VAUGHAN ULYATE & ASSOCIATES POPIA COMPLIANCE POLICY
1. INTRODUCTION
1.1 We (Vaughan Ulyate & Associates) process personal information and other confidential information of individuals and juristic persons (whether they are our clients or third parties) to deliver legal services to our clients. The nature of the personal information which we process, depends on the legal service we render in each matter, as well as the legislative requirements to be adhered to by us.
1.2 We are obliged to process personal information in accordance with the provisions of the Protection of Personal Information Act, No. 4 of 2013 (‘the POPI Act’), and we hereby declare our firm’s commitment to comply with the POPI Act when processing personal information and special personal information, as defined herein below. This POPIA policy (together with any supplementary policies) shall apply until such time as we replace it with a new one.
2. WHEN AND HOW INFORMATION WILL BE COLLECTED AND PROCESSED
2.1 The POPI Act is intended to balance two competing interests, namely the constitutional rights of individuals to privacy, and the needs of our society to have reasonable access to and to process personal information for legitimate purposes, including the purpose of doing business.
2.2 We will therefore only process (as defined herein below) personal information in a lawful and reasonable manner which do not unfairly infringe on the privacy of our clients or other data subjects. The purpose of the collection and processing must be adequate, relevant and not excessive.
2.3 Personal information may only be processed if the data subject (or his or her parent or guardian, where the data subject is a child) consents thereto, which consent may at any time be withdrawn. A data subject may at any time object, in the manner as prescribed by the POPI Act, to the processing of personal information, whereafter the information may, subject to paragraph 2.4 hereof below, no longer be processed.
2.4 In terms of the POPI Act, personal information may in the following circumstances be processed in the absence of consent from the data subject, namely where the processing is necessary for the conclusion or performance of a contract, where the processing is necessary to comply with an obligation imposed by law, or where the processing is necessary to protect or pursue the legitimate interests of either the data subject, the responsible party or of a third party to whom the information is supplied.
2.5 Personal information must be obtained directly from the data subject unless the data subject has consented to the use of another source, or where the information is derived from a public record or if the data subject has made the information public on, for instance, social media, or where the collection of the information would not prejudice a legitimate interest of the data subject, or where the collection of the information is necessary to comply with an obligation imposed by law or for the conduct of existing or reasonably contemplated legal proceedings or to maintain the legitimate interests of the responsible party or of a third party, or where compliance is not reasonably practical in the circumstances.
2.6 When you contact us by email, telephone, post, telefax, electronic or other means of communication, we collect, store, use and keep record of certain personal information that you disclose to us. This may include details such as your names, identity number, address, telefax number, telephone number and email communication data. By providing us with your personal information, you authorise us and associated entities or third parties (where applicable) to process such information as set out herein.
2.7 Apart from the above-mentioned limitations on the processing of personal information, as well as any limitations mentioned herein below, the POPI Act requires us to obtain prior authorisation from the Information Regulator if we intend to process unique identifiers of data subjects (such as bank account, policy, identity, employee and contact numbers) with the aim of linking it together with information processed by other responsible parties, if we intend to process information on criminal behaviour on behalf of third parties, if we intend to process information for purposes of credit reporting or if we intend to transfer special personal information or personal information about children to a third party in a foreign country that does not provide an adequate level of protection of personal information (safe to the extend that the Information Regulator has issued a code of conduct or exemption for a specific sector of society).
3. PURPOSE OF PROCESSING PERSONAL INFORMATION
3.1 In terms of the POPI Act, personal information may only be collected for a specific, explicitly defined and lawful purpose related to a function or activity of the responsible party, and we are committed to only processing information for the aforesaid type of purpose. As set out more fully in paragraph 7.1 hereof below, and subject to the provisions of paragraph 7.3 hereof below, reasonably practical steps must be taken to ensure that the data subject is aware of the purpose of the collection and (further) processing of the personal information (and we hereby accordingly inform you of such purpose in the following paragraphs of this section of our POPIA compliance policy).
3.2 We process personal information primarily to deliver legal services to our clients and/or in connection with legal proceedings. We also process personal information when, inter alia, we have to process the application of someone who applies for employment at our firm, for audit and record keeping purposes, for the detection and prevention of fraud, crime, money laundering or other malpractices, to deal with your requests and enquiries about personal information held by us and to update this information, in connection with and/to comply with legal and regulatory requirements (for example the requirements of the Financial Intelligence Centre Act no. 38 of 2001), to conduct client satisfaction research or when it is otherwise required by law.
3.3 Special rules apply to the collection and use of information relating to children or to a person’s religious or philosophical beliefs, their race or ethnic origin, their trade union membership, their political persuasion, their health or sex life, their biometric information, or their criminal behaviour (which the POPI Act defines as special personal information). In line with the requirements of the POPI Act, we do not process the personal information of a child or special personal Information about a data subsect unless the data subject (or his or her parent or guardian, where the data subject is a child) consents thereto, alternatively where it is necessary to establish, exercise or defend a right or obligation in law (for example if we have to process information relating to your health as part of our Covid-19 screening process when you access our premises), where processing is necessary to comply with an obligation of public international law, where processing is for historical, statistical or research purposes to the extent that its purpose serves an essential public interest or it appears to be impossible or would involve a disproportionate effort to ask for consent to process the information for such historical, statistical or research purposes (in which case there must be sufficient safeguards to ensure that the processing does not adversely affect the individual privacy of the data subject to a disproportionate extent), or where the information has been deliberately made public by the data subject (with the consent of his or her guardian, where the data subject is a child).
3.4 Our firm currently does not generally make use of direct marketing methods, but we undertake to not process your personal information for purposes of direct marketing unless you have consented thereto and/or elected to receive such marketing material or newsletters from us, alternatively if you are an existing client, in which latter case you will have the opportunity, free of charge, to object (at the time of collecting your information and on occasion of each direct marketing communication), to the (further) use of your personal information for direct marketing purposes and/or to receive such marketing communications. In terms of the POPI Act, the processing of personal information for direct marketing by means of electronic communications is limited to the responsible party’s own similar products and services (i.e. your personal information may not be shared with third parties for the aforesaid purposes).
4. RETENTION AND DELETION OF PERSONAL INFORMATION
4.1 As provided for in the POPI Act, we will retain your personal information for as long you permit us to do so and/or until such time as we no longer reasonably require the record for lawful purposes related to our functions or activities and/or in accordance with the provisions of any applicable legislation.
4.2 Please note that we are obliged by law to retain our client file contents (and by extension the personal information contained therein) for at least seven years from the date of the “closure” of the file. In terms of the applicable law, a Notary Public must retain copies of all notarial deeds which were executed in his or her presence until such time as he or she ceases to practice as an Attorney/Notary Public, whereafter he or she must lodge his or her protocol with the relevant Registrar of the High Court.
4.3 We will destroy or delete a record of personal information or de-identity it as soon as is reasonably practical after the personal information is no longer necessary for achieving the purpose for which the information was collected and subsequently processed and/or as soon as we are no longer authorised to retain the record. As required by the POPI Act, the destruction of the information will be final and/or done in a manner that prevents its reconstruction in an intelligible form.
5. SHARING OR TRANSFER OF PERSONAL INFORMATION
5.1 We undertake to only share and/or further process your personal Information if it is essential to do so and/or in accordance with the purpose for which it was collected (i.e. to render legal services to our clients). Before sharing and/or further processing your information, we will also first consider the legitimate interests of all concerned, the nature of the information concerned, the consequences of the intended further processing for the data subject, the manner in which the information has been collected and the contractual rights and obligations between all relevant parties.
5.2 We also undertake to not share or further process personal information of the data subject without his or her consent, save in certain prescribed circumstances. Please note that in certain circumstances we must share personal information with third parties, including existing or reasonably contemplated legal proceedings, as well as the further processing of information to comply with an obligation imposed by law. The POPI Act also allows responsible parties to further process information where, inter alia, the information is derived from a public record or has been deliberately made public by the data subject, where it is in the interests of national security / public safety, where it is necessary to prevent a serious and imminent threat to the life or health of the data subject or another individual, or where the further processing of the information is in accordance with an exemption granted by the POPI Information Regulator.
5.3 We aim to have agreements in place with all our service providers to ensure that the personal information that we remain responsible for, is safeguarded by them. Anyone to whom we pass on your personal information, will be required to treat your information with the same level of protection as we are obliged to do.
5.4 We may need to transfer your personal information to another country for processing or storage of data or when it is otherwise required for the performance of our mandate or contract with you and/or to render legal services to you (or for the implementation of pre-contractual measures taken in response to your request for our services), or whenever such processing is required for the conclusion or performance of a third party contract which is to your benefit. The aforesaid transfer may, for example, happen when we transmit emails using reputable international email servers or store information on a secure cloud storage facility. Safe for the aforesaid circumstances of transborder information transfers, the POPI Act also permits us to, without your consent, transfer information outside of the Republic of South Africa if the third party offers similar protection of personal information, or where the transfer of the information is for your benefit and it is not reasonably possible to obtain consent (provided that if it were otherwise possible to obtain your consent, you would likely have given consent).
5.5 We will, however, where appropriate (having due regard to the content of the preceding sub-paragraphs as well as paragraph 7 hereof below), always attempt to obtain your prior consent to a transborder transfer of information. Transborder transfers of information will only be done in limited circumstances and in strict adherence with the requirements of the POPI Act and other relevant national and (where applicable) international laws. As set out more fully below, we will take reasonable measures to adequately protect all your personal information.
6. QUALITY OF INFORMATION
6.1 As required by the POPI Act, we will endeavour to take all reasonably practical steps to ensure that the personal information of clients and other relevant data subjects is complete, accurate, not misleading and updated where necessary.
6.2 In taking the last-mentioned steps, we will have regard to the purpose for which the information is collected or further processed. Where appropriate, we will verify information through documentary proof.
7. OPENNESS / NOTIFICATION TO DATA SUBJECT WHEN PROCESSING INFORMATION
7.1 As required by the POPI Act and subject to the provisions of paragraph 7.3 hereof below, we commit ourselves to taking all reasonably practical steps to ensure that our clients and other data subjects are aware of personal information being collected and/or (further) processed, the source of the information and its contact details (if not collected from the data subject), the purpose for which it is collected and/or (further) processed, whether the supply of the information is voluntary or mandatory, the consequences of a failure to provide the information, any particular law authorising or requiring the collection and/or (further) processing of the information, whether we intend to transfer the information to a another country or an international organisation (in which case we will have to explain the protection which the information will have in such foreign country), or any further relevant information such as the recipient of information.
7.2 The steps as referred to in paragraph 7.1 hereof above must be taken before the personal information is collected, in the event of the information being collected directly from the data subject, unless the data subject is already aware thereof, or in any other case either before or as soon as is reasonably practical after its collection.
7.3 In terms of the POPI Act, it is not necessary for a responsible party to comply with the provisions of paragraph 7.1 hereof above if, inter alia, the client or another data subject (or his or her parent or guardian, where the data subject is a child) has provided consent for the non-compliance, or where non-compliance would not prejudice the legitimate interests of the data subject, or where non-compliance is necessary to comply with an obligation imposed by law (for example, the disclosure of personal information to law enforcement agencies or institutions such as the Financial Intelligence Centre and SARS), or where it is required for the conduct of existing or reasonably contemplated legal proceedings, or where compliance would prejudice a lawful purpose of the collection, or where compliance is not reasonably practical in the circumstances of the particular case, or where the information will be used in a form in which the client or another data subject cannot be identified.
8. SAFEGUARDING OF PERSONAL INFORMATION
8.1 We are required to secure the integrity and confidentiality of personal information in our possession or under our control by taking appropriate, reasonable technical and organisational measures to adequately protect all the personal information we hold, to prevent a loss and damage thereof and to avoid unauthorized access, destruction and use of such personal information.
8.2 To comply with this requirement, we established and intend to maintain reasonable industry-standard physical, electronic and procedural safeguards in respect of the personal information we collect, store, disclose and destruct. These include the protection of our business premises by means of access control, burglar alarms and armed response, storing archived files behind locked and access-controlled doors, protecting our computers with passwords, having our servers backed up on a regular basis, and using internationally recognised email infrastructure, firewalls and antivirus software. Our staff will receive appropriate training about the POPI Act and they will be contractually obliged to carry out their duties in compliance with the Act, including the observance of security measures and maintaining confidentiality in respect of information. A breach of this policy will be viewed as a serious disciplinary offence.
8.3 Vulnerability assessments will also be conducted on at least an annual basis of all reasonably foreseeable internal and external risks to personal information. We will furthermore regularly verify that our safeguards are effectively implemented and ensure that the safeguards are continually updated in response to new risks or potential deficiencies in previously implemented safeguards.
8.4 A lot of our written communication with clients and third parties occur via the internet and/or email. Although we have implemented generally accepted and up-to-date electronic communication safety measures, the internet is not entirely secure and we therefore cannot unconditionally guarantee the security of any information you provide to us via email, social media, or other communication platforms. Should you be particularly concerned about the safety of specific personal information you intend to send to us, you should liaise with your contact person at our firm regarding the appropriate communication platform to be used.
8.5 In the unlikely event of an information security breach involving your personal information, we will inform both you and the Information Regulator thereof as soon as is reasonably possible, just as our staff will be contractually obliged to inform us whenever there are reasonable grounds to believe that the personal information of a client or another data subject has been accessed by an unauthorised person. We will in such event also take all reasonable measures to limit any possible damage which may arise from such breach and inform you of the possible consequences of the security breach, what you yourself can do to mitigate the adverse effects of the breach and (if known) the identity of the person who may have unlawfully accessed or acquired the personal information. Notification of a breach may only be delayed where the Information Regulator or another relevant public body determines that an immediate notice will impede a criminal investigation or compromise their legitimate needs.
9. ACCESS TO AND AMENDMENT OF PERSONAL INFORMATION HELD BY US (CLIENT / DATA SUBJECT PARTICIPATION)
9.1 You (our client/another data subject) have the right to, after having provided adequate proof of identity, know whether we hold any personal information about you, which feedback will be given free of charge. Such a request must be made in accordance with Section 53 of the Promotion of Access to Information Act, No. 2 of 2000 (“PAIA”).
9.2 You furthermore have the right to request a copy of such record or a description of the personal information which we hold, including which third parties may have had access to the information, but the POPI Act allows responsible parties to charge a reasonable fee in the aforesaid regard (no specific amount is currently prescribed by the Information Regulator). We will furnish, in writing, either an estimate of the expected variable fee or a fixed fee (and whether we require payment of a deposit for all or part thereof) before furnishing the aforesaid information. The amount will ultimately depend on, inter alia, the extent of the records and information to be provided.
9.3 In terms of Chapter 4 of Part 3 of PAIA, we are in certain circumstances obliged to refuse access to records and information (or the relevant parts thereof). These circumstances include information which are privileged from production in legal proceedings, unless the person entitled to privilege has waived his or her privilege, as well as situations such as where the disclosure of the information could reasonably be expected to endanger the life or physical safety of an individual or the public.
9.4 You also have the right to request, in the prescribed manner, a correction or deletion of your personal information if it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, or if we are no longer authorised to retain it on any of the grounds as set out under paragraphs 2.4 and 4 hereof above. On receipt of any such request, we will process it as soon as is reasonably practical and inform you of the action that has been taken pursuant to your request. In terms of the POPI Act, such action includes correcting or deleting such information, providing credible evidence (to the satisfaction of the data subject) in support of the accuracy of the information, and/or attaching a note to the record to reflect that a request for an amendment has been requested but not made.
9.5 Please contact our Information Officer, Mrs. Leonore Kotze, should you have any further queries about our privacy policy, or wish to request a copy of your personal information, or require a correction or deletion of such information and/or to access the prescribed forms. You can send an email to leonore@vaughanulyate.co.za or ask our switchboard (021 914 1686) to direct your phone call. It is the responsibility of our Information Officer, as well as anyone else from within our firm who may be appointed as Deputy Information Officers, to ensure that we always comply with the POPI Act.
10. NON-COMPLIANCE AND COMPLAINTS TO THE INFORMATION REGULATOR
10.1 If we do not satisfactorily respond to your request pertaining to personal information, you may lodge a complaint at the office of the Information Regulator at the following addresses and/or contact them on the following telephone number:
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal address: P.O Box 31533, Braamfontein, Johannesburg, 2017
Complaint email address: complaints.IR@justice.gov.za
General enquiry email address: inforeg@justice.gov.za
Telephone number: +27(0) 12 406 4818
10.2 The POPI Act prescribes serious penalties for the contravention of its terms. For minor offences, a guilty party can receive a fine or be imprisoned for up to 12 months. For serious offences, the period of imprisonment rises to a maximum of 10 years. Administrative fines for the company can reach a maximum of R10 million. We therefore intend to fully comply with the provisions of the POPI Act.
10.3 Data subjects, however, hereby agree that we shall not be held liable for any damages suffered by you in the unlikely event of any breach by us, our employees or agents with the relevant provisions of the POPI Act, and our clients hereby indemnify us against any resultant claim for loss, damage or injury which may be suffered by them or any third party to their legal action or transaction.
11. DEFINITIONS OF TERMS USED IN THIS NOTICE
In this policy, "responsible party" means Vaughan Ulyate & Associates. All other terms and expressions have the meaning as assigned to them in Section 1 of the POPI Act, a copy whereof can be accessed on the website of the Information Regulator using the following link: https://www.justice.gov.za/inforeg/legal/InfoRegSA-act-2013-004.pdf . The POPI Act must be read as if fully set out in this policy.