Back to Home

Protection of Personal Information Act (POPI)

Understanding your rights and our responsibilities under South Africa's data protection law

What is the POPI Act?

The Protection of Personal Information Act (POPI Act or POPIA) is South Africa's data protection law that came into full effect on July 1, 2021. The Act regulates how organizations collect, process, store, and share personal information.

The POPI Act aims to protect the personal information of individuals (data subjects) and ensure that South African organizations process personal information in a fair, responsible, and secure manner.

At SmartKollect, we are fully committed to complying with the POPI Act and protecting your personal information. We have implemented comprehensive measures to ensure that your data is processed lawfully, securely, and transparently.

Key Definitions

  • Personal Information: Information relating to an identifiable, living individual or company.
  • Data Subject: The person to whom the personal information relates.
  • Responsible Party: The entity that determines the purpose and means of processing personal information.
  • Operator: A person who processes personal information for a responsible party in terms of a contract or mandate.
  • Processing: Any operation concerning personal information, including collection, storage, use, dissemination, or destruction.

8 Key Principles of the POPI Act

The POPI Act is built on eight fundamental principles that guide how personal information should be handled

Accountability

Organizations must ensure that the POPI Act's principles are complied with through appropriate measures.

Processing Limitation

Personal information must be processed lawfully and in a manner that doesn't infringe on the privacy of the data subject.

Purpose Specification

Personal information must be collected for specific, explicitly defined, and legitimate purposes.

Further Processing Limitation

Further processing must be compatible with the purpose for which it was collected.

Information Quality

Personal information must be complete, accurate, not misleading, and updated when necessary.

Openness

Data subjects must be aware that their information is being collected and for what purpose.

Security Safeguards

Personal information must be kept secure against risks of loss, unauthorized access, or unlawful processing.

Data Subject Participation

Data subjects have the right to access their personal information and request corrections or deletions.

Your Rights Under the POPI Act

The POPI Act grants data subjects (you) specific rights regarding your personal information. At SmartKollect, we respect and uphold these rights:

Right to Access

You have the right to request confirmation of whether we hold your personal information and to access that information.

Right to Correction

You have the right to request the correction of inaccurate or incomplete personal information we hold about you.

Right to Deletion

You have the right to request the deletion of your personal information under certain circumstances.

Right to Object

You have the right to object to the processing of your personal information for direct marketing purposes or based on legitimate interests.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time.

Right to Complain

You have the right to lodge a complaint with the Information Regulator if you believe your rights under the POPI Act have been infringed.

To exercise any of these rights, please contact our Information Officer using the contact details provided at the bottom of this page.

How We Ensure Compliance

At SmartKollect, we have implemented comprehensive measures to ensure compliance with the POPI Act:

  • Appointed an Information Officer responsible for ensuring POPI Act compliance
  • Implemented robust security measures to protect personal information from unauthorized access
  • Developed comprehensive data protection policies and procedures
  • Conducted regular staff training on data protection and POPI Act requirements
  • Implemented data breach notification procedures
  • Regularly review and update our data protection measures
  • Ensure that all third-party service providers comply with the POPI Act

Our Commitment

We are committed to processing your personal information lawfully, fairly, and transparently. We only collect and process personal information for specific, explicitly defined, and legitimate purposes, and we ensure that the personal information we process is adequate, relevant, and limited to what is necessary.

Contact Our Information Officer

If you have any questions about the POPI Act or how we handle your personal information, please contact our Information Officer:

Information Officer

Rofhiwa Zimako

Address

61 Sonop Street,
Horizonview Shopping Centre
Horizon, Roodepoort, 1724

You also have the right to lodge a complaint with the Information Regulator if you believe that your personal information has been processed in a way that does not comply with the POPI Act.

Information Regulator (South Africa)

https://www.justice.gov.za/inforeg/