personal information on behalf of Empact Group want to process additional personal information for a new purpose for which the personal information was collected, then they will have to provide the data subject with the details of such processing and the reason(s) why the data has to be processed, and where necessary, if required, obtain the data subject’s consent to such processing.

5.3     Data minimisation#

5.3.1
The personal information that Empact Group or its directors, employees and others processing personal information on behalf of Empact Group collect and process must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is to be processed.
5.3.2
Directors, employees and others processing personal information on behalf of Empact Group must only process personal information that is absolutely necessary for the performance of the required purpose and related duties and tasks and not for any other purposes. Accessing excessive personal information that is unnecessary or which one is not authorised to access,or that one has no reason to access, may result in disciplinary action and in certain circumstances, may constitute a criminal offence, give rise to civil liability or administrative penalties.

5.4     Accuracy#

5.4.1
The personal information that Empact Group it’s directors, employees and others processing personal information on behalf of Empact Group collect and process must be accurate and, where necessary, kept up-to-date and must be corrected and deleted without delay when Empact Group or its directors, employees and others processing personal information on behalf of Empact Group discover, or are notified, that the data is inaccurate.
5.4.2
Directors, employees and others processing personal information on behalf of Empact Group must ensure that they have procedures in place to ensure that the personal information on record is kept updated, especially where one becomes aware that personal information is inaccurate. Where appropriate, any inaccurate or out-of-date records should be deleted or destroyed.

5.5     Security, integrity and confidentiality#

5.5.1
The personal information that Empact Group, its directors, employees and others processing personal information on behalf of Empact Group collect and process must be secured by appropriate technical and organisational measures which guard against accidental loss, destruction or damage, and against unauthorised or unlawful processing.
5.5.2
Empact Group has developed, implemented and maintains appropriate technical and organisational measures for the processing of personal information taking into account the nature, scope, context and purposes for such processing, the volume of personal information processed and the likelihood and severity of the risks ofsuch processing for the rights of data subjects and has procedures in place to ensure that it regularly evaluates and tests the effectiveness of such measures to ensure that they are adequate and effective.
5.5.3
Directors, employees and others processing personal information on behalf of Empact Group must ensure that they:
5.5.3.1
observe and comply with all Empact Group ’s information security policies, especially those pertaining to personal information security at all times;
5.5.3.2
do not attempt to circumvent any administrative, physical or technical measures Empact Group has implemented, as doing so may result in disciplinary action and in certain circumstances, may constitute a criminal offence, give rise to civil liability or administrative penalties;
5.5.3.3
ensure that the confidentiality and security of personal information is maintained at all times;
5.5.3.4
ensure that they only store personal information on Empact Group servers which are protected by approved security software, and one or more firewalls under the direction of the IT Manager and where transferred or uploaded to cloud computing services from computers, devices and applications, that these services have been approved by their IT Manager;
5.5.3.5
ensure that prescribed security measures and controls are implemented, or where instructed, followed to prevent all and any unauthorised access to personal information, the accidental deletion of personal information or the exposure of personal information to malicious hacking attempts;
5.5.3.6
ensure that all devices where personal information is stored, are password protected and that passwords are not written down or shared, irrespective of seniority or department which passwords must be strong passwords which are changed regularly. If a password is forgotten,it must be reset using the applicable method;
5.5.3.7
ensure that all hard copies of personal information, along with any electronic copies stored on physical or removable media is stored securely in a locked box, drawer, cabinet, or similar, and that such data is not removed from Empact Group’s premises unless with prior approval from the data subject’s departmental head and when so removed,thatsuch data is encrypted if it is on a removable media device;
5.5.3.8
ensure that all personal information stored electronically is regularly backed up using Empact Group’s provided systems and applications and in accordance with backup protocols. Such backups will be tested regularly in line with Empact Group’sstandard backup procedures and protocols under the direction of its IT Manager;
5.5.3.9
ensure that no personal information is stored on any mobile device (including, but not limited to, laptops, tablets, smartphones or data sticks), whether such device belongs to Empact Group or otherwise, without the formal written approval of the department head and, in the event of such approval, the personal information is stored or held strictly in accordance with all instructions and limitations described at the time the approval is given, and for no longer than is absolutely necessary when so stored, that such data is encrypted;
5.5.3.10
ensure that where personal information is stored on paper, that it is not left in places where persons can view the data, e.g. on a printer, but instead is kept in a secure place where an unauthorised person cannot access or see it, such as in a locked drawer, safe or cabinet and that when no longer required, that same is shredded;
5.5.3.11
ensure that when any personal information is to be erased or otherwise disposed of for any reason (including where copies have been made and are no longer needed), it should be securely deleted and disposed of. For further information on the deletion and disposal of personal information, please refer to the relevant Company’s data retention and destruction policy.
5.5.3.12
ensure that all device screens, when not in use, are always locked especially when left unattended;
5.5.3.13
ensure that all personal information transferred within Empact Group’s network and infrastructure is only transmitted over secure networks, including wireless and wired networks;
5.5.3.14
ensure that personal information is not shared informally and when shared that there is alawful or business reason for such sharing. When sending emails which contain personal information, ensure that they are marked “confidential”, do not contain the personal information in thebody of the email, whether sent or received, but rather placed in an attachment, which email is then encrypted before being transferred electronically;
5.5.3.15
ensure that personal information is not transferred or sent to any entity not authorised directly to receive it;
5.5.3.16
ensure that personal information is not being kept in a form that identifies a data subject for longer than is necessary in relation to the purposes for which it was collected (except in order to comply with any legal, accounting or reporting requirements);
5.5.3.17
ensure that where personal information is to be sent by facsimile transmission, ensure that the recipient has been informed in advance of the transmission and that he or she is waiting by the fax machine to receive the data;
5.5.3.18
ensure that where personal information is transferred physically, whether in hardcopy form or on removable electronic media, that it is passed directly to the recipient or sent using recorded delivery services and housed in a suitable container marked “confidential”;
5.5.3.19
ensure that generally all personal information is handled with care at all times, kept confidential, and that it is not left unattended or on view to unauthorised employees; and
5.5.3.20
ensure that all software (including, but not limited to, applications and operating systems) used in connection with Empact Group are installed on Empact Group owned computers or devices and which have been installed by and with the prior approval of the IT department, which software must at all times be kept up-to-date.

5.6     Retention of personal information#

5.6.1
Storing personal information for longer than necessary may increase the severity of a data breach and may also lead to increased costs associated with such storage in order to manage these risks Empact Group will maintain policies and procedures to ensure that personal information is deleted, destroyed or anonymised after a reasonable period of time following expiry of the purpose for which it was collected.
5.6.2
Where appropriate, directors, employees and others processing personal information on behalf of Empact Group must take all reasonable steps to delete or destroy any personal information that Empact Group no longer requires in accordance with the relevant Empact Group’s records management policies and data retention and destruction policy.

5.7     Sharing personal information#

5.7.1
The transfer of any personal information to an unauthorised third party will give rise to and constitute a breach of the lawfulness, fairness and transparency principle and, where caused by a security breach, will give rise to and constitute a personal information breach.
5.7.2
Directors, employees and other processing personal information on behalf of Empact Group are not permitted to share personal information with third parties, unless:
5.7.2.1
there is a legitimate company need to share the personal information;
5.7.2.2
the fact that the personal information will be shared with another has been communicated to the data subject in a privacy notice or processing notice before hand; and
5.7.2.3
the person receiving the personal information has either agreed to keep the personal information confidential and to use it only for the purpose for which it was shared under a datatransfer agreement, or where acting as an operator or a processor, (i.e., such person will be processing the personal information on behalf of Empact Group), has concluded an Operator Agreement with Empact Group, before receipt of the personal information.

5.8     Transfers outside of South Africa#

5.8.1
The data processing laws prohibit the transfer of personal information outside of South Africa, including transmitting, sending, viewing or accessing personal information in or to a different country unless:
5.8.1.1
the data subject consents to such processing;
5.8.1.2
the country where the personal information is being transferred to provides the same level of protection from the data subject(s) as housed under the data processing laws applicable in South Africa;
5.8.2
Following the above, directors, employees and others processing personal information on behalf of Empact Group are not permitted to transfer personal information to areas outside South Africa, unless one of the following controls and safeguards are in place, (which can be obtained from the Information Officer on request):
5.8.2.1
the South African Data Privacy Regulator has issued an “adequacy decision” confirming that the territory or country to which Empact Group proposes transferring the personal information to, has adequate personal information protection laws in place which will ensure that such data remains protected as it was in the country or territory from where it came;
5.8.2.2
Empact Group has a standard data transfer contract or Operator Agreement in place which will be concluded with the third-party recipient of the personal information prior to them receiving personal information and which agreement houses the rules which will have to be followed by the third party in order to ensure that such data remains protected as it was in the country or territory from where it came;
5.8.2.4
Empact Group has an approved code of conduct in place which has been approved by the Information Regulators, which allows such transfers;
5.8.2.5
the data subject has given its express and explicit consent to the proposed transfer, having been fully informed of any potential risks;
5.8.2.6
the transfer is necessary to perform a contract between Empact Group and a data subject, for reasons of public interest, to establish, exercise or defined legal claims or to protect the vital interests of the data subject in circumstances where the data subject is incapable of giving consent; or
5.8.1.7
the transfer is necessary, in limited circumstances to protect the parties’ legitimate interests.
5.8.3
Whenever a director, employee and or any other representative needs to transfer personal information to areas outside South Africa, it has a duty to ensure that one of the controls and safeguards detailed above are in place.

5.9     Transparency and processing notices#

5.9.1
Empact Group has a duty to show that it has dealt with a data subject in a transparent manner. To demonstrate transparency, Empact Group must provide all data subjects with appropriate privacy notices or processing notices before it collects and processes their personal information.
5.9.2
The data privacy laws set out a detailed list of information that must be contained in all privacy notices and processing notices, including the types of personal information collected;the purposes for which they will be processed; the lawful basis relied upon for such processing; the period for which the personal information will be retained; who Empact Group may share the personal information with; and, if Empact Group intends to transfer personal information to countries outside South Africa, the mechanism relied upon for such transfer as well as the respective rights of the data subjects.
5.9.3
Whenever a director, employee and or any other representative processes personal information on behalf of Empact Group, such person must ensure that data subject is made aware of the information set out below:
5.9.3.1
the types of personal information collected and the purpose or reason for the collection;
5.9.3.2
the lawful basis relied upon for such processing or whether consent is required for the processing;
5.9.3.3
the period for which the personal information will be retained;
5.9.3.4
who Empact Group will be sharing the personal information with, including external transfers and the mechanism relied upon for such transfer;
5.9.3.5
the security measures which are in place to protect the data; and
5.9.3.6
the respective rights of the data subjects.
5.9.4
Directors, employees and/or any other representatives who processes personal information on behalf of Empact Group , in order to give effect to the obligations set out under section 5.8.3 above, must ensure that all documents and/or records where personal information is recorded and/or housed or which calls for or sets out that personal information is required, must house a data processing clause which records or states in such document or record, that Empact Group will have to, in order to deal with the data subject, process the data subject’s personal information and that such processing is subject to:
5.9.4.1
the provisions of the data processing laws;
5.9.4.2
where applicable, Empact Group ’s standard binding corporate rules, its standard data transfer contract and/or Operator Agreement.

5.10     Data subject rights and requests#

5.10.1
The data processing laws provide data subjects with a number of rights in relation to their personal information, including the right to access its data, and to change it.
5.10.2
Empact Group has developed, implemented and will maintain certain processes which give effect to these data subject rights, as described below, which processes will be directed to and handled directly by the Information Officer or his deputy, and no other.
5.10.3
All directors, employees and persons processing personal information on behalf of Empact Group must take note of and give effect to these processes as described below.

5.11     The right to withdraw consent#

5.11.1
Where a data subject has had to give its consent to the processing of its personal information, the data subject in such case will have the right to withdraw such consent at any time, which withdrawal will apply from the date of withdrawal only and which will not affect the legality of the processing of its personal information to which the consent applies prior to the withdrawal.
5.11.2
In order to give notice of the withdrawal of consent, the data subject must complete the standard “withdrawal of consent notice”, which form must be emailed to the Information Officer for further attention. Should the Information Officer give effect to such withdrawal, a stop processing notice will be sent to the affected director, employee or person processing such personal information on behalf of Empact Group together with the consequences of such decision, who will then be required to stop the processing of the affected personal information.

5.12     The right to be informed#

5.12.1
A data subject has the right to be told why its personal information is being processed, including what type of personal information will be processed, the reason for the processing, who the personal information will be shared with and whether such information will be sent outside the territory where it is being processed or held, and how the personal information will be safeguarded.

5.13     The data subject’s right to have access to its personal information#

5.13.1
All data subjects have the right at any time to ask any person or entity who holds its personal information, for access to their personal information, including finding out more about the personal information which Empact Group holds about them, what it is doing with that personal information , and why it is processing the personal information .
5.13.2
In South Africa, in terms of POPIA, this has to be exercised using the “request for access to information” procedure which is described under a law known as the Promotion of Access to Information Act, 2000 (PAIA) and which request procedure is more fully set out under the relevant entity’s PAIA Manual.
5.13.3
All request for information held by Empact Group, including personal information has to be made using the standard request procedure referred to above, which request will be submitted directly to, and which will be handled directly by, the Information Officer, in accordance with the provisions of PAIA.
5.13.4
If any director, employee and/or any other representatives who processes personal information on behalf of Empact Group is asked for any information which pertains to a data subject or to Empact Group , such person making the request must be referred firstly to the Information Officer or his Deputy if necessary.

5.14     Rectification of personal information#

5.14.1
All data subjects have the right to request thattheir personal information is updated orrectified where it is inaccurate, incomplete or out of date.
5.14.2
The Information Officer on receipt of the request, will where able, rectify so far as possible, the personal information in question, and inform the data subject of the rectification. Furthermore, in the event that any affected personal information has been disclosed to third parties, those parties will also be informed of any such rectification and the reasons therefor.

5.15     The right to object and/or restrict processing#

5.15.1
Data subjects have the right to object to Empact Group processing their personal information based on its legitimate interests, Empact Group shall cease such processing immediately, unless it can be demonstrated that Empact Group haslegitimate grounds forsuch processing which override the data subject’s interests, rights, and freedoms, or that the processing is necessary for the performance of a legal or statutory duty or the conduct of legal claims.
5.15.2
Where a data subjects objects to Empact Group processing its personal information for direct marketing purposes, Empact Group must immediately stop any further direct marketing.
5.15.3
A data subject furthermore has the right to object to the processing of its personal information coupled with the right to ask Empact Group to restrict processing the personal information where the data subject:
5.15.3.1
believes that the personal information is inaccurate;
5.15.3.2
believes that the processing was unlawful, and the data subject prefers restriction of processing over erasure;
5.15.3.3
believes that the personal information is no longer necessary in relation to the purposes for which it was collected but one is required to establish, exercise or defend a legal claim and needs to retain the data; or
5.15.3.4
has objected to the processing pending a determination whether Empact Group ’s legitimate interest’s grounds for processing the personal information override those of the data subject.
5.15.4
In accordance with the above, the data subject may object to, and ask Empact Group to place a restriction on the processing of the personal information which Empact Group holds. Such request will be sent to Information Officer or his deputy for determination and action.
5.15.5
If the Information Officer, as applicable in the circumstances is in agreement with and succumbs to the request of the data subject, then Empact Group shall pend any further processing of the personal information in question and retainonly the amount of personal information concerning that data subject (if any) that is necessary to ensure that the personal information in question is not processed further.
5.15.6
In the event that any affected personal information has been disclosed to third parties, those parties shall be informed of the applicable restrictions on processing it (unless it is impossible or would require disproportionate effort to do so).

5.16     The right to data portability#

5.16.1
This is the right of the data subject to receive or ask Empact Group to transfer to a third party, a copy of the data subject’s personal information in a structured, commonly used machine-readable format.
5.16.2
The data subject must submit the request to the Information Officer, who will attend to and where possible facilitate the request if technically feasible. All requests for copies of personal information shall be complied with within one month of the data subject’s request. The period can be extended by up to two months in the case of complex or numerous requests. If such additional time is required, the data subject shall be informed.

5.17     The right to object to direct marketing#

5.17.1
A data subject who has opted into any form of direct marketing has the right to opt out from any subsequent direct marketing, i.e., it has the right to ask Empact Group not to process its personal information for any further direct marketing purposes.

5.18     The right to object to decisions based solely on automated processing including Profiling#

5.18.1
A data subject has the right to object to decisions creating legal effects or significantly affecting the data subject which weremade solely by automated means, including profiling, and the right to request human intervention.
5.18.2
The data subject also has the right to ask for the reasons why a decision was made and the underlying methodology which was used to make the decision.

5.19     The right to erasure (right to be forgotten)#

5.19.1
A data subject has the right to request that Empact Group erases the personal information which Empact Group holds about it in the following circumstances:
5.19.1.1
it is no longer necessary for Empact Group to hold that personal information with respect to the purpose(s) for which it was originally collected or processed;
5.19.1.2
the data subject wishes to withdraw its consent;
5.19.1.3
the data subject objects to Empact Group holding and processing its personal information (and there is no overriding legitimate interest to allow Empact Group to continue doing so);
5.19.1.4
the personal information has been processed unlawfully; or
5.19.1.5
personal information needs to be erased in order for Empact Group to comply with a particular legal obligation.
5.19.2
The request for erasure must be submitted to the Information Officer and/or his deputy, as applicable.
5.19.3
Unless Empact Group hasreasonable grounds to refuse to erase personal information, all requests for erasure shall be complied with, and the data subject must be informed of the erasure, within one month of receipt of the data subject’s request. The period can be extended by up to two months in the case of complex requests. If such additional time is required, the employee data subject shall be informed.
5.19.4
In the event that any personal information that is to be erased in response to a data subject’s request has been disclosed to third parties, those parties shall be informed of the erasure (unless it is impossible or would require disproportionate effort to do so).

5.20     The right to be notified of a personal information breach#

5.20.1
A data subject must be notified of a personal information breach which involves its personal information, which notice will be prepared by and conveyed to affected data subjects by the Information Officer.

5.21     The right to complain#

5.21.1
A data subject has the right to lodge a complaint or objection with regards to the processing of its personal information, which complaint or objection must set out and concern a non-compliance by Empact Group with the data processing principles or concern a non-compliance with the data processing laws.
5.21.2
On receipt of the complaint or objection, the Information Officer will attempt to hear and resolve the matter and failing resolution will provide the data subject with a non-resolution notice.
5.21.3
If the Information Officer and data subject are able to resolve the matter, a record setting out the solution will be complied, and signed by the parties and any other affected persons provided with details of the resolution.
5.21.4
Where the parties are unable to resolve the matter, the data subject on receipt of the abovementioned notice will have the right to refer the complaint onwards, in the case of an alleged POPIA breach or infringement to the Information Regulator or another appropriate supervisory authority.
5.21.5
In order to give effect to the above, all directors, employees and/or any other representatives who processes personal information on behalf of Empact Group, must familiarise themselves with these rights and the related processes, and ensure that all data subjects are informed of these rights and the procedure which has to be followed when a data subject wishes to makeuse of these rights.

5.22     Direct marketing#

5.22.1
Empact Group and its directors, employees and/or other representatives who processes personal information on behalf of Empact Group must ensure that before they send direct marketing to customers for the first time, that they have given the customer the opportunity in an informal manner to agree or disagree to the receipt of direct marketing material.
5.22.2
Empact Group and its directors, employees and/or other representatives who process personal information on behalf of Empact Group must ensure that before they send direct marketing to non-customers that they receive appropriate opt in consentsin the prescribed manner and form as per the provisions of POPIA.
5.22.3
Empact Group and its directors, employees and/or any other representatives who process personal information on behalf of Empact Group must ensure that when a data subject exercises their right to object to direct marketing, in the form of an opt out, that such opt out is recorded and honored.
5.22.4
Empact Group has developed a direct marketing policy and guideline and all directors, employees or persons who process personal information on behalf of Empact Group,must familiarise themselves with these documents and ensure that they understand and comply with these obligations in relation to direct marketing before embarking upon any direct marketing campaign.

5.23     Operators#

5.23.1
An operator is an entity who processes personal information on behalf of Empact Group without coming under its direct control.
5.23.2
All operators and processors have to conclude Empact Group ’s standard data transfer contract or Operator Agreement prior to them receiving and or processing personal information on behalf of the Empact Group, which agreement houses the rules which will have to be followed by the operator or processor in order to ensure that such data is processed and protected in accordance with the processing laws and Empact Group’s security procedures and standards.
5.23.3
Directors, employees or persons who process personal information on behalf of Empact Group,must ensure that when they appoint an operator that the relevant standard data transfer contract or Operator Agreement is concluded with such operator or processor prior to them receiving and or processing personal information on behalf of Empact Group.

5.24     Profiling#

5.24.1
Empact Group from time to time, uses personal information for profiling purposes which is done via “cookies” on its website.
5.24.2
Directors, employees or persons who process personal information on behalf of Empact Group,must ensure that when personal information is used for profiling purposes, that the following takes place:
5.24.2.1
clear information explaining the profiling is provided to data subjects, via privacy notices, cookie opt ins and cookie notices, including the significance and likely consequences of the profiling;
5.24.2.2
Appropriate mathematical or statistical procedures are used;
5.24.2.3
Technical and organisational measures are implemented to minimise the risk of errors. If errors occur, such measures must allow the errors to be easily corrected; and
5.24.2.4
All personal information processed for profiling purposes shall be secured to prevent discriminatory effects arising out of profiling.

5.25     Training#

5.25.1
Empact Group will conduct regulartraining sessions covering the contents ofthe data privacy laws and Empact Group ’s related personal information processing policies and procedures, which will be available to all directors, employees and/or persons who process personal information on behalf of Empact Group.
5.25.2
All directors, employees and/or persons who process personal information on behalf of Empact Group, must ensure that they have undertaken the necessary training, that they understand the privacy laws and Empact Group related personal information processing policies and procedures, and that importantly all processing of personal information is done in accordance with the data processing laws, the training, the related policies and procedures and/or any guidelines issued by Empact Group from time to time.

5.26     Record-keeping#

5.26.1
Empact Group must keep full and accurate records of all its processing activities in accordance with the data processing laws and related requirements including:
5.26.1.1
the name and details of the Information Officer and any deputy as appointed by Empact Group in South Africa;
5.26.1.2
all processors and/or operators who process personal information on behalf of Empact Group;
5.26.1.3
the purposes for which Empact Group collects, holds and processes personal information;
5.26.1.4
details of the categories of personal information collected, held and processed by Empact Group;
5.26.1.5
detailed descriptions of all technical and organisational measures taken by Empact Group to ensure the security of personal information.

5.27     Archiving and destruction of data#

5.27.1
Empact Group to facilitate the correct creation, use, storage, archive, retrieval and ultimate destruction of records has developed a records management and retention policy and records retention schedule.
5.27.2
Directors, employees and others processing personal information on behalf of Empact Group must ensure that when they process personal information, that such data is processed in strict compliance with Empact Group ’s records management and retention policy and records retention schedule.
5.27.3
Directors, employees and others processing personal information on behalf of Empact Group must furthermore ensure that when personal information is no longer needed for the specific purposes for which it was collected, that such personal information is archived for the legally required retention period and thereafter deleted, destroyed or anonymised, which must be done in strict compliance with Empact Group’s retention Policy and records retention schedule.

5.28     Reporting personal information breaches#

5.28.1
In the event of a personal information breach, Empact Group has a duty to give notice of such breach to the Information Regulator and to the affected data subjects.
5.28.2
Empact Group has put in place appropriate procedures to deal with any personal information breach and will report such breach to the Information Regulator and notify any data subjects whose personal information may have been compromised.
5.28.3
All personal information breaches must be reported immediately to the Information Officer which report must include the following details:
5.28.3.1
Categories and approximate number of data subjects concerned;
5.28.3.2
Categories and approximate number of personal information records concerned;
5.28.3.3
The likely cause of the consequences of the breach; and
5.28.3.4
Details of the measures taken, or proposed to be taken, to address the breach including,where appropriate, measures to mitigate its possible adverse effects.
5.28.4
Empact Group’s Information Officer with the approval of Empact Group’s Board will report any personal information or security breach to the Information Regulator and notify the affected data subjects, at the time that such breach occurs.
5.28.5
Directors, employees and/or any other representatives who processes personal information on behalf of Empact Group must familiarise themselves with, observe and comply with Empact Group’s personal information breach procedure and to this end has a duty to immediately report through to the Information Officer as the case may be, any known or suspected data breach and to take all appropriate steps to preserve evidence relating to the breach.

6     GOVERNANCE#

6.1     Information Officers and Deputy Information Officers#

6.1.1
Empact Group has appointed Alan Brian Quinn who will act as the duly appointed Information Officer and Stephen David Lewis Rushton who will act as the duly appointed Deputy Information Officer.
6.1.2
The Information Officer/Deputy Information Officer will be responsible for the following:
6.1.2.1
developing, constructing and once prepared, implementing and overseeing a personal information processing framework and related roadmap;
6.1.2.2
developing, constructing and once prepared, implementing and overseeing the various personal information processing policies and procedures, including this Policy;
6.1.2.3
monitoring compliance with this Policy, the various personal information processing policies and the data processing laws;
6.1.2.4
arranging and implementing data protection training to all directors, employees and other persons who process personal information on behalf of Empact Group;
6.1.2.5
providing ongoing guidance and advice on personal information processing;
6.1.2.6
ensuring that all operational and technological data protection standards are in place and are complied with;
6.1.2.7
working closely with IT in order to ensure that appropriate technological and operational measures have been implemented in order to ensure the safety and security of all personal information which Empact Group holds;
6.1.2.8
receiving and considering reports from IT about compliance with all technological and operational data protection standards and protocols;
6.1.2.9
be entitled and have authorisation to initiate disciplinary proceedings against any employee who at any time breaches any technological and/or organisational and/or operational data protection standard, rule, custom, instruction, policy, practice and/or protocol (verbal, in writing or otherwise) (“rule”) applicable in any department or area of the operations within Empact Group ;
6.1.2.10
review and approve any contracts or agreements with third parties to the extent that they may handle or process data subject information;
6.1.2.11
attend to requests and queries from data subjects in respect of their respective data subject rights, including requests for access to their personal information or information; and
6.1.2.12
liaising with and/or co-operating with any regulators or investigators or officials who may be investigating a data privacy matter.

6.2     IT SteerCo#

6.2.1
Empact Group has appointed an IT SteerCo which will be responsible for the following:
6.2.1.1
conducting cyber security risk assessments including base line risk assessments of all Empact Group information technology activities;
6.2.1.2
ensuring that adequate and effective IT operational and technological data protection procedures and standards are in place in order to address all IT security risks;
6.2.1.3
ensuring that all systems, services and equipment used for processing and/or storing data adheres to internationally acceptable standards of security and data safeguarding, and is regularly updated to continue to comply with such standards;
6.2.1.4
issuing appropriate, clear, and regular rules and directives, whether for Empact Group as a whole or a particular part of it, department, person or level of person in relation to any aspect of Empact Group ’s work, including password protocols, data access protocols, levels of persons who enjoy access to certain data sign-on and sign-off procedures, log-on and log-off procedures; the description of accessories, applications and equipment that will or may be used, and/or that may be used under any circumstances, and the like; and
6.2.1.5
evaluate any third-party services Empact Group is considering or may acquire to process or store data, e.g. cloud computing services and ensuring that appropriate and effective operational and technological data protection procedures and standards are in place in orderto address all IT security risks which may present themselves in respect of these external service providers.

7     NON-COMPLIANCE#

Any transgression of this Policy will be investigated and may lead to disciplinary action being taken against the offender.


ANNEXURE A: OPERATOR AGREEMENT#

Operator’s Agreement

entered into by and between:

Name:

Registration number:

(Hereinafter to be referred to as: the “Responsible Party”),

AND

Name:

Registration number/ Identity number:

(Hereinafter to be referred to as: the “Operator”).

Hereby Agree as Follows:

1.
Definitions And Interpretations:
1.1.
In this agreement:
1.1.1.
Clause headings are for convenience and shall not be used in its interpretation and unless the context clearly indicates a contrary intention.
1.1.2.
An expression which denotes any gender includes the other gender; a natural person includes an artificial or juristic person and vice versa; the singular includes the plural and vice versa.
1.1.3.
The following words shall bear the meanings assigned to them below:
1.1.3.1.
“Agreement” means this Operator Agreements and any schedules attached hereto.
1.1.3.2.
“Data subject” means the person to whom personal information relates.
1.1.3.3.
“Information officer” of, or in relation to, a –
1.1.3.4.
Public body means an information officer or deputy information officer as contemplated in terms of Section 1 or 17 of this Act; or
1.1.3.5.
Private body means the head of a private body as contemplated in Section 1, of PAIA.
1.1.4.
“Operator” means a person who processes personal information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party.
1.1.5.
“Personal information” meansinformation relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to:
1.1.5.1.
Information relating to the race, gender, sex, pregnancy, marital status, national, ethnic, or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person.
1.1.5.2.
Information relating to the education or the medical, financial, criminal or employment history of the person.
1.1.5.3.
Any identifying number, symbol, e-mail address, telephone number, location information, online identifier, or other particular assignment to the person.
1.1.5.4.
The biometric information of the person.
1.1.5.5.
The personal opinions, views, or preferences of the person.
1.1.5.6.
Correspondence sent by the person that would reveal the contents of the original correspondence.
1.1.5.7.
The views or opinions of another individual about the person; and
1.1.5.8.
The name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person.
1.1.6.
“Processing” means any operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including:
1.1.6.1.
The collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, or use.
1.1.6.2.
Dissemination by means of transmission, distribution or making available in any other form; or
1.1.6.3.
Merging, linking, as well as restriction, degradation, erasure, or destruction of information.
1.1.7.
“PAIA” means the Promotion of Access to Information Act No. 2 of 2000.
1.1.8.
“POPI”: meansthe Protection of Personal information Act No. 4 of 2013.
1.1.9.
“Responsible Party” means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information.
2.
Application:
2.1.
This Agreement shall apply to all processing of personal information that may be subject to POPI in the scope of all agreements, currently entered into between the parties.
2.2.
Insofar as the Operator will be processing personal information subject to POPI on behalf of the Responsible Party during the performance of the Operator’s obligations in terms of the agreements referred to in clause 2.1.
2.3.
In the event of a conflict between any provisions of the agreements as referred to in clause 2.1 and the provisions of this agreement, the provisions of this Agreement shall prevail.
3.
Duration And Termination:
3.1.
This Agreement shall come into effect on the date of the last signature being appended unto this Agreement.
3.2.
This Agreement may be terminated by either party upon 30 (thirty) days written notice.
3.3.
Termination or expiration of this Agreement shall not discharge the Operator from its confidentiality obligations in terms of this agreement.
3.4.
The Operator shall process personal information until the date of termination of this Agreement, or until such data is returned or destroyed on instruction of the Responsible Party.
3.5.
It is noted between the parties that should this agreement be terminated in terms of clause 3.3 of this agreement, the Operator may not be able to fulfil all its obligations in terms of the agreements as detailed in clause 2.1 due to requirements in POPI not being met.
3.6.
An overview of the categories of personal information, the categories of Data Subjects, and the nature and purposes for which the personal information are being processed is provided in Schedule 2.
4.
The Responsible Party and The Operator:
4.1.
The Operator will not process any personal information on behalf of the Responsible Party unless explicitly instructed to do so by the Responsible Party.
4.2.
The Operator hereby undertakes that it will not process any personal information on behalf of the Responsible Party without the Responsible Party’s knowledge and authorization.
4.3.
Subject to the provisions of the agreements referred to in clause 2.1, to the extent that the Operator’s personal information processing activities are not adequately defined in the agreements referred to in clause 2.1, the Responsible Party will determine: -
4.3.1.
the parameters.
4.3.2.
Purposes; and
4.3.3.
the manner
by which the personal information may be processed by the Operator.
4.4.
The Operator will process the personal information only on Responsible Party’s written instructions and within the parameters as set forth in the Responsible Party’s written instructions.
4.5.
The Operator will only process the personal information to the extent that this is required for the provision of the services.
4.6.
The Operator will inform the Responsible Party if the Operator is under a legal obligation to process the personal information in a manner which is beyond the scope of the Responsible Party’s written instructions.
4.7.
The Responsible Party warrants that it has the necessary consent and/or justification exists in terms of POPI for the processing to be performed in relation to the services.
4.8.
Should the consent be revoked by a Data Subject and/or a justification for the processing activity no longer exist, the Responsible Party is responsible for communicating the fact of such revocation and/or termination to the Operator.
4.9.
Should the Responsible Party communicate the revocation of consent and/or the termination of a justification in terms of POPI, the Operator will immediately cease to process the personal information that is associated with the said revocation and/or termination.
5.
Confidentiality:
5.1.
The Operator hereby undertakes to keep all personal information provided to it by the Responsible Party as confidential and shall not disclose the personal information without the Responsible Party’s written consent.
5.2.
The Operator shall inform all its employees, agents and/ or approved sub-Operators engaged in processing the personal information of the confidential nature of the personal information. The Operator will ensure that its employees, agents and/ or approved sub-Operators have entered into the necessary contractual agreements in order to ensure that all personal information is kept confidential, and the Operator will take action against its employees, agents and/ or approved sub-Operators in the event that they breach the aforementioned contractual agreements.
6.
Security:
6.1.
TheOperatorshall secure the integrity and confidentiality of the personal information in its possession or under its control by taking appropriate, reasonable technical and organizational measures to prevent: -
6.1.1.
The loss of damage to or unauthorized destruction of personal information; and
6.1.2.
Unlawful access to or processing of the personal information.
6.2.
the Operator must take reasonable measures to—
6.2.1.
identify all reasonably foreseeable internal and external risks to personal information in its possession or under its control;
6.2.2.
establish and maintain appropriate safeguards against the risks identified;
6.2.3.
regularly verify that the safeguards are effectively implemented; and
6.2.4.
ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards.
6.3.
The Operator must have due regard to generally accepted information security practices and procedures which may apply to it generally or be required in terms of specific industry or professional rules and regulations.
6.4.
The operator must notify the responsible party immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person.
7.
Transborder Information Flow
7.1.
The Responsible party hereby grants the Operator authorization to transfer data outside the borders of South Africa for the purposes of fulfilling its contractual duties. The data will enjoy no less protection than it does in South Africa.
8.
Notification Of Security Compromises:
8.1.
Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, the responsible party must notify the Responsible Party.
8.2.
The notification referred to in clause 8.1 must be made as soon as reasonably possible after the discovery of the compromise, considering the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of the Operator’s information system.
8.3.
The notification referred to in clause 8.1 must provide sufficient information to allow the Responsible Party and/or data subject to take protective measures against the potential consequences of the compromise, including—
8.4.
a description of the possible consequences of the security compromise.
8.5.
a description of the measures that the Operator intends to take or has taken to address the security compromise.
8.6.
a recommendation with regard to the measures to be taken by the Responsible Party and/or data subject to mitigate the possible adverse effects of the security compromise; and
8.7.
if known to the Operator, the identity of the unauthorised person who may have accessed or acquired the personal information.
9.
Sub-Operators:
9.1.
The Operator shall obtain the Responsible Party’s written authorisation before it subcontracts any of the processing operations as required in the agreements in clause 2.1.
9.2.
The Operator shall remain fully will all obligations in terms of this Agreement and the agreements as set out in clause 2.1.
9.3.
The Operator shall ensure that an Operator Agreement, comparable to this agreement, is signed between the Operator and any approved sub-operator.
10.
Returning Or Destruction of Personal Information:
10.1
Upon termination of this Agreement, the Responsible Party’s written instruction or the fulfilment of the obligation in the agreements as detailed in clause 2.1, the Operator shall, at the discretion of the Responsible Party, either delete, destroy, or return all personal information to the Responsible Party and destroy or return any existing copies of the personal information (should any exist).
10.2
The Operator shall notify all third parties supporting its own processing of the personal information of the termination of this Agreement and shall ensure that all such third parties shall either destroy the personal information or return the personal information to the Responsible Party, at the discretion of the Responsible Party.
11
Miscellaneous:
11.1
The Laws of the Republic of South Africa shall at all times govern this agreement and the contractual relationship between the parties.
11.2
No provision of this agreement (including, without limitation, the provisions of this clause) may be amended, substituted, or otherwise varied, and no provision may be added to or incorporated in this agreement, except by a written agreements signed by the duly authorized representatives of each party.
11.3
No provision of this agreement (including, without limitation, the provisions of this clause) may be amended, substituted, or otherwise varied, and no provision may be added to or incorporated in this agreement, except by a written agreements signed by the duly authorized representatives of each party.
11.4
Any indulgence by the Responsible Party in exercising, or any failure by the Responsible Party to exercise, any right under this agreement shall not be construed as a waiver of that right and shall not affect the ability of the Responsible Party subsequently to exercise that right or to pursue any remedy, nor shall any indulgence constitute a waiver of any right (whether against the Operator or any other person).
11.5
The waiver of any right under this agreement shall be binding on the waiving party only to the extent that the waiver has been reduced to writing and signed by the duly authorized representatives of the waiving party.
11.6
This agreement supersedes all prior agreements representations, communications, negotiations, and understandings between the parties concerning the subject matter of the agreement.
11.7
Whenever possible, each provision of the agreement shall be interpreted in a manner which makes it effect and valid under the applicable law but if any provision of the agreement is held to be illegal, invalid, or unenforceable under the applicable law, the offending clause shall be severed from the agreement and the offending clause shall not affect the other provisions of this agreement which will remain in full force and affect.
11.8
Further information on how the Company processes Personal Information is available in our Privacy Policy at https://empactgroup.co.za
11.9
The parties choose the following addresses as their respective domicillia citandi et executandi at which all documents and notices, including those of a legal nature, can be delivered and/or served. The parties must notify the other party of any change in domicillia citandi et executandi.
THE RESPONSIBLE PARTY
Contact number:
Address:
E-mail Address:
THE OPERATOR:
Contact Number:
Mobile Number:
Address:
E-mail Address:
11.10
The parties agree to perform or procure the performance, of all further things, and execute and deliver (or procure the execution and delivery) of all further documents, as may be required by law or as may be desirable or necessary to implement or give effect to this agreement and the transactions contemplated herein.
11.11
The headings in this agreement will not be used in the interpretation of this agreement and are merely for ease of reference.

Signed at          on this          day of                      202_

Witnesses:

1.__________________

2.__________________                 ___________________________________

For and on behalf of the Responsible Party, being duly authorised hereto.

Full name and designation of signatory:
___________________________________

___________________________________

Signed at          on this          day of                      202_

Witnesses:

1.__________________

2.__________________                 ____________________________________

For and on behalf of the Operator, being duly authorised hereto.

Full name and designation of signatory:
___________________________________

___________________________________

SCHEDULE 1

CONTACT INFORMATION OF THE INFORMATION OFFICER OF THE RESPONSIBLE PARTY

Name and Surname:_________________________
Contact number:   _________________________
Email address:      _________________________

CONTACT INFORMATION OF THE INFORMATION OFFICER OF THE OPERATOR.

Name and Surname: _________________________
Contact number:   _________________________
Email address:      _________________________

SCHEDULE 2

TYPES OF PERSONAL INFORMATION THAT WILL BE PROCESSED IN THE SCOPE OF THE AGREEMENTS REFERRED TO IN CLAUSE 2.1

Categories                        of                        Data                        Subjects:

Nature and purpose of the information processing:

↑ Back to contents