INFORMATION REGULATOR PRIVACY NOTICE

INTRODUCTION OR WHO WE ARE

The Information Regulator (Regulator) is an independent body established in terms of section 39 of the Protection of Personal Information Act 4 of 2013 (POPIA). It has jurisdiction throughout the Republic and is subject only to the Constitution and the law. It exists to protect the personal information of a data subjects when processed by public and private bodies (responsible parties) and promotes access to information. The Regulator is empowered to exercise its powers and perform its functions in accordance with POPIA and the Promotion of Access to Information Act 2 of 2000 as amended (PAIA).

This Privacy Notice is provided in accordance with section 18 (1) of POPIA. Its purpose is to inform data subjects about the personal information that the Regulator processes, or may process, in the course of fulfilling its regulatory mandate.

ABOUT THE REGULATOR’S PRIVACY NOTICE

The Regulator’s Privacy Notice is reviewed and updated periodically. Any changes made will be published on the Regulator’s website, and data subjects will be informed if the changes are significant. For the latest information or updates, please visit the Regulator’s website.

THE PURPOSE OF THE PRIVACY NOTICE

The purpose of this Privacy Notice is to outline how the Regulator collects, uses, processes, stores, shares, and protects personal information of data subjects in accordance with POPIA. This Privacy Notice is intended to:

  • Inform data subjects of their rights and obligations with respect to their personal information;
  • Ensure transparency in the way the Regulator handles personal information, whether relating to its staff, members of the public, service providers, or its stakeholders;
  • Set out its commitment to safeguarding data subjects’ personal information and promoting responsible personal information handling practices;
  • Provide guidance to its staff, service providers, and third parties on how to manage personal information lawfully and in an ethical manner; and
  • Demonstrate compliance with the 8 conditions for lawful processing of personal information.

SCOPE OF APPLICABILITY OF THE PRIVACY NOTICE

  • This Notice, unless otherwise stated or indicated, is applicable to:
    • The members of the public;
    • Service Providers or stakeholders who process personal information on behalf of the Regulator.

WHAT PERSONAL INFORMATION DOES THE REGULATOR COLLECT?

  • The Regulator collects and processes different attributes of data subjects personal information at specific points in its legislative and regulatory mandate or for internal business purposes such as complaints handling, POPIA and PAIA Compliance assessments, investigations, processing of payments, registration of Information Officers and Deputy Information Officers, training and community outreach programmes, audit purposes, media and communication purposes, stakeholder engagements, research purposes, detection and prevention of cybercrimes and fraud, legal proceedings, human resources, procurement of services, accountability by reporting to parliament. Below is a non-exhaustive list of personal information categories the Regulator collects and processes;
    • Identifying numbers (employee number, company registration number, ID number);
    • E -mail addresses, physical addresses, telephone or cell phone numbers;
    • Names, surnames, marital status, nationality, age, status, race, banking details, images and videos, disability, language, personal opinions and views of people based on research surveys conducted, implicit or explicit correspondence of a private or confidential nature, and date of birth;
    • Information submitted through forms, emails, or during investigations or POPIA and PAIA compliance assessments;
    • Information submitted through Dikopano events and other outreach programmes, such as training events.
  • Some of this information may be more commonly used in the Regulator’s recruitment processes than in its core regulatory functions:
    • Biometric information such as fingerprinting, particularly in its recruitment processes;
    • Information on data subjects race, ethnic or social origin, criminal recordings /proceedings;
    • Education, medical, financial, and employment information.
    • Records of correspondence or enquiries from any party acting on behalf of the Regulator.
  • To effectively and efficiently carry out its regulatory mandate in relation to both public and private bodies, particularly for recruitment and procurement purposes, the Regulator will require the personal information of data subjects.

WHY DOES THE REGULATOR COLLECT AND PROCESS PERSONAL INFORMATION OF DATA SUBJECTS?

  • The Regulator collects and processes personal information of data subjects for the following purposes:
    • To fulfil its legislative mandate under POPIA and PAIA;
    • To assess and investigate complaints and security compromise notifications from responsible parties, pertaining to alleged interference with the privacy of data subjects’ personal information;
    • To communicate with data subjects and keep them informed of the progress or outcome of their matter (s)/complaint (s);
    • To maintain records of complaints, investigations, decisions, and enforcement notices;
    • For recruitment purposes, appointment of service providers, events/trainings hosted by the Regulator and Human Resource Management & Administration (HRM & A);
    • For administrative, audit, and compliance purposes.

HOW IS PERSONAL INFORMATION OF DATA SUBJECTS COLLECTED BY THE REGULATOR.

  • The Regulator collects personal information of data subjects through various ways, including but not limited to the following:
    • Through complaints lodged in terms of section 74(1) of POPIA using Forms 1 to 11 and Form SCN1;
    • Through complaints lodged in terms of PAIA;
    • Through the PAIA internal appeal form;
    • PAIA requests lodged through the Information Officer (IO) and Deputy Information Officer (DIO);
    • Through requests for an assessment in terms of section 77H of PAIA;
    • Through Supply Chain Management (SCM) processes;
    • Through its community outreach programmes and attendance registers;
    • Through surveys and research conducted;
    • Through the registration of information officers and deputy information officers;
    • Through assessments in terms of section 89 of POPIA;
    • Through applications in terms of sections 26, 34,36 57,60 of POPIA;
    • When data subjects visit or browse its website;
    • When data subjects visit the Regulator’s business premises.

UNDER WHAT CIRCUMSTANCES WILL THE REGULATOR PROCESS SPECIAL PERSONAL INFORMATION OF DATA SUBJECTS?

  • The Regulator processes data subjects’ special personal information under the following circumstances, among others:
    • If the processing is needed to create, use or protect a right or obligation in law;
    • If the processing is necessary to carry out actions for the conclusion or performance of a contract to which the data subject is party;
    • If the processing is for statistical or research purposes, and all legal conditions are met;
    • If the processing protects a legitimate interest of the data subject;
    • If the information was made public by the member of the public/stakeholder /service provider;
    • If the processing is required by law;
    • If the racial information is processed and the processing is required to identify the member of the public/stakeholder/service provider;
    • If the member of the public has consented to the processing.

INFORMATION SECURITY

  • The Regulator is legally obliged to take reasonable steps to provide adequate protection for the personal information it holds in its possession and to prevent unauthorised access.
  • On an ongoing basis, the Regulator reviews its internal security controls and related processes to ensure that the personal information kept in its records, remains secure and that data subjects (natural and juristic persons) will be informed of any breaches in accordance with POPIA.
  • The Regulator’s records management and Information Communication and Technology (ICT) policies cover the following:
    • Computer and network security;
    • Access to information in terms of PAIA;
    • Security in contracting out activities or functions to external service providers (Operators);
    • Retention and disposal of information;
    • Monitoring Compliance with provisions of POPIA through Personal Information Impact Assessments (PIIA).

DATA SUBJECTS’ RIGHTS

  • Requests must be made in writing to the Regulator’s Deputy Information Officer to enquire or enforce these rights on the contact details provided in this Notice. Data subjects have the right to:
    • Request the Regulator, free of charge, to confirm whether it holds any personal information about the data subject, and to request access to such information as provided for in section 23;
    • Request the correction or deletion of their personal information, or that of any data subject, held by the Regulator that is inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained;
    • Object to how the Regulator processes their personal information;
    • Object to how the Regulator shares their personal information;
    • To be notified when their personal information is collected, in accordance with section 18 of POPIA, except in the circumstances outlined in section 18(4);
    • To be notified when there is a security compromise in accordance with section 22 of POPIA.
    • To ensure the Regulator obtains informed consent from data subjects/ competent person;
    • To withdraw their consent;
    • Information should be collected directly from the data subject in accordance with section 12 except in instances specified in section 12 (2);
    • Lodge a complaint with the Regulator regarding the processing of their personal information through the Deputy Information Officer’s contact details.
  • It is important to note that these rights are not absolute and must be balanced against competing rights. As such, they may be limited owing to the nature of the Regulator’s public interest mandate.

WITHDRAWAL OF CONSENT

  • In terms of section 11(2)(b) and (c) of POPIA, data subjects have the right to withdraw their consent to the processing of their personal information at any time, provided that such withdrawal:
    • does not affect the lawfulness of any processing carried out prior to the withdrawal; and
    • Is communicated to the responsible party in writing using the contact details provided below.
  • To withdraw their consent, they may submit their request by sending a written request using the contact details provided below.
  • Upon receipt of their request, the Regulator will;
    • Acknowledge receipt of their withdrawal within 48 hours;
    • Stop processing their personal information, except where processing is permitted or required by law; and
    • Notify data subjects of any consequences or limitations that may arise as a result of their withdrawal.

CONDITIONS UNDER WHICH THE REGULATOR MAY SHARE PERSONAL INFORMATION OF DATA SUBJECTS

  • The Regulator may share personal information of data subjects under the following circumstances:
    • With their consent;
    • If the information is available or derived from a public record or has deliberately been made public in accordance with section 15(3);
    • If it is necessary for the prevention, detection, prosecution, investigation of offences;
    • To comply with an obligation imposed by law;
    • If it is in the interest of national security;
    • If it is meant to prevent or mitigate serious threat to public health or safety or the life or health of another individual;
    • If it is used for research or statistical purposes;
    • External service providers who support our operations (e.g., IT, legal, auditing services) under strict confidentiality;
    • The courts, law enforcement, or regulators where disclosure is required by law.

RETENTION OF PERSONAL INFORMATION

  • The Regulator retains personal information and special personal information in strict compliance with section 14 of POPIA, as well as the provisions of the Regulator’s Records Management Policy No. 7/2/P of 18 November 2022.
  • In line with paragraph 8.6.1 of the Records Management Policy, records of personal information shall not be retained for any period longer than is necessary to fulfil the purpose for which the information was originally collected or subsequently processed.
  • Personal information of data subjects will be securely disposed of or de-identified once it is no longer required for the purposes for which it was collected, or when retention is no longer authorised by law.
  • The Regulator may retain records beyond the initial purpose for reasons including compliance with legal obligations, contractual requirements, provided such retention is in accordance with POPIA.

CORRECTION AND DELETION OF PERSONAL INFORMATION

  • Data subjects have the right to request the correction or deletion of personal information held by the Regulator where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • If data subjects believe that any personal information held by the Regulator about them is incorrect or requires deletion, they may submit a written request to the Regulator’s Information Officer or Deputy Information Officer using the contact details provided below.
  • Upon receipt of a data subjects request, the Regulator will take reasonable steps to investigate where appropriate, correct or delete the information within reasonable time.
  • The Regulator may require data subjects to verify their identity and provide reasons for their request and may decline their request were permitted or required to do so by law.

TRANSBORDER FLOW OF PERSONAL INFORMATION

  • Where necessary for the fulfilment of its mandate or as required by law, the Regulator may transfer personal information to foreign jurisdictions. Such transfers may take place, for instance, when cooperating with international regulatory authorities, foreign governments, or cross-border service providers.
  • In accordance with section 72 of POPIA, any cross-border transfer of personal information will only take place under one or more of the following conditions:
    • The recipient is subject to a law, binding corporate rules, or binding agreement which provides an adequate level of protection that is substantially similar to POPIA’s principles;
    • The data subject consents to the transfer;
    • The transfer is necessary for the performance of a contract with the data subject or in the interest of the data subject;
    • The transfer is for the benefit of the data subject, and it is not reasonably practicable to obtain their consent, and if it were, such consent would likely be given.
  • The Regulator will take reasonable steps to ensure that appropriate security safeguards are in place to protect the personal information that is transferred internationally.

NOTIFICATION OF SECURITY COMPROMISE

  • The Regulator will notify data subjects as soon as reasonably possible if it has reasonable grounds to believe that data subjects’ personal information has been unlawfully accessed or acquired by a third party.

AUTOMATED DECISION-MAKING AND PROFILING

  • In accordance with section 71 of POPIA, the Regulator does not engage in any form of automated processing of personal information that has the purpose of profiling, or that may result in decisions being taken which produce legal consequences, or which may significantly affect the data subjects.

COOKIES AND TRACKING TECHNOLOGIES

  • The Regulator’s websites and online platforms make use of cookies and similar tracking technologies, including third-party tools such as Google Analytics, to improve functionality, security, and the overall user experience.
  • Cookies are small text files stored on a data subject’s device when visiting a website. They assist the website in remembering user preferences, login details, and other settings to enhance usability.
  • Tracking technologies, such as Google Analytics, may automatically collect certain information about visitors, including:
    • Internet Protocol (IP) address;
    • Browser type and version;
    • Device and operating system information;
    • Pages visited and time spent on each page;
    • Click patterns, navigation paths, and referring websites; and
    • General geographic location inferred from the IP address.
  • This information is used for analytical and statistical purposes, to understand how users interact with the Regulator’s websites, measure usage patterns, identify content of interest, and detect or resolve technical issues. The data assists the Regulator in improving accessibility, performance, and service delivery through its online platforms.
  • The Regulator does not use tracking technologies to identify individual users or to collect personal information without consent. Information processed through third-party analytics tools is aggregated and anonymised before being used for analytical purposes.
  • Data subjects may manage or disable cookies and related tracking technologies in their browser settings. However, doing so may affect certain website functionalities or limit the user experience.