# POPIA Policy

**Legacy Risk Consult (Pty) Ltd**  
**Protection of Personal Information Act 4 of 2013**  
**Effective date:** 23 September 2026  
**Policy owner:** Dirk Coetzee, Information Officer  
**Review:** At least annually and following material changes or incidents.

## 1. Purpose and scope

Legacy must handle personal information responsibly throughout collection, use, sharing, storage and disposal. This policy applies to directors, employees, contractors and service providers handling personal information for Legacy, in digital or physical form.

It covers website enquiries and extends to other business processing only when the relevant activities, purposes, roles and safeguards have been documented. Personal information includes information about identifiable living individuals and, where applicable, existing juristic persons. Special personal information and children's information require additional assessment.

A **responsible party** determines the purpose and means of processing. An **operator** processes for a responsible party under authority and instructions. Legacy's role must be established per activity: it may be responsible for its own enquiries while acting as an operator for specified client administration. Describing Legacy as an operator must not conceal independent uses for which it is responsible.

## 2. Accountability and ownership

Management must allocate resources, maintain this policy and address identified risks. The Information Officer must oversee the compliance framework, rights requests, impact assessments, staff awareness and cooperation with the Regulator. Registration and any delegation to Deputy Information Officers must be addressed and documented. These governance responsibilities are described in the [Regulator's Information Officer guidance](https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-GuidanceNote-IO-DIO-20210401.pdf).

The website owner must maintain an accurate account of forms, trackers, hosting, logs and providers. Department owners must identify the personal information in their processes. Staff must use approved systems, follow access restrictions and report suspected misuse promptly.

**Designated public contact:** compliance@legacyconsult.co.za  
**Office:** 91 Lyttelton Road, Clubview, Centurion, Gauteng, 0157  
**Telephone:** +27 12 658 0464

## 3. Applying the eight processing conditions

| Condition | Required company practice |
| --- | --- |
| Accountability | Assign an owner and retain evidence of decisions and safeguards. |
| Processing limitation | Record a lawful ground; minimise collection and unjustified intrusions. |
| Purpose specification | Define each purpose before collection and set an appropriate retention rule. |
| Further-processing limitation | Review a proposed new use before repurposing existing records. |
| Information quality | Give staff and data subjects a practical correction route. |
| Openness | Keep processing records and provide understandable, accessible notices. |
| Security safeguards | Assess risks, implement proportionate controls and manage incidents. |
| Data-subject participation | Support lawful access, correction, deletion and objection requests. |

These are operational requirements based on [POPIA's conditions for lawful processing](https://inforegulator.org.za/knowledge-base/category/popia/chapter-3-conditions-for-lawful-processing/); publishing a policy alone does not implement them.

## 4. Processing inventory and assessments

The Information Officer must coordinate a register showing each activity's purpose, information categories, affected people, source, lawful ground, recipients, operator/responsible-party roles, locations, retention and controls.

The current website register must include the name/email enquiry fields; optional company, telephone, service and message fields; Vercel website hosting and measurements; the Resend delivery route to the Microsoft 365 business mailbox; and hosting, delivery and error logs.

Assess material changes before launch, including a new client portal, file upload, advertising tool, AI feature or data-sharing arrangement. Marketing descriptions of future or separate platforms do not establish what this public website processes.

## 5. Collection, notices and sensitive records

Form owners must collect only what the enquiry needs, distinguish required from optional fields, explain the consequences of not providing required information and place an accessible privacy notice at the collection point. Broad statements that submitting a form constitutes agreement to all processing must not be used as a substitute for a lawful ground.

Staff must not request member spreadsheets, medical records, identity documents or children's details through the public enquiry form. When such records are genuinely necessary for an authorised service, document the applicable special-information or children's-information permission, the appropriate recipient and transfer method, and any required notice or authorisation. Consent must not be assumed to cure every restriction.

Assess whether prior authorisation is required before starting processing covered by section 57, including relevant unique-identifier linking and certain overseas transfers of special or children's information. Apply any required statutory waiting or approval process. See the [Regulator's prior-authorisation resources](https://inforegulator.org.za/popia/).

## 6. Operators and international transfers

Before appointing an operator, the service owner must assess its role, access, security, subcontractors, retention and processing locations. Required written terms must address confidentiality, authorised processing, safeguards, incident escalation, assistance with requests and return or deletion of records. An operator must immediately notify Legacy where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

Record the basis for each cross-border transfer. Where relying on adequate protection, assess the applicable law or binding arrangement, including onward transfers; do not assume a foreign provider's general compliance statement is sufficient. Section 72 also recognises other specified grounds whose conditions must be met. See [POPIA's transborder provisions](https://inforegulator.org.za/knowledge-base/category/popia/chapter-9-transborder-information-flows/).

When Legacy is an operator, it must follow the responsible party's lawful instructions, assist that party, and avoid independent reuse of the information without a separately established lawful role and basis.

## 7. Security requirements

The operational security programme must include risk-appropriate access controls, account protection, staff confidentiality, secure transfer methods, patching, backup management and periodic review. Restrict enquiry-mailbox and provider-console access to people who need it. Remove access when responsibilities end.

Do not place personal information or secrets in public repositories, page URLs, analytics events or unnecessary application logs. Assess endpoint abuse protection and monitoring for the email-submission workflow. Staff must report misdirected emails, lost devices, exposed records and suspected account compromise through the incident process.

## 8. Retention and disposal

The standard retention period for enquiry and related business records is **five years**. This runs from enquiry closure where no engagement follows, the end of the relevant engagement for related client/service records, and request closure for privacy-request records.

The five-year period is a company policy rather than a universal statutory requirement. The record-specific schedule must identify the lawful justification, owner, trigger date, legal holds, backup expiry and disposal method. Apply shorter retention where continued processing is not justified and any longer retention required by law or justified by a documented hold or unresolved dispute. Assess separate financial-services and personnel records against their applicable requirements.

Apply the schedule to mailboxes, provider records, exports and backups as well as any application database. Record exceptions and review them. Retain only proportionate suppression information needed to honour marketing objections. A deletion request must be assessed against actual retention duties rather than rejected automatically or accepted with an unsupported promise of immediate erasure everywhere.

## 9. Rights and complaints

Provide an accessible route to submit requests, verify identity proportionately, identify relevant systems and document the decision. Confirm the applicable statutory process and deadline; explain any refusal, restriction or permitted fee. Assist with the prescribed forms or processes where applicable.

Where Legacy is only an operator, promptly route the request to the responsible party and assist under the contract without obscuring the identity of the correct contact.

Maintain a request register and escalation route. Data subjects may approach the [Information Regulator](https://inforegulator.org.za/complaints/) without being required by this policy to waive their remedies or complete an exclusive internal process.

## 10. Direct marketing and automated decisions

Separate enquiry responses from campaigns. For unsolicited electronic marketing, staff must establish valid consent or satisfy the limited existing-customer exception, provide sender details and an effective opt-out, and respect objections. Maintain evidence of the basis used. A purchased list or business email address does not by itself establish permission. See the [Regulator's direct-marketing guidance](https://inforegulator.org.za/wp-content/uploads/2020/07/GUIDANCE-NOTE-ON-DIRECT-MARKETING-IN-TERMS-OF-THE-PROTECTION-OF-PERSONAL-INFORMATION-ACT-4-OF-2013-POPIA.pdf).

No solely automated decision with relevant legal or substantial effects may be introduced without assessing POPIA's restrictions and safeguards, providing applicable explanations and an appropriate opportunity for representations. The current website enquiry workflow does not make such insurance decisions.

## 11. Security-compromise response

Staff must escalate suspected compromise immediately to the Information Officer and designated technical lead. The response team must contain exposure, preserve evidence, identify affected information and responsible parties, assess notification duties, and track remedial action.

Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, apply section 22. Notify the Regulator and affected data subjects as soon as reasonably possible, subject to the Act's qualifications, including identification of affected people and permitted delays. Do not substitute a GDPR-style blanket 72-hour rule or a high-risk-only reporting threshold. Notifications must provide the required useful information, including protective steps people can take.

The Regulator directs security-compromise reports through its [eServices portal](https://eservices.inforegulator.org.za/), as explained in its [security-compromise guidance](https://inforegulator.org.za/popia/). Where Legacy is an operator, immediately notify the relevant responsible party and assist it with reporting. Document decisions and corrective actions.

## 12. Implementation, training and review

Management must maintain the processing inventory and retention schedule, oversee operator and transfer arrangements, review safeguards, and maintain request and incident procedures. Maintain or prepare the separate PAIA manual as required; this policy is not that manual. See the [Regulator's PAIA resources](https://inforegulator.org.za/paia/).

Provide training relevant to each role. Review the policy annually and after a significant change, complaint or incident. Record approval, version history, identified gaps, owners and completion dates. Assess breaches of this policy fairly under applicable employment, contractual and legal processes.
