Privacy Statement

 PROTECTION OF PERSONAL INFORMATION (POPI) POLICY

  1. INTRODUCTION

Practical Publishing (“the Company”) is a Publisher and Events Organiser, duly incorporated in terms of South African law.

The Protection of Personal Information Act 4 of 2013 (“POPIA”) regulates the lawful collection, storage, usage, handling, processing, transfer, retention, archiving and disposal of a Data Subject’s Personal Information (see definitions below).

As part of its business functions, the Company collects and processes Personal Information, as defined in POPIA.

The Company is responsible to collect, store, use, handle, process, transfer, retain, archive, and otherwise manage Personal Information in a lawful, legitimate, and responsible manner in accordance with the provisions set out in POPIA.

The purpose of the POPI Policy is to set out the procedures and processes to manage the collection, processing and deletion of Personal Information, to manage all the risks associated therewith and to ensure compliance with POPIA.

The POPI Policy demonstrates the Company’s commitment to protecting the privacy rights of Data Subjects in the following manner:

Failing to comply with POPIA could potentially damage the Company’s reputation or expose the Company to civil claims for damages. The protection of Personal Information is therefore every employee’s responsibility.

The Company will ensure that the provisions of POPIA and the guiding principles outlined in this policy are complied with through the necessary awareness and training of its employees and encouragement of desired behaviour.

The Company will take appropriate steps, when necessary, which may include disciplinary action, against those employees who through their intentional or negligent actions and/or omissions fail to comply with the principles and responsibilities outlined in this policy.

  1. DEFINITIONS 

The following definitions are those set out or referenced in POPIA itself and are applied throughout this policy, unless the context indicates a contrary meaning:

“Child” means a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take any action or decision in respect any matter concerning him- or herself;

“Consent” means any voluntary, specific, and informed expression of will in terms of which permission is given for the collection and processing of Personal Information; 

“Cookies” a small piece of information stored on your computer or smart phone by the web browser.

“Data Subject” means the person to whom Personal Information relates;

“De-identify”, in relation to Personal Information of a Data Subject, means to delete any information that:

“Direct Marketing” means to approach a Data Subject, either in person or by mail or electronic communication, for the direct or indirect purpose of:

“Electronic Communication” means any text, voice, sound, or image message sent over an electronic communications network which is stored in the network or in The Recipient’s terminal equipment until it is collected by The Recipient; 

“Information Officer” of, or in relation to, a private body means the head of a private body as contemplated in section 1, of the Promotion of Access to Information Act;

“Information Regulator” means the independent regulatory body having jurisdiction throughout South Africa, and having been established in terms of section 39 of POPIA to perform certain functions under both POPIA and Promotion of Access to Information Act (PAIA);

“Person” means a natural person or a juristic person; 

“Personal Information” means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to:

“Processing” means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Information, including:

Promotion of Access to Information Act” and “PAIA” mean the Promotion of Access to Information Act 2 of 2000, together with Regulation 187 of 15 February 2002 as amended to 1 June 2007;

“Protection of Personal Information Act” and “POPIA” means the Protection of Personal Information Act 4 of 2013, together with any and all Regulations that may in the future be promulgated thereunder;

“Public Record” means a record that is accessible in the public domain and which is in the possession of or under the control of a public body, whether or not it was created by that public body;

“Record” means any recorded information:

“Regulator” means the Information Regulator established in terms of section 39;

“Responsible Party” means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing Personal Information, in this document, being the company Absolut Wealth Management (Pty) Ltd, and all its associated and holding companies and associated business units and divisions;

“Restriction” means to withhold from circulation, use or publication of any Personal Information that forms part of a filing system, but not to delete or destroy such information;

“Special Personal Information” means Personal Information as referred to in section 26 of POPIA concerning:

“Unique Identifier” means any identifier that is assigned to a Data Subject and is used by a responsible party for the purposes of the operations of that responsible party and that uniquely identifies that Data Subject in relation to that responsible party.

  1. Principles of POPI

POPIA creates nine actionable rights for South African citizens (Data Subjects), listed as follows:

POPIA creates eight conditions for lawful data processing, in which the consent of the Data Subject is central, i.e,

POPIA prescribes specific authorisation and conditions precedent required for the processing of Personal Information relating to minors.

At all times, the Company will endeavour to ensure that the Data Subject’s rights and conditions for lawful data processing, as detailed in POPIA, are adhered to.

  1. COLLECTION OF PERSONAL INFORMATION 

The Company will approach all identified Data Subjects, in writing, to obtain their consent for the collection and processing of their Personal Information and explain the purpose therefor.

The purpose for the collection of Personal Information is to enable the Company:

The process of collecting Personal Information will include, amongst others, the following:

The purpose of holding Personal Information is to enable the Company to provide services to Data Subjects, which will include amongst others the following:

Special Personal Information will not be collected and processed by the Company unless it is required in terms of the provisions of POPIA, Section 27.

In all such instances the authorisation of the Information Officer must be obtained before any collection or processing takes place.

Personal Information regarding a child will not be collected and processed by the Company unless it is required in terms of the provisions of POPIA, Section 35.

In all such instances the authorisation of the Information Officer must be obtained before any collection or processing takes place.

  1. CONFIDENTIALITY UNDERTAKING 

All Personal Information provided to the Company will only be used for the purposes set out above.

The Company will not share, sell, or disclose any Personal Information other than as described in this policy.

The Company may, depending on particular business needs, disclose Personal Information to any of the following:

In some instances, the Company may be required to disclose Personal Information without the Data Subject’s consent. Specific instances where this may occur include, amongst others, the following:

  1. WITHOLDING CONSENT TO COLLECT AND PROCESS PERSONAL INFORMATION 

All Data Subjects are within their rights to withhold consent to the Company collecting and processing their Personal Information.

In the event that consent to providing the Company with Personal Information is withheld, the Company may not be able to engage with the Data Subject or enter into an agreement or business relationship.

Any instances where consent is withheld must be referred to the Information Officer.

  1. STORAGE OF PERSONAL INFORMATION 

Personal Information supplied to and stored by The Company can be in any of the following formats:

Any Personal Information provided to the Company will be held and stored securely for the purpose for which it was collected.

The secure storage facilities for all the Personal Information will be checked regularly by the Company to ensure compliance with required security and privacy standards.

All laptop and desktop computers will be password protected, and passwords will be tested to ensure they are of sufficient strength.

All laptop and desktop computers must have the auto lock facility enabled.

No Personal Information will be stored unencrypted on any laptop or desktop computer.

No Personal Information may be downloaded onto mobile phones, tablets, external hard drives, or memory sticks.

The Personal Information contained in hard copies will be stored and retained safely under lock and key.

Access to The Company’s premises is restricted and controlled.

  1. RETENTION, ARCHIVING AND DESTRUCTION OF PERSONAL INFORMATION 

Personal Information will not be retained for longer than is necessary for achieving the purpose for which it was collected and subsequently processed and will be destroyed and/or deleted when appropriate.

The exceptions to the above principle specifically provided in POPIA are where:

When the Company is no longer authorised to retain Personal Information, it shall destroy or delete such Personal Information or records of Personal Information or de-identify them in a manner that prevents their reconstruction in an intelligible form.

  1. DISCLOSURE AND TRANSFER OF PERSONAL INFORMATION TO OTHERS 

As a general principle no Personal Information will be disclosed to any 3rdparties without the written consent of the concerned Data Subjects.

Should business needs so dictate, the Company may from time-to-time transfer and/or disclose Personal Information to other parties, including its group companies or subsidiaries, joint venture companies, and/or approved third party product and service providers.

Such disclosure shall always be subject to a written agreement concluded between the Company and such other person (“The Recipient”) obligating The Recipient to comply with strict confidentiality, with all the information security conditions and provisions as contained in the Company POPI Policy.

Any requests from 3rd parties for Personal Information stored by The Company must be referred to the Information Officer.

  1. TRANSFER OF PERSONAL INFORMATION OUTSIDE OF SOUTH AFRICA 

The Company may be required to transfer Personal Information outside of the borders of South Africa, depending on the business needs.

If the Company transfers Personal Information outside of the South African borders it undertakes to transfer only to a recipient in a country that has in place similar privacy laws to POPIA or has binding corporate rules or binding agreements that provides the necessary privacy protection.

The requirements of POPIA Chapter 9, Section 72 will be adhered to at all times.

  1. RIGHT TO OBJECT TO THE PROCESSING OF PERSONAL INFORMATION 

All Data Subjects have the right to have their Personal Information processed in accordance with the eight conditions of lawful processing of Personal Information as set out in POPIA.

In terms of Section 11(3) of POPIA and in the prescribed manner, they also have the right, unless legislation provides for such processing, to object at any time to the Company processing their Personal Information, on reasonable grounds and relating to a particular situation.

On receipt of any notice of objection together with the reasons therefor, the Company is responsible to place any further processing of that data subject’s Personal Information on hold until the reason for the objection has been addressed and either:

In the event that the objection is upheld, no further processing of that data subject’s Personal Information shall be done by the Company.

Data Subjects also have the right to submit a complaint directly to the Information Regulator in terms of Section 74 of POPIA, alleging interference with the protection of their Personal Information.

  1. RIGHT TO WITHDRAW CONSENT FOR THE PROCESSING OF PERSONAL INFORMATION

In terms of Section 11(2) of POPIA, Data Subjects have the right to withdraw their consent to the Company processing their Personal Information.

This withdrawal is on the proviso that the lawfulness of the processing of their Personal Information before such withdrawal, if the processing is necessary to carry out actions for the conclusion or performance of a contract to which they are a party, will not be affected.

  1. RIGHT TO ACCESS PERSONAL INFORMATION 

Data Subjects have the right at any time to request the Company to provide them with:

Such request shall be made in writing to the Information Officer of the Company.

The data subject shall make the request in terms of Section 53 of PAIA and specifically, as set out in Form C of the PAIA Regulations of 2002 as amended, which standard PAIA Form is available on request from the Information Officer of the Company.

  1. RIGHT TO REQUEST CORRECTION, DESTRUCTION OR DELETION 

Data Subjects have the right to request the Company, where necessary, to correct and/or delete their Personal Information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.

Data Subjects also have the right to request the Company to destroy or to delete a record of their Personal Information that the Company is no longer authorised to retain.

Upon receiving either of the requests as set out above, the Company is responsible to follow the process as out in Section 24 of POPIA, which deals specifically with the correction of Personal Information.

  1. ACCURACY OF INFORMATION 

POPIA requires that all Personal Information and related details as supplied by Data Subjects are complete, accurate and up to date. Whilst the Company will always use its best endeavours to ensure that their Personal Information is reliable, it is the Data Subject’s responsibility to advise the Company of any changes to their Personal Information, as and when these changes may occur.

  1. DIRECT MARKETING, ADVERTISING AND PROMOTIONAL ACTIVITIES 

The Company undertakes not to further process any Personal Information for the purpose of marketing to Data Subjects any third-party products or other optional products.

Notwithstanding the above, the Company including its associated and holding companies may further process Personal Information for the purpose of providing Data Subjects with market news and/or the Company’s own products and services.

Should Data Subjects not wish to receive such communications from the Company, they will be provided with an opportunity to opt out of receiving any such communication.

The Company will maintain a register of all Data Subjects who have opted out of receiving any communication and/or marketing material.

  1. INFORMATION OFFICER AND DEPUTY INFORMATION OFFICER 

The Company Information Officer’s details are as follows:

Name: Dyelan Copeland

Address: 19 Kloof Road, The Kloof Mall, Shop 5, Bedfordview 2007

Tel: +27 11 568 1894

The Company Deputy Information Officer’s details are as follows:

Name: Charnia Yapp

Address: 19 Kloof Road, The Kloof Mall, Shop 5, Bedfordview 2007

Tel: +27 11 568 1894

The Information Officer’s and Deputy Information Officer’s duties and responsibilities will include all aspects as outlined and described in the following documents: