All documents are pre-filled. Review, customise, and download.
How your business collects, uses, stores, and shares personal information. Required under POPIA Section 14.
[Your Company Name] ("we", "us", "our") is committed to protecting the privacy and personal information of all individuals ("data subjects") whose information we collect, use, and store in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA").
We collect the following categories of personal information:
We process personal information for the following purposes:
We process personal information based on:
We may share your information with:
We implement appropriate technical and organisational measures to protect personal information against unauthorised access, loss, destruction, or damage. These measures include encryption, access controls, firewalls, and regular security assessments.
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are set out in our Data Retention Schedule.
You have the right to:
For any queries regarding this policy or your personal information, contact our Information Officer:
We may update this policy from time to time. Any material changes will be communicated to you via email or notice on our website. Last updated: [Date]
Promotion of Access to Information Act manual. Required for public bodies, recommended for private companies.
This Manual is published in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000 ("PAIA") to assist persons who wish to request information from [Your Company Name].
The following categories of records are held:
To request information, complete Form A (attached) and submit it to the Information Officer. A fee of R35 may apply. Requests will be processed within 30 days.
Requests may be refused on the following grounds:
If a request is refused, the applicant may lodge an internal appeal within 60 days. If still dissatisfied, a court application may be made.
Templates for employee, customer, supplier, and website consent. POPIA compliant opt-in language.
I, [Employee Name], hereby consent to [Company Name] processing my personal information for the following purposes:
I understand that:
Signature: _________________
Date: _________________
I, [Customer Name], consent to [Company Name] processing my personal information for:
I consent to receiving marketing communications
Signature: _________________
Date: _________________
I, [Supplier Name], consent to [Company Name] processing my/our business and personal information for:
Signature: _________________
Date: _________________
By using this website, you consent to the collection and processing of your personal information as described in our Privacy Policy. We collect:
Electronic Communications: By submitting your information, you consent to receiving electronic communications from us in terms of the Electronic Communications and Transactions Act.
Forms for access, correction, deletion, and objection requests under POPIA Sections 23-25.
To: Information Officer, [Company Name]
From: [Data Subject Name]
ID Number: [ID Number]
I hereby request access to all personal information held about me by [Company Name], including:
Signature: _________________
Date: _________________
I, [Data Subject Name], request the correction of the following personal information held by [Company Name]:
Signature: _________________
Date: _________________
I, [Data Subject Name], request the deletion of all personal information held about me by [Company Name].
Reason for request: _________________
I understand that deletion may not be possible where retention is required by law.
Signature: _________________
Date: _________________
I, [Data Subject Name], object to the processing of my personal information for the following purpose(s):
Signature: _________________
Date: _________________
Technical and organisational safeguards to protect personal information. POPIA Section 19.
This policy sets out the technical and organisational measures [Company Name] implements to protect personal information against unauthorised access, loss, destruction, or damage.
We collect only the minimum personal information necessary for the stated purpose. Data is anonymised where possible and deleted when no longer required.
In the event of a data breach, we will:
This policy is reviewed annually by the Information Officer and updated as necessary. Last reviewed: [Date]
Step-by-step guide for reporting data breaches to the Information Regulator and affected data subjects.
A data breach includes any unauthorised access to, or acquisition, disclosure, or destruction of, personal information. This includes:
If there is a reasonable risk of harm to data subjects, notify the Information Regulator "as soon as reasonably possible" using the prescribed form. Include:
If notification is required, communicate to affected individuals "without undue delay" via email, letter, or public notice. Include:
Within 30 days, conduct a full review: root cause analysis, lessons learned, policy updates, and staff retraining.
Data processing agreement for third-party vendors and service providers. POPIA Section 21.
This Agreement is between [Company Name] ("Responsible Party") and [Operator Name] ("Operator").
The Operator will process personal information on behalf of the Responsible Party for the following purpose: [Describe service]
The Operator agrees to:
The Operator shall implement at minimum the security measures specified in Annexure A of this agreement.
The Operator may not engage sub-operators without prior written consent of the Responsible Party.
This agreement commences on [Date] and continues until [Date] or until terminated by either party with 30 days written notice. Upon termination, all personal information must be returned or securely deleted.
Responsible Party: _________________
Date: _________________
Operator: _________________
Date: _________________
Record of all processing activities involving employee personal information. POPIA Section 17.
| Category | Details |
|---|---|
| Categories of data subjects | Current employees, former employees, job applicants, contractors |
| Categories of personal information | Name, ID number, contact details, bank details, tax number, qualifications, employment history, performance records, disciplinary records, medical information (if applicable) |
| Recipients | Payroll provider, SARS, UIF, COIDA, medical aid, pension fund, professional bodies |
| Cross-border transfers | None (unless specified) |
| Retention period | 5 years after employment ends (tax records); 3 years (general HR records); indefinitely (proof of employment) |
| Security measures | Access controls, encryption, secure storage, confidentiality agreements |
Record of all processing activities involving customer personal information.
| Category | Details |
|---|---|
| Categories of data subjects | Current customers, potential customers, website visitors, marketing contacts |
| Categories of personal information | Name, email, phone, address, ID number (if required), payment information, purchase history, communication preferences, website usage data |
| Recipients | Payment gateway, delivery services, accounting services, marketing platforms |
| Cross-border transfers | None (unless payment processor requires it) |
| Retention period | 5 years after last transaction (tax records); 3 years (marketing records); until consent withdrawn (opt-in lists) |
| Security measures | Encryption, access controls, secure payment processing, data minimisation |
How long different types of personal information must be kept, and when it must be deleted or anonymised.
| Data Category | Retention Period | Legal Basis | Disposal Method |
|---|---|---|---|
| Employee records | 5 years after termination | Income Tax Act, BCEA | Secure shredding, digital wipe |
| Payroll records | 5 years | Income Tax Act, UIF Act | Digital wipe, archive if required |
| Customer financial records | 5 years | Income Tax Act, VAT Act | Digital wipe |
| Customer personal data | 3 years after last interaction | POPIA legitimate interest | Digital wipe, anonymise for analytics |
| Marketing contacts | Until consent withdrawn | POPIA consent | Remove from all lists immediately |
| CCTV footage | 90 days (unless incident) | POPIA data minimisation | Automatic overwrite, incident footage retained |
| Website analytics | 26 months (anonymised) | POPIA legitimate interest | Anonymise IP addresses, aggregate data |
| Supplier records | 5 years after last transaction | Income Tax Act | Digital wipe |
How to handle electronic marketing opt-outs. POPIA Section 69 + ECTA Section 45.
Direct marketing by electronic means requires prior consent. You must provide a clear opt-out mechanism in every marketing communication. Opt-out requests must be processed within a reasonable time.
Every marketing email, SMS, or WhatsApp message must include:
Maintain records of all opt-out requests, including date, method, and confirmation sent. These records may be required as evidence of compliance.
To opt out of marketing communications, provide your email or phone:
Email: [text field]
Phone: [text field]
What cookies your website uses, why, and how users can manage them. POPIA + ECTA.
Cookies are small text files placed on your device when you visit a website. They help the website remember your preferences and improve your experience.
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics — distinguishes unique users | 2 years |
| _gid | Google Analytics — distinguishes unique users | 24 hours |
| session | Maintains your session state | Session only |
| cookie_consent | Remembers your cookie preferences | 1 year |
You can control and delete cookies through your browser settings. Note that disabling cookies may affect website functionality.
What to do when a data breach occurs. Roles, responsibilities, and step-by-step response.
| Role | Name | Contact |
|---|---|---|
| Information Officer (Lead) | [Name] | [Email/Phone] |
| IT Security | [Name] | [Email/Phone] |
| Legal Counsel | [Name] | [Email/Phone] |
| Communications | [Name] |
| Organisation | Contact Details |
|---|---|
| Information Regulator (SA) | Tel: 010 023 5207 | Email: enquiries@justice.gov.za |
| South African Police Service | Crime Stop: 08600 10111 |
| Cybersecurity Hub | Tel: 0860 234 567 |
© 2026 MY-LO · POPIA Compliance Pack · All documents are templates — customise with your business details
13. Social Media Policy
Rules for employees using social media. Protects company data and reputation. POPIA compliant.
1. Purpose
This policy sets guidelines for employee use of social media to protect the company's data, reputation, and compliance with POPIA.
2. Personal Social Media
3. Company Social Media
4. POPIA Compliance
5. Consequences
Breaches of this policy may result in disciplinary action, including termination. Serious breaches may also result in legal liability.