Phandu Communications A client-centric approach that aligns people, processes, and technology

Privacy Policy

Privacy Policy

Protection of Personal Information Policy — Phandu Communications
ISMS-012 · POPI Policy Process Owner & Authorised by the CEO Public
Information Security Management System

Protection of Personal Information Policy

Document ISMS-012
Effective 26 July 2026
Legislation PoPI Act (South Africa)

The PoPI Act treats your personal information as precious goods. This policy sets out how Phandu Communications collects, uses, protects and — when asked — deletes it, and what happens if that trust is broken.

Governs
Employees, volunteers, board & committee members
Response window
7 days for individual access requests
Retention ceiling
7 years, unless law requires longer
01

Purpose

The purpose of the PoPI Act (Protection of Personal Information Act) is to ensure that all South African institutions responsibly conduct themselves when collecting, processing, storing, and sharing another entity's personal information — by holding them accountable should they abuse or compromise one's personal information in any way.

02

Preamble

The PoPI legislation considers personal information to be "precious goods", and bestows on its owner certain rights of protection and control over:

  • Consent — when and how one chooses to share one's information
  • Purpose — the type and extent of information shared, collected only for valid reasons
  • Transparency — accountability on how data is used, and notification if it's compromised
  • Access — the right to see one's own information, and to have it removed or destroyed
  • Who — controls to track access and prevent unauthorised persons, even within the same company
  • Storage — measures to safeguard information from theft or compromise
  • Accuracy — information must be captured correctly and kept up to date

Examples of personal information for an individual could include:

Identity / passport number
Date of birth & age
Phone number(s)
Email address(es)
Online / IM identifiers
Physical address
Gender, race & ethnic origin
Photos, voice & video, biometrics
Marital status & family relations
Criminal record
Private correspondence
Religious / philosophical beliefs
Employment history & salary
Financial information
Education information
Health information
Union / organisation membership
Note: some personal information on its own does not let a third party confirm or infer identity. The Act calls information that does a "unique identifier" — data that uniquely identifies a data subject in relation to a responsible party. A name combined with a phone number or email is far more significant than either alone.

We live in a progressive information age, and each person carries responsibility for protecting their own information — one cannot accuse an institution of compromising information that was already published on social media or in public directories. The PoPI Act cannot protect one if one does not take care to protect oneself.

This right extends beyond individuals to any legal entity — companies, communities, and other organisations are all "data subjects." As a company, Phandu Communications is also a "responsible party," obligated to protect the information of its employees, suppliers, vendors, service providers and business partners.

Incorporating PoPI into daily operations takes real time and effort: training staff, updating processes, and implementing technology safeguards. Early action matters — under the Act, something as ordinary as syncing phone contacts, emailing sensitive content, or sharing a photo can carry legal weight.

03

Accountability

  1. 3.1
    A Personal Information Compliance Officer (the "Officer") must be appointed in writing by the CEO.
  2. 3.2
    The Officer forms a Review Committee of at least 3 people who fully understand the Act and this Policy, to attend to any appeals.
  3. 3.3
    Everyone who collects, processes, or uses personal information — employees, volunteers, board or committee members — is accountable to the Officer, and must be advised of this in writing along with a copy of this policy.
  4. 3.4
    This policy is available via phandu.co.za, or as a paper copy on written request.
  5. 3.5
    Information transferred to a third party for processing remains subject to this Policy; the Officer uses contractual means to hold the third party to an equivalent standard of protection.
  6. 3.6
    Personal information is only collected, retained, or used after the Officer's written approval, and secured per the Officer's instruction.
  7. 3.7
    Anyone who believes their information is being used beyond what they explicitly approved may contact the Officer to register a complaint or inquiry.
  8. 3.8
    The Officer promptly investigates complaints and reports back on findings and any corrective action.
  9. 3.9
    A dissatisfied complainant may appeal to the Review Committee.
  10. 3.10
    The Review Committee's determination is final, and the Officer implements its recommendations.
  11. 3.11
    The Officer communicates, explains, and trains staff and volunteers on this policy.
  12. 3.12
    The Officer prepares and shares public-facing information on Phandu Communications' data protection policies and procedures.
04

Identify purposes

  1. 4.1
    The Officer documents why personal information is collected, in line with the openness and individual access principles.
  2. 4.2
    The Officer determines only the information genuinely needed to fulfil that purpose, per the limited collection principle.
  3. 4.3
    The purpose is specified at or before the point of collection.
  4. 4.4
    Information is not reused for a different purpose without approval, unless required by law.
  5. 4.5
    Anyone collecting information can explain to the individual why it's being collected.
  6. 4.6
    Limited collection, use, disclosure, and retention principles are respected throughout.
05

Consent

  1. 5.1
    The individual consents to their information being collected, used, and disclosed.
  2. 5.2
    The individual reasonably understands who will use their information and how, at the point consent is given.
  3. 5.3
    Access to Phandu Communications' benefits is never conditional on consenting to collection beyond what the stated purpose requires.
  4. 5.4
    Express consent is obtained wherever possible; implied consent is acceptable only in rare cases, at the Officer's discretion.
  5. 5.5
    The individual's reasonable expectations are respected — e.g. a newsletter sign-up shouldn't quietly become a fundraising list.
  6. 5.6
    Express consent is captured clearly, in a verifiable format.
  7. 5.7
    Consent can be withdrawn at any time, subject to legal or contractual limits and reasonable notice; withdrawal implications are explained promptly.
06

Limiting collection

  1. 6.1
    Information is never collected indiscriminately — the Officer specifies exactly what type is needed, and only that much.
  2. 6.2
    Collection uses only fair and lawful means, with no misleading or deceptive framing.
  3. 6.3
    The identifying-purposes and consent principles govern every collection decision.
07

Limiting use, disclosure & retention

  1. 7.1
    Information is never used or disclosed beyond its original purpose, except with consent or where law requires it — and every use is documented.
  2. 7.2
    Information is destroyed, erased, or anonymised as soon as its purpose is no longer relevant, or as law permits.
  3. 7.3
    Retention need is reviewed annually. Unless law requires otherwise, all personal information is deleted, erased, or anonymised no later than 7 years after its purpose is complete.
  4. 7.4
    Erasure uses acceptable methods — mechanical shredding, permanent deletion of cloud records, and similar.
  5. 7.5
    All use, disclosure, and retention decisions honour the consent, identifying-purposes, and individual-access principles together.
08

Accuracy

  1. 8.1
    Information is kept accurate, complete, and up to date enough that it can't lead to an inappropriate decision about an individual.
  2. 8.2
    Information is not routinely updated unless doing so is necessary to fulfil its original purpose.
  3. 8.3
    Information used on an ongoing basis, including anything disclosed to third parties, stays accurate and current unless limits are clearly documented.
09

Safeguards

  1. 9.1
    Security safeguards protect information — in any format — against loss, theft, unauthorised access, disclosure, copying, use, or modification.
  2. 9.2
    Protection scales with sensitivity: more sensitive information gets a higher level of safeguard.
  3. 9.3
    Protection methods span three layers:
    • Physical — locked filing cabinets, key registers, restricted office access
    • Organisational — security clearance, need-to-know access limits
    • Technological — passwords and encryption
  4. 9.4
    All employees and volunteers understand the importance of keeping personal information confidential.
  5. 9.5
    Disposal and destruction are handled carefully, so unauthorised parties can't gain access.
10

Openness

  1. 10.1
    Phandu Communications is open about its policies and practices, available without unreasonable effort and in generally understandable form.
  2. 10.2
    Available information includes:
    • The Officer's name/title and address, for complaints or inquiries
    • How to gain access to personal information held
    • What type of information is held, and a general account of its use
    • Any brochures explaining policies, standards, or codes
    • What information is shared with related/affiliated organisations
  3. 10.3
    This information is available as a brochure at Phandu Communications' locations, online, or by mail.
11

Individual access

  1. 11.1
    On request, Phandu Communications confirms whether it holds information about an individual, where possible its source, how it has been used, and which third parties it's been disclosed to. (If the Officer believes access should be denied, legal counsel is consulted first.)
  2. 11.2
    A requester may need to provide enough detail to allow the Officer to account for the existence, use, and disclosure of the information — which is then used only for that purpose.
  3. 11.3
    Where information has been disclosed to third parties, the Officer is as specific as possible; where an exact list isn't feasible, a list of organisations it might have been disclosed to is provided instead.
  4. 11.4
    Requests are answered within 7 days of receipt, at minimal or no cost, in generally understandable form — with abbreviations or codes explained.
  5. 11.5
    Where an individual demonstrates inaccurate or incomplete information, it is corrected, deleted, or added to as required.
  6. 11.6
    Where a challenge isn't resolved to the individual's satisfaction, its substance is recorded — and, where appropriate, passed on to third parties who have access to that information.
12

Challenging compliance

  1. 12.1
    The Officer is authorised to address any challenge concerning compliance with the above principles.
  2. 12.2
    The Officer develops procedures to receive and respond to complaints or inquiries about these policies and practices.
  3. 12.3
    Compliance procedures are kept easily accessible and simple to use.
  4. 12.4
    Individuals inquiring about complaints are told the relevant procedure exists.
  5. 12.5
    All complaints are investigated; justified complaints lead to corrective measures, including amending this Policy where necessary.
13

Discipline

Any employee or manager who fails to adhere to this policy and procedure may be subject to disciplinary action.

ISMS-012 POPI Policy · 26 July 2026 Process Owner & Authorised by the CEO Printed copies are uncontrolled — consult the electronic system for the latest version
Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare