Privacy Policy (POPIA)
1. Introduction
We at The Fiduciary Gazette ("the Company", "the Responsible Party") are committed to ensuring the protection of personal information in compliance with the Protection of Personal Information Act (POPIA) No. 4 of 2013. This policy outlines the Company's responsibilities and obligations regarding the collection, processing, storage, and protection of personal information.
2. Definitions
- Act: the Protection of Personal Information Act No. 4 of 2013.
- Personal Information: any information relating to an identifiable natural or juristic person.
- Data Subject: the individual whose personal information is being processed.
- Responsible Party: The Fiduciary Gazette, which determines the purpose and means of processing personal information.
- Information Officer: the appointed person responsible for overseeing compliance with POPIA — currently E. Goddard (Editor).
- Deputy Information Officer: not yet appointed.
3. Scope of application
This policy applies to:
- All employees, contractors, and service providers handling personal information.
- All personal information processed by the Company in any format (electronic, physical, or verbal).
4. Collection and processing of personal information
The Responsible Party shall:
- Collect personal information lawfully and for a defined purpose.
- Process personal information in a reasonable manner that does not infringe on privacy rights.
- Inform Data Subjects about the purpose of data collection and obtain consent where necessary.
- Ensure information is accurate, up-to-date, and relevant.
5. Purpose of processing personal information
Personal information will be processed for purposes including but not limited to:
- Employment and HR administration.
- Client relationship management and customer support.
- Marketing, as consented to, and service improvements.
- Legal and contractual obligations.
6. Storage and security of personal information
The Responsible Party will implement appropriate measures to prevent unauthorised access, loss, or damage of personal information, including:
- Obtaining access to secure international cloud-based storage facilities on behalf of data subjects.
- Access control and password protection.
- Regular data security audits.
- Physical documents containing privileged and/or protected information secured by the Information Officer and/or duly appointed company employees in accordance with industry standards.
7. Disclosure and non-disclosure of personal information
The Responsible Party shall not disclose personal information to third parties without the Data Subject's consent, unless required by law or contract to do so.
8. Data subject rights
Data Subjects have the right to:
- Request access to their personal information.
- Request corrections or deletion of incorrect information.
- Reasonably object to the processing of their personal information.
- Lodge complaints with the Information Regulator.
9. Retention and destruction of personal information
Personal information shall be retained only for as long as necessary for its intended purposes and legally required periods.
10. Breach management procedure
In the event of a breach as prescribed in the Act, the Responsible Party shall:
- Identify and contain the breach.
- Notify affected Data Subjects and the Information Regulator where necessary.
- Take remedial actions to prevent recurrence.
11. Compliance and responsibilities
The Information Officer, E. Goddard, is responsible for monitoring compliance. Their duties include:
- (a) the encouragement of compliance, by the Responsible Party, with the conditions for the lawful processing of personal information;
- (b) dealing with requests made to the Responsible Party pursuant to the Act;
- (c) working with the Regulator in relation to investigations conducted pursuant to Chapter 6 of the Act in relation to the Responsible Party;
- (d) otherwise ensuring compliance by the Responsible Party with the provisions of the Act; and
- (e) such other duties as may be prescribed.
All employees must co-operate in adhering to this policy and report any suspected breaches.
12. Policy review
This policy shall be reviewed annually, or as required by the Information Regulator, to ensure compliance with legislative provisions.
13. Contact details
For any queries regarding this policy or personal information, contact:
- Information Officer: E. Goddard (Editor)
- Email: eugene@thegazette.co.za
- Phone: +27 82 490 3518