POPIA Compliant
POPIA Compliance Statement
Last Updated: September 9, 2026 | Review Date: September 9, 2027
1. Introduction to POPIA
The Protection of Personal Information Act 4 of 2013 ("POPIA") is South Africa's data protection law that regulates how personal information must be collected, processed, stored, and shared. POPIA aims to protect the privacy of individuals ("data subjects") while balancing competing interests, including the need for free flow of information .
POPIA became fully effective on 1 July 2021, and all organizations processing personal information in South Africa are required to comply with its provisions .
Key POPIA Definitions:
- Personal Information: Information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person .
- Processing: Any operation or activity concerning personal information, including collection, storage, use, and dissemination .
- Data Subject: The person to whom the personal information relates .
- Responsible Party: The organization that determines the purpose and means of processing .
- Operator: A third party that processes personal information on behalf of the responsible party .
2. Our Commitment to Compliance
At ACVV Helen Bellinganhof, we are fully committed to protecting the privacy and security of your personal information. We have implemented comprehensive measures to ensure compliance with POPIA and to demonstrate our dedication to data protection .
✓ Our POPIA Compliance Status: ACVV Helen Bellinganhof has completed a full POPIA compliance assessment and has implemented all necessary policies, procedures, and technical measures to ensure compliance with the Act .
Our compliance framework is built on the following principles:
- Accountability: We take full responsibility for the personal information we process .
- Transparency: We are open about how we collect, use, and protect your information.
- Lawfulness: We process information only on lawful grounds .
- Purpose Specification: We collect information only for specified, lawful purposes .
- Minimality: We collect only the information necessary for our purposes .
- Security: We protect information with appropriate safeguards .
4. The 8 POPIA Conditions
POPIA establishes 8 conditions for lawful processing of personal information . Below is how we comply with each condition:
| POPIA Condition |
Our Compliance Measures |
| 1. Accountability |
We have appointed an Information Officer, documented all processing activities, and implemented comprehensive policies and procedures . |
| 2. Processing Limitation |
We collect only information necessary for specified purposes, with consent where required, and in a lawful manner . |
| 3. Purpose Specification |
We clearly define and document the purpose of collection before processing, as outlined in our Privacy Policy . |
| 4. Further Processing Limitation |
We do not use information for purposes other than those specified without obtaining additional consent . |
| 5. Information Quality |
We take reasonable steps to ensure personal information is accurate, complete, and up-to-date . |
| 6. Openness |
We maintain a transparent Privacy Policy and provide clear information about our processing activities . |
| 7. Security Safeguards |
We implement technical and organizational measures to protect information against loss, damage, and unauthorized access . |
| 8. Data Subject Participation |
We provide mechanisms for individuals to access, correct, and request deletion of their information . |
For detailed information about how we process your personal information, please refer to our Privacy Policy.
5. Data Subject Rights
Under POPIA, you have the following rights regarding your personal information . We have established procedures to facilitate the exercise of these rights:
5.1 Right to Access
You have the right to request a copy of the personal information we hold about you. To exercise this right:
- Submit a written request to our Information Officer using the contact details in Section 16.
- Include sufficient information to verify your identity and locate your records.
- We will respond within a reasonable time, usually within 30 days .
- A reasonable fee may be charged for repetitive or excessive requests .
5.2 Right to Correction
You may request that we correct or update inaccurate, incomplete, or outdated information . Please provide supporting documentation where possible.
5.3 Right to Deletion
You may request deletion of your personal information where:
- The information is no longer needed for the purpose it was collected .
- You withdraw consent and there is no other legal basis for processing .
- The processing is unlawful .
- Retention is no longer required by law .
5.4 Right to Object
You may object to the processing of your personal information on reasonable grounds relating to your particular situation .
5.5 Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal .
5.6 Right to Lodge a Complaint
If you believe your rights under POPIA have been infringed, you have the right to lodge a complaint with the Information Regulator .
Information Regulator Contact Details:
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
Website: https://www.justice.gov.za/inforeg/index.html
6. Security Safeguards
We have implemented comprehensive security measures to protect personal information against:
- Unauthorized access, disclosure, or processing .
- Accidental or unlawful destruction, loss, or alteration .
Technical Measures
- Encryption: Sensitive data is encrypted during transmission and storage where appropriate.
- Firewalls: Network firewalls protect our systems from unauthorized access.
- Access Controls: Strict authentication and authorization mechanisms control system access.
- Secure Sockets Layer (SSL): Our website uses SSL encryption to protect data in transit .
- Regular Updates: Systems are regularly patched and updated to address vulnerabilities.
- Backups: Regular secure backups ensure data can be recovered in case of loss.
Organizational Measures
- Access Restrictions: Staff access personal information only on a need-to-know basis .
- Confidentiality Agreements: All staff sign confidentiality agreements .
- Security Policies: Written policies govern information security practices.
- Regular Reviews: Security measures are reviewed and updated regularly .
- Physical Security: Secure premises with access controls protect physical records.
Important: While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents in accordance with POPIA requirements .
7. Data Breach Response
In accordance with Section 22 of POPIA, we have established a comprehensive data breach response plan .
What constitutes a data breach?
A data breach occurs when there is unauthorized access to, acquisition of, or loss of personal information . This includes:
- Hacking or cyberattacks
- Theft of devices containing personal information
- Unauthorized disclosure by staff
- Accidental loss or destruction of data
Our breach response procedure:
- Detection: Identify and confirm the breach .
- Containment: Take immediate steps to contain the breach and prevent further access .
- Assessment: Investigate the scope, cause, and impact of the breach .
- Notification: Notify affected data subjects and the Information Regulator as required by law .
- Remediation: Implement measures to prevent future breaches .
Notification requirements:
Under Section 22 of POPIA, we must notify:
- The Information Regulator: As soon as reasonably possible after discovering the breach .
- Affected Data Subjects: Unless the identity of the data subject cannot be established or the Regulator directs otherwise .
Notifications will include:
- Description of the breach
- Personal information involved
- Measures taken to address the breach
- Recommendations for data subjects to protect themselves
8. Staff Training & Awareness
All staff members at ACVV Helen Bellinganhof undergo regular training on POPIA compliance and data protection . Our training program covers:
- Initial Training: All new employees receive POPIA training during onboarding.
- Annual Refresher Training: Mandatory annual updates on data protection requirements.
- Role-Specific Training: Specialized training for staff handling sensitive information.
- Breach Response Training: Procedures for identifying and reporting potential breaches.
Staff are required to acknowledge receipt and understanding of our data protection policies annually .
9. Third-Party Processing
When we engage third-party operators to process personal information on our behalf, we ensure compliance with POPIA through:
- Written Agreements: Formal contracts that bind operators to comply with POPIA .
- Due Diligence: Assessment of operator's security measures and compliance history.
- Audit Rights: Provision to audit operator's compliance when necessary .
- Confidentiality: Operators must maintain confidentiality of all personal information .
Our operators are authorized to process personal information only for the specific purposes we instruct and cannot use it for their own purposes .
10. Cross-Border Transfers
POPIA restricts the transfer of personal information outside South Africa unless certain conditions are met . If we transfer personal information to another country, we ensure:
- The recipient country has adequate data protection laws comparable to POPIA .
- The recipient agrees to protect the information in accordance with POPIA .
- The transfer is necessary for the performance of a contract or for legal proceedings .
- The data subject has consented to the transfer .
Currently, ACVV Helen Bellinganhof does not routinely transfer personal information outside South Africa. Should this change, we will update our policies accordingly .
11. Data Retention & Destruction
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law .
Retention periods:
- Contact form submissions: Up to 5 years
- Donor records: Up to 7 years (for tax and accounting purposes)
- Employee records: As required by labour laws (typically 5 years after termination)
- Website logs: 12 months
Secure destruction:
When personal information is no longer needed, we ensure secure destruction through:
- Electronic data: Secure deletion using industry-standard methods .
- Physical records: Cross-cut shredding or incineration .
- Documentation: Destruction certificates maintained for audit purposes .
12. Consent Management
Where we rely on consent as the legal basis for processing, we ensure:
- Specific consent: Consent is specific to the purpose and clearly explained .
- Freely given: Consent is voluntary and not coerced .
- Informed: Data subjects understand what they are consenting to .
- Recorded: Consent is documented and stored securely .
- Withdrawal mechanism: Clear process for withdrawing consent at any time .
Our contact forms include a consent checkbox that links to our Privacy Policy, ensuring informed consent before processing personal information .
13. Cookie Compliance
Our website uses cookies and similar technologies. In compliance with POPIA's requirements for electronic communications :
- Essential cookies: Used without consent as they are necessary for website functionality.
- Non-essential cookies: We will implement a cookie consent mechanism to obtain consent before placing non-essential cookies .
- Cookie policy: Detailed information about cookies is available in our Privacy Policy.
14. PAIA Manual
In accordance with the Promotion of Access to Information Act 2 of 2000 ("PAIA"), we have developed a PAIA Manual that outlines the procedure for requesting access to information held by ACVV Helen Bellinganhof .
The PAIA Manual includes:
- Contact details of the Information Officer
- Procedure for requesting information
- Available information categories
- Fees structure for requests
- Grounds for refusal of access
To request a copy of our PAIA Manual, please contact our Information Officer. Requests must be made in writing and may be subject to applicable fees as prescribed under PAIA.
15. Compliance Audits
We conduct regular internal and external audits to assess and improve our POPIA compliance . These audits include:
- Annual compliance audits: Comprehensive review of all processing activities and security measures.
- Risk assessments: Identification and mitigation of privacy risks.
- Policy reviews: Regular updates to policies and procedures.
- Technical assessments: Vulnerability scans and penetration testing where appropriate.
Audit findings are reported to management and used to continuously improve our data protection practices .
© 2026 ACVV Helen Bellinganhof. All rights reserved.
This POPIA Compliance Statement was developed in accordance with the Protection of Personal Information Act 4 of 2013.