What Is POPIA?
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's comprehensive data privacy law, which came into full effect on 1 July 2021. POPIA regulates how organisations collect, store, use, share, and destroy personal information belonging to individuals (data subjects).
POPIA is administered and enforced by the Information Regulator of South Africa. Non-compliance may result in administrative fines of up to R10 million and, in serious cases, criminal penalties including imprisonment.
Our Commitment to POPIA
Kenako HSE Solutions is committed to processing personal information lawfully, fairly, and transparently. Our POPIA compliance programme includes:
- Appointing and registering an Information Officer with the Information Regulator
- Maintaining a personal information impact assessment and PAIA manual
- Training all staff who handle personal information on their POPIA obligations
- Implementing appropriate security measures to protect personal information
- Entering into data processing agreements with third-party operators
- Maintaining records of processing activities
- Responding to data subject requests within statutory timeframes
- Reporting notifiable data breaches to the Information Regulator as required
Information Officer
POPIA requires every private body to designate an Information Officer responsible for ensuring compliance. Our Information Officer oversees all aspects of our POPIA compliance programme.
Email: info@kenakoconsulting.co.za
Telephone: +27(0) 729179203
Address: Johannesburg, Gauteng, South Africa
Business hours: MonβFri, 08:00β17:00 SAST
Our Information Officer is registered with the Information Regulator of South Africa as required under section 55(1) of POPIA.
The Eight Conditions for Lawful Processing
POPIA sets out eight conditions (sections 8β25) that every Responsible Party must comply with. Kenako HSE Solutions adheres to all eight:
Accountability
We are responsible for ensuring POPIA compliance and have appointed a registered Information Officer.
Processing Limitation
We collect only the minimum personal information necessary for a specific, defined purpose.
Purpose Specification
Personal information is collected for a specific, explicitly defined, and lawful purpose communicated to data subjects.
Further Processing Limitation
We do not use personal information for any purpose incompatible with the original purpose of collection.
Information Quality
We take reasonable steps to ensure that the personal information we hold is accurate, complete, and up to date.
Openness
We document all processing activities and inform data subjects about our processing through our Privacy Policy.
Security Safeguards
We implement appropriate technical and organisational measures to protect personal information against loss, damage, or unauthorised access.
Data Subject Participation
We provide data subjects with access to their information and allow them to request corrections or deletions.
Grounds for Lawful Processing
In terms of section 11 of POPIA, we rely on the following grounds to process personal information:
- Consent (s.11(1)(a)): Where you have given us specific, informed, and voluntary consent.
- Contractual necessity (s.11(1)(b)β(c)): Where processing is necessary to perform a service contract with you.
- Legal obligation (s.11(1)(d)): Where processing is required by applicable law such as SARS tax records or SETA learner reporting.
- Legitimate interests (s.11(1)(f)): Where processing is necessary to pursue our legitimate business interests without overriding your rights.
Your Rights as a Data Subject
POPIA grants you important rights over your personal information:
Right of Access (s.23)
Request a record of the personal information we hold about you and details of how it has been used.
Right to Correction (s.24)
Request that we correct, update, or delete inaccurate, irrelevant, or unlawfully obtained information.
Right to Object (s.11(3))
Object to the processing of your information on grounds relating to your particular situation or for direct marketing.
Right to Withdraw Consent (s.11(4))
Withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Complain (s.74)
Lodge a complaint with the Information Regulator of South Africa if you believe your rights have been infringed.
Right to Civil Remedies (s.99)
Institute civil proceedings for damages suffered as a result of a contravention of POPIA.
How to Exercise Your Rights
Submit a written request to our Information Officer including your full name, contact details, description of the personal information concerned, the right you wish to exercise, and a copy of your ID document or passport.
We will acknowledge your request within 3 business days and respond substantively within 30 days.
Email: info@kenakoconsulting.co.za
Subject line: "POPIA Data Subject Request"
Response time: Within 30 days of a complete request
Third Parties and Operators
We may share personal information with third-party "operators" β service providers who process information on our behalf. In accordance with section 21 of POPIA, we only use operators that provide sufficient security assurances, process information only on our instructions, and have entered into written data processing agreements with Kenako. We do not sell, rent, or trade your personal information.
Security Safeguards and Breach Response
We implement appropriate technical and organisational measures including SSL/TLS encryption, access-controlled systems, staff POPIA training, and regular security assessments to safeguard personal information against unauthorised access, loss, or destruction.
In the event of a security compromise that poses a real risk of harm, we will comply with section 22 of POPIA by notifying the Information Regulator and affected data subjects as soon as reasonably possible, and taking immediate remedial steps.
Special Personal Information
POPIA provides heightened protection for categories of special personal information (sections 26β33), including information concerning race, health, religious beliefs, trade union membership, or biometric data. Kenako does not routinely collect special personal information. Where necessary β for example, medical information for occupational health assessments β we obtain explicit consent and handle such information with the highest level of care.
Direct Marketing
We send marketing communications only where you have given consent, or where you are an existing client and the communication relates to similar services. Every marketing communication includes a clear opt-out mechanism. You may unsubscribe at any time by emailing info@kenakoconsulting.co.za with "Unsubscribe" in the subject line.
The Information Regulator
If you have a concern about the way we handle your personal information and are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa:
General enquiries: inforeg@justice.gov.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website: www.inforegulator.org.za
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001