POPIA Compliance Notice
Table of Contents
- Introduction
- Responsible Party
- Operators and Service Providers
- Eight POPIA Principles and Our Compliance
- Processing Limitation Principle
- Purpose Specification Principle
- Further Processing Principle
- Information Quality and Accuracy Principle
- Openness Principle
- Security Safeguards Principle
- Data Subject Participation Principle
- How to Request Access to Your Personal Information
- How to Request Correction of Your Personal Information
- How to Request Deletion of Your Personal Information
- How to Object to Processing
- Complaints Procedure
- Information Regulator
- Contact Details
- Document Review
1. INTRODUCTION
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary privacy and data protection legislation. POPIA establishes the rights of individuals (data subjects) regarding their personal information and imposes obligations on organizations (responsible parties) that process that information.
This POPIA Compliance Notice serves to:
(a) Formally confirm our status and responsibilities under POPIA as a Responsible Party;
(b) Outline the eight principles of POPIA and how we comply with each;
(c) Inform you of your rights as a data subject;
(d) Provide clear procedures for exercising your data subject rights;
(e) Explain how to lodge complaints about POPIA violations.
This Notice supplements our Privacy Policy (Document 1) and should be read in conjunction with it. Where there is any inconsistency, this Notice takes precedence on matters of POPIA compliance.
2. RESPONSIBLE PARTY
2.1 Our Status
Isango Enterprises (Pty) Ltd is the Responsible Party for personal information processing conducted through our Website and services.
A "Responsible Party" under POPIA means an entity that determines the purpose of and means for processing personal information. In practical terms, this means:
(a) We decide what personal information to collect;
(b) We decide why we collect it and how long we keep it;
(c) We decide who can access it within our organization;
(d) We decide whether to share it with third parties;
(e) We are accountable for compliance with POPIA.
2.2 Company Details
| Particulars | Details |
|---|---|
| Legal Name | Isango Enterprises (Pty) Ltd |
| CIPC Registration Number | 2026/472055/07 |
| Type of Entity | Private Company |
| Head Office | 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201 |
| Alternative Office | Stand 7776, Roodekop Ext 011, Germiston, Gauteng, 1401 |
| Website | https://www.isangoenterprises.co.za |
| General Email | info@isangoenterprises.co.za |
| Telephone | +27 (0)87 801 2919 |
2.3 Information Officer
We have designated a senior officer responsible for overseeing POPIA compliance and serving as the primary contact for data subject requests:
Mr Kwakhanya Magutywa Information Officer Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919
3. OPERATORS AND SERVICE PROVIDERS
3.1 Definition of Operators
An "Operator" under POPIA is an entity that processes personal information on behalf of a Responsible Party and in accordance with the Responsible Party's instructions. Operators do not make decisions about processing; they simply process information according to our direction.
3.2 Our Operators and Service Providers
We use the following operators and service providers to process personal information on our behalf:
| Category | Service Provider | Purpose | Location |
|---|---|---|---|
| Web Hosting | Axxess | Website hosting and server management | South Africa/International |
| Email Services | Microsoft Outlook | Email hosting and communication | International |
| Analytics | Google Analytics (Google Inc.) | Website usage analysis | International (USA) |
| CRM/Database | Internal systems + Cloud platforms | Customer relationship management | South Africa/International |
| Payment Processing | Banks (Nedbank) | Payment receipt and processing | South Africa |
| Accounting Software | Cloud-based accounting system | Financial records management | International |
| Backup Services | Third-party backup provider | Data backup and recovery | International |
| IT Support | Contracted IT service provider | Technical support and maintenance | South Africa |
| Courier/Logistics | Various delivery partners | Order delivery (where applicable) | South Africa |
3.3 Operator Agreements
Each operator is bound by a written agreement that:
(a) Restricts their use of personal information to purposes specified by us;
(b) Requires them to implement appropriate security measures;
(c) Prohibits them from disclosing personal information to others;
(d) Requires return or deletion of personal information when services end;
(e) Allows us to audit their compliance;
(f) Complies with POPIA Section 20 (Processor Restrictions);
(g) Includes provisions for handling data breaches.
3.4 Sub-Processors
Some of our operators may use sub-processors (third parties they engage on our behalf). We do not authorize use of sub-processors without our prior written consent. Our agreements require that any sub-processor must:
(a) Be approved by us;
(b) Be bound by equivalent confidentiality and security obligations;
(c) Meet our data protection standards.
3.5 Your Right to Information About Processors
You have the right to know which operators and service providers we use to process your personal information. For details, contact our Information Officer at POPIA@isangoenterprises.co.za.
4. EIGHT POPIA PRINCIPLES AND OUR COMPLIANCE
POPIA establishes eight information protection principles that all Responsible Parties must comply with. Below we outline each principle and explain how Isango Enterprises complies with it.
5. PROCESSING LIMITATION PRINCIPLE
5.1 The Principle
The Processing Limitation Principle (POPIA Section 9) requires that personal information may be processed only if:
(a) One of the lawful grounds is satisfied — processing must be based on one of the lawful bases established in POPIA (such as your consent, contractual performance, legal obligation, or legitimate interest);
(b) The processing is not objectionable — the processing must not be manifestly excessive relative to the purpose, and must not otherwise be objectionable.
5.2 Our Compliance
We comply with the Processing Limitation Principle by:
(a) Documenting our lawful basis — For each type of processing we conduct, we have documented our lawful basis (consent, contractual necessity, legal obligation, or legitimate interest);
(b) Obtaining consent where required — We seek your explicit consent before processing personal information where consent is the lawful basis (e.g., for direct marketing or non-essential cookies);
(c) Limiting to necessary information — We collect only the minimum personal information necessary to fulfill our stated purposes;
(d) Assessing proportionality — We assess whether our processing is proportionate to our purpose and not manifestly excessive;
(e) Refusing unreasonable requests — We refuse to process information where the request would be objectionable (e.g., requests to profile you for undisclosed purposes);
(f) Reviewing our practices regularly — We periodically review our processing activities to ensure ongoing compliance.
5.3 Your Rights Under This Principle
You have the right to:
- Know the lawful basis for any processing of your information
- Object to processing that appears to be manifestly excessive
- Request that we cease processing where it violates this principle
- Lodge a complaint with the Information Regulator
6. PURPOSE SPECIFICATION PRINCIPLE
6.1 The Principle
The Purpose Specification Principle (POPIA Section 10) requires that personal information must be collected for a specific, explicitly stated, and legitimate purpose. The purpose must be communicated to you when the information is collected.
6.2 Our Compliance
We comply with the Purpose Specification Principle by:
(a) Clearly stating purposes — When we collect your personal information, we explicitly inform you of the purposes for which we will use it (through this Notice, our Privacy Policy, and in-form disclosures);
(b) Limiting to stated purposes — We use personal information only for the purposes we have disclosed. We do not use your information for hidden or undisclosed purposes;
(c) Specific and legitimate purposes — Our purposes are specific (e.g., "to respond to your enquiry about catering services"), not vague (e.g., "for business purposes");
(d) Documented purposes — We maintain records documenting the purpose for each category of processing;
(e) No secondary use without authority — We do not use your information for purposes beyond those stated without your consent or a lawful basis.
6.3 Our Stated Purposes
We collect and process your personal information for the following specific purposes:
Primary Purposes: 1. To respond to your enquiry or request 2. To provide quotations and service proposals 3. To deliver services you have engaged 4. To invoice and process payment 5. To maintain records for compliance and accountability 6. To improve our website and services (analytics) 7. To send direct marketing communications (only with your consent)
Supporting Purposes: 8. To detect and prevent fraud or security threats 9. To comply with legal obligations (tax, audit, regulatory) 10. To enforce our terms and agreements 11. To protect our legal rights
6.4 Your Rights Under This Principle
You have the right to:
- Know the specific purposes for which your information is collected
- Request clarification about our purposes
- Refuse to provide information for purposes you disagree with
- Request that we not use your information for purposes beyond those disclosed
- Lodge a complaint if we use your information for undisclosed purposes
7. FURTHER PROCESSING PRINCIPLE
7.1 The Principle
The Further Processing Principle (POPIA Section 11) requires that if we want to use personal information for a purpose that is materially different from the purpose for which it was originally collected, we must obtain your consent or establish a new lawful basis.
In other words, we cannot simply collect information for one purpose and then use it for a completely different purpose without notifying you and obtaining consent or establishing another lawful basis.
7.2 What Constitutes "Further Processing"
Further processing occurs when we use information for a purpose that is:
(a) Materially different from the original purpose;
(b) Not reasonably contemplated by you when you provided the information;
(c) Not compatible with the original purpose;
(d) Incompatible with your reasonable expectations.
Examples of further processing:
- Collecting information to respond to an enquiry, then selling your contact details to a third party for marketing (without consent)
- Collecting information for service delivery, then using it for research or profiling (without consent)
- Collecting information for one division's services, then sharing it with an unrelated third party (without consent)
Examples that are NOT further processing:
- Using information to respond to an enquiry, then following up with related service information (compatible with original purpose)
- Using information you provided for a quote, then using it to invoice you (contemplated in the transaction)
- Using Website analytics data to improve the Website (reasonably expected by website visitors)
7.3 Our Compliance
We comply with the Further Processing Principle by:
(a) Checking compatibility — Before using personal information for a new purpose, we assess whether it is compatible with the original purpose and your reasonable expectations;
(b) Obtaining consent — Where further processing is not compatible, we seek your explicit consent before proceeding;
(c) Establishing lawful basis — If consent is not available, we establish another lawful basis (legal obligation, contractual necessity, or legitimate interest) before further processing;
(d) Notifying you — We inform you of any material change in how we use your information;
(e) Documented assessments — We maintain records of our compatibility assessments.
7.4 Examples of Our Compliance
Example 1 — Related Service Information
You enquire about our catering services. We provide a quotation and, if you don't respond, we may send you information about our supply & delivery services (which may be useful to the same organization). This is not further processing because it is reasonably related to the original enquiry.
Example 2 — Analytics
When you visit our Website, we collect analytics information. We use this to improve the Website's functionality. This is not further processing because analytics improvement is a purpose reasonably expected by website visitors.
Example 3 — Marketing
You enquire about electrical services. We respond to your enquiry. Later, we want to add you to our general marketing list to receive regular updates about all our services. This is further processing. We will seek your consent before doing this.
7.5 Your Rights Under This Principle
You have the right to:
- Be informed if we intend to use your information for a purpose different from the original
- Refuse further processing for new purposes
- Withdraw consent for further processing
- Lodge a complaint if we use your information for incompatible purposes without consent
8. INFORMATION QUALITY AND ACCURACY PRINCIPLE
8.1 The Principle
The Information Quality and Accuracy Principle (POPIA Section 12) requires that personal information must be:
(a) Accurate — correct and factually true;
(b) Complete — not misleading due to omissions;
(c) Up to date — current and not obsolete;
(d) Relevant — adequate and not excessive in relation to the purpose.
8.2 Our Compliance
We comply with the Information Quality and Accuracy Principle by:
(a) Accurate collection — We collect information directly from you (where possible) to ensure accuracy. We do not make assumptions or inferences;
(b) Verification practices — Where we collect information from other sources, we verify its accuracy before recording it;
(c) Update mechanisms — We provide you with opportunities to update your information (through contact forms, update requests, or direct communication);
(d) Correction procedures — We have a clear process for you to request correction of inaccurate information (see Section 13 below);
(e) Purging outdated data — We regularly review our records to identify and remove outdated or obsolete information;
(f) Proportionality — We collect only information that is relevant and adequate for our stated purposes, not excessive;
(g) Staff training — Our staff are trained on the importance of data accuracy.
8.3 Your Responsibility
You have a responsibility to:
- Provide accurate information when you submit forms or communicate with us
- Inform us of changes to your information (e.g., new contact details)
- Notify us if you believe our records are inaccurate
8.4 Your Rights Under This Principle
You have the right to:
- Request access to the information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of information that is obsolete or no longer relevant
- Request that we note your correction request if we dispute your version
- Lodge a complaint if we refuse to correct information
9. OPENNESS PRINCIPLE
9.1 The Principle
The Openness Principle (POPIA Section 13) requires that we must be transparent and open about our information practices. You must be able to:
(a) Know whether we hold personal information about you;
(b) Know what personal information we hold;
(c) Understand how we use that information;
(d) Understand our security measures;
(e) Know who has access to your information.
This principle is about transparency and preventing secret data practices.
9.2 Our Compliance
We comply with the Openness Principle by:
(a) Publishing this Notice — We publicly state our role as Responsible Party and our compliance practices;
(b) Privacy Policy — We have published a comprehensive Privacy Policy explaining our data practices in clear language;
(c) In-form disclosures — Our website forms include clear statements about what information we collect and how we use it;
(d) Accessible contact details — We provide clear contact information for data subject requests;
(e) Responding to access requests — We respond to requests for access to information we hold about you;
(f) Explaining our practices — We explain (in plain language) the purposes of processing, storage periods, and who has access;
(g) Information about processors — We disclose which service providers process your information;
(h) Breach notification — We notify you of security breaches affecting your information.
9.3 Access to Our Practices
Information about our data practices is available:
(a) On our Website: https://www.isangoenterprises.co.za (links to Privacy Policy and this Notice)
(b) In our forms: Disclosure statements appear on data collection forms
(c) Upon request: Contact our Information Officer for specific information about our practices
(d) In this Notice: This document explains our POPIA compliance
9.4 Your Rights Under This Principle
You have the right to:
- Know what personal information we hold about you
- Request access to your personal information
- Receive clear explanations about our data practices
- Understand our security measures
- Know who has access to your information
- Request information about our processors and service providers
10. SECURITY SAFEGUARDS PRINCIPLE
10.1 The Principle
The Security Safeguards Principle (POPIA Section 19) requires that we must implement appropriate technical and organizational security measures to protect personal information against:
(a) Unauthorized access — preventing unauthorized people from accessing your information;
(b) Unauthorized modification — preventing unauthorized changes to your information;
(c) Unlawful destruction — preventing unauthorized or accidental loss of your information;
(d) Loss and damage — protecting against damage or loss through negligence.
Security measures must be proportionate to: - The sensitivity of the personal information - The likelihood and severity of potential harms - The state of technological development - Industry best practices
10.2 Our Security Measures
We have implemented the following security measures:
Technical Safeguards:
(a) Encryption: - HTTPS encryption for data transmitted between your browser and our servers - Encryption of sensitive data at rest (in storage) - Encrypted backups
(b) Access Controls: - Role-based access to personal information - Password authentication for staff - Multi-factor authentication where available - Audit logs tracking who accessed what information
(c) Firewalls and Network Security: - Firewalls protecting our networks - Intrusion detection systems - Regular security scanning
(d) System Maintenance: - Regular security updates and patches - Vulnerability assessments - Penetration testing
(e) Backup and Recovery: - Regular automated backups - Secure backup storage - Tested recovery procedures
Organizational Safeguards:
(a) Staff Training: - Data protection training for all staff - Confidentiality obligations - Security awareness programs
(b) Access Policies: - Need-to-know principle (staff access only what they need) - Segregation of duties - Monitoring of access patterns
(c) Confidentiality Agreements: - Written confidentiality obligations for all staff - Confidentiality clauses in service provider agreements
(d) Physical Security: - Secure office locations - Access restrictions to areas containing personal information - Secure disposal of documents containing personal information
(e) Incident Response: - Security breach detection procedures - Incident response plan - Breach notification procedures - Regular reviews and testing of incident response
(f) Third-Party Security: - Security requirements in service provider agreements - Audit rights to verify security measures - Due diligence on new service providers
10.3 Limitations of Security
While we implement comprehensive security measures, we acknowledge that:
(a) No security system is completely impenetrable;
(b) The Internet is not a completely secure medium;
(c) There is always some risk that information transmitted electronically could be intercepted;
(d) You have a responsibility to protect your own devices and passwords.
10.4 Data Breach Notification
If a security breach occurs that compromises your personal information, we will:
(a) Investigate the breach to determine scope and impact;
(b) Notify you without unreasonable delay where the breach poses a high risk to your rights and interests;
(c) Notify the Information Regulator where required;
(d) Take corrective action to remediate the breach and prevent recurrence.
Breach notifications will include: - Nature of the breach - Personal information compromised - Likely consequences for you - Steps we are taking in response - Your contact for further information
10.5 Your Rights Under This Principle
You have the right to:
- Know what security measures we have implemented
- Be notified of security breaches
- Request information about our security practices
- Lodge a complaint if we fail to implement adequate security
11. DATA SUBJECT PARTICIPATION PRINCIPLE
11.1 The Principle
The Data Subject Participation Principle (POPIA Section 14-18) recognizes your fundamental rights regarding your personal information. You have the right to:
(a) Access — know what personal information we hold about you;
(b) Correct — request that inaccurate information be corrected;
(c) Delete — request deletion in certain circumstances;
(d) Object — object to certain types of processing;
(e) Restrict — restrict processing while a request is investigated.
These rights are detailed in Sections 12-15 below.
11.2 Exercising Your Rights
You may exercise your data subject rights:
(a) In writing — by emailing or posting your request to our Information Officer;
(b) Free of charge — we will not charge you a fee (except in exceptional circumstances);
(c) Promptly — we will respond within 30 days (60 days in complex cases);
(d) With assistance — if you need assistance exercising your rights, contact us for help.
12. HOW TO REQUEST ACCESS TO YOUR PERSONAL INFORMATION
12.1 Your Right
You have the right to request access to personal information we hold about you. This is called an "access request" or "POPIA Section 14 request."
12.2 What You Will Receive
If we grant your access request, we will provide:
(a) Confirmation of whether we process your personal information;
(b) The personal information we hold about you;
(c) The categories of personal information we hold;
(d) Why we are processing it (the purpose);
(e) Who we may have disclosed it to;
(f) How long we will retain it;
(g) Your rights regarding the information.
12.3 How to Submit an Access Request
Submit your request in writing to:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
Your request must include:
(a) Your full name;
(b) Your contact details (email and/or telephone);
(c) Clear description of the personal information you are requesting;
(d) Reasons for your request (optional but helpful);
(e) Your preferred format for receiving the information (e.g., email, printed document);
(f) Copy of your identification document (to verify your identity).
12.4 Our Response Process
Step 1 — Acknowledgment (within 5 business days)
We will acknowledge receipt of your request and confirm that we have understood what you are requesting.
Step 2 — Verification (within 5 business days)
We will verify your identity by checking your identification document. This is to protect your privacy and ensure we do not disclose your information to someone impersonating you.
Step 3 — Search and Compilation (within 15-25 business days)
We will search our systems for all personal information relating to you and compile it in an accessible format.
Step 4 — Disclosure (within 30 days)
We will provide you with the personal information in the format you requested. We will also include an explanation of what the information means (if necessary) and information about your other rights.
12.5 Extensions
If we cannot comply within 30 days due to complexity or volume, we will:
(a) Notify you before the 30-day deadline;
(b) Explain the reasons for the delay;
(c) Provide a revised timeframe (not exceeding 60 days total);
(d) Keep you updated on progress.
12.6 Possible Refusals or Limitations
We may refuse or limit your access request in the following circumstances:
(a) Identity Verification — If you cannot verify your identity, we may refuse to disclose information;
(b) Third-Party Information — If the information relates to other people, we may redact their names and contact details to protect their privacy;
(c) Privileged Information — If the information is subject to legal privilege (e.g., attorney-client communications), we may refuse to disclose it;
(d) Trade Secrets — If the information contains our trade secrets or confidential business information, we may refuse or limit disclosure;
(e) Ongoing Investigations — If disclosing the information would interfere with an ongoing investigation (internal or law enforcement), we may refuse or delay disclosure;
(f) No Information Held — If we do not hold personal information about you, we will notify you.
If we refuse your request, we will provide written reasons for the refusal and inform you of your right to complain to the Information Regulator.
12.7 Format of Disclosure
We will provide the information in a format accessible to you:
(a) Electronic Format — By email (PDF or other commonly used format);
(b) Printed Format — By post to your address (if requested);
(c) Accessible Format — If you have accessibility needs, we will provide information in an accessible format (e.g., large print, audio format).
12.8 Cost
No Fee — We provide access to your personal information at no cost. You will not be charged a fee for:
(a) Reviewing and compiling the information;
(b) Providing copies (electronic or printed);
(c) Explaining the information.
Exceptional Cases — In exceptional circumstances where your request is excessive or manifestly unfounded, we may charge a reasonable fee covering our costs. We will notify you of any fee before proceeding and discuss the amount.
12.9 Your Appeal
If we refuse your access request, you have the right to:
(a) Request written reasons for the refusal;
(b) Request an internal review of the refusal (we will reconsider);
(c) Lodge a complaint with the Information Regulator;
(d) Seek legal advice.
13. HOW TO REQUEST CORRECTION OF YOUR PERSONAL INFORMATION
13.1 Your Right
You have the right to request correction of personal information about you that is inaccurate, incomplete, misleading, or outdated. This is called a "correction request" or "POPIA Section 15 request."
13.2 What We Will Do
If we agree your information is inaccurate or incomplete, we will:
(a) Correct the information — update our records with accurate information;
(b) Notify third parties — where practicable, notify third parties (including service providers) to whom we disclosed the incorrect information, so they can correct their records;
(c) Confirm the correction — notify you that the correction has been made;
(d) Document the request — maintain a record of the correction request and our action.
13.3 How to Submit a Correction Request
Submit your request in writing to:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
Your request must include:
(a) Your full name and contact details;
(b) Identification of the specific information you believe is inaccurate or incomplete;
(c) Description of why you believe it is inaccurate (e.g., "My email address is no longer valid; the correct address is...");
(d) The correct or updated information;
(e) Supporting evidence (if any) demonstrating the inaccuracy;
(f) Copy of your identification document.
13.4 Our Response Process
Step 1 — Acknowledgment (within 5 business days)
We will acknowledge receipt and confirm that we understand your correction request.
Step 2 — Investigation (within 15-25 business days)
We will investigate your claim by:
(a) Reviewing the information in question;
(b) Checking our records and any source documents;
(c) Considering any evidence you have provided;
(d) Assessing whether the information is inaccurate or incomplete.
Step 3 — Decision (within 30 days)
We will make a decision and notify you:
(a) If we agree — We will confirm that we have corrected the information and notify third parties where relevant.
(b) If we disagree — We will explain why we believe the information is accurate and provide you with your options (see below).
13.5 If We Disagree with Your Correction Request
If we believe the information is accurate and refuse to correct it, we will:
(a) Provide written reasons for our refusal;
(b) Offer you the right to make a statement explaining your position;
(c) If you make a statement, we will add it to our records and disclose it along with the information if we disclose it to third parties;
(d) Inform you of your right to lodge a complaint with the Information Regulator.
13.6 Correction Requests We May Refuse
We may refuse to correct information in limited circumstances:
(a) Accurate Information — If we reasonably believe the information is accurate;
(b) Not Our Information — If the information does not relate to you or was not collected by us;
(c) Privileged Information — If the information is subject to legal privilege;
(d) Legal Obligation — If we are required by law to retain the information in its current form.
13.7 Cost
No Fee — We correct information at no cost to you.
13.8 Your Rights if We Refuse
If we refuse your correction request, you have the right to:
(a) Make a formal statement disputing the information;
(b) Request that we add your statement to our records;
(c) Request an internal review (we will reconsider our decision);
(d) Lodge a complaint with the Information Regulator.
14. HOW TO REQUEST DELETION OF YOUR PERSONAL INFORMATION
14.1 Your Right
You have the right to request deletion of personal information about you in certain circumstances. This is called a "deletion request" or "POPIA Section 16 request."
14.2 When You Can Request Deletion
You can request deletion in the following circumstances:
(a) No Longer Necessary — The information is no longer necessary for the purpose it was collected;
(b) Consent Withdrawn — You have withdrawn consent, and consent was the lawful basis for processing;
(c) Unlawful Processing — The information was collected or processed unlawfully;
(d) Outdated — The information is outdated or obsolete;
(e) Right to Be Forgotten — Your request is based on POPIA Section 16 rights;
(f) Legal Obligation — You are required by law to have the information deleted.
Example scenarios where deletion may be appropriate:
- You enquired about our services but have decided not to proceed; you request deletion of your enquiry information
- You previously engaged our services, but the retention period has expired, and no legal obligation requires us to keep the records
- You believe information was collected unlawfully or without proper consent
14.3 How to Submit a Deletion Request
Submit your request in writing to:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
Your request must include:
(a) Your full name and contact details;
(b) Specific identification of the information you want deleted;
(c) Reasons for the deletion request (explaining which circumstance applies);
(d) Supporting evidence (if any);
(e) Copy of your identification document.
14.4 Our Response Process
Step 1 — Acknowledgment (within 5 business days)
We will acknowledge receipt of your deletion request.
Step 2 — Assessment (within 15-25 business days)
We will assess whether:
(a) We actually hold the information;
(b) Your deletion request is valid;
(c) We have a lawful reason to retain the information.
Step 3 — Decision (within 30 days)
We will notify you of our decision:
(a) If we agree — We will delete the information and confirm deletion to you.
(b) If we refuse — We will explain our reasons and your appeal options.
14.5 When We May Refuse Deletion
We may refuse to delete information in the following circumstances:
(a) Legal Obligation — We are required by law to retain the information (e.g., tax records must be kept for 7 years under tax law);
(b) Legitimate Interest — Deletion would interfere with our legitimate legal or business interests (e.g., records necessary for dispute resolution);
(c) Contract — The information is necessary to perform a contract with you;
(d) Public Interest — Deletion would interfere with the public interest or official authority functions;
(e) Rights of Others — Deletion would interfere with the rights of other individuals.
Common reasons we may retain information despite deletion requests:
- Tax and Financial Records — We must retain invoices and payment records for 7 years under South African tax law
- Service Records — We may need to retain records to honor warranties or respond to future disputes
- Legal Claims — If there is a potential legal dispute, we may retain information necessary for defense
- Compliance — We may need to retain records to demonstrate POPIA compliance
14.6 Partial Deletion
In some cases, we may delete some information but retain other information:
Example: You request deletion of your entire file. However: - Your name and contact details may be retained in a "do not contact" list - Your payment history may be retained for tax compliance - Records of services delivered may be retained for warranty purposes
We will explain which information we are deleting and which we are retaining, and why.
14.7 Notification of Third Parties
If we delete your information, we will:
(a) Notify service providers and third parties (where practicable) that information about you should be deleted;
(b) Note that we cannot guarantee third parties will comply, as they are bound by their own retention obligations;
(c) Inform you that backup copies may retain the information for a limited period (but will be deleted once backups are rotated).
14.8 Cost
No Fee — We delete information at no cost to you.
14.9 Consequences of Deletion
You should be aware that deletion of personal information may:
(a) Make it impossible for us to provide future services to you;
(b) Result in loss of any active customer status or relationship history;
(c) Require you to re-provide information if you engage with us again;
(d) Affect our ability to respond to your enquiries if we have deleted your contact details.
14.10 Your Rights if We Refuse
If we refuse your deletion request, you have the right to:
(a) Request written reasons for the refusal;
(b) Request an internal review (we will reconsider);
(c) Lodge a complaint with the Information Regulator;
(d) Seek legal advice or court intervention if necessary.
15. HOW TO OBJECT TO PROCESSING
15.1 Your Right
You have the right to object to processing of your personal information in certain circumstances. This is called an "objection" or "POPIA Section 17 request."
15.2 When You Can Object
You can object to processing in the following circumstances:
(a) Legitimate Interest Processing — We are processing your information based on our legitimate interest, and you believe our interest does not outweigh your privacy rights;
(b) Direct Marketing — We are using your information for direct marketing purposes (marketing emails, SMS, phone calls, etc.);
(c) Profiling and Automated Decision-Making — We are using your information for automated profiling or decision-making that produces legal or similarly significant effects;
(d) Historical Processing — You are objecting to processing that occurred in the past.
15.3 Effect of an Objection
If you object to processing, we will:
(a) Stop the processing (if we agree your objection is valid);
(b) Assess the objection — evaluate whether our processing can continue on another lawful basis;
(c) Notify you — inform you whether we will cease or continue processing, and why.
15.4 How to Submit an Objection
Submit your objection in writing to:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
Your objection must include:
(a) Your full name and contact details;
(b) Clear description of the processing you are objecting to;
(c) Specific grounds for your objection (which circumstance applies);
(d) Explanation of why you believe the processing should cease;
(e) What action you want us to take (e.g., stop direct marketing, stop profiling, etc.);
(f) Copy of your identification document.
15.5 Our Response Process
Step 1 — Acknowledgment (within 5 business days)
We will acknowledge receipt and confirm we understand your objection.
Step 2 — Investigation (within 15-25 business days)
We will:
(a) Review the processing you are objecting to;
(b) Assess the validity of your objection;
(c) Determine if we have another lawful basis to continue processing.
Step 3 — Decision (within 30 days)
We will notify you:
(a) If we uphold your objection — We will cease the processing and confirm cessation to you.
(b) If we overrule your objection — We will explain why we believe the processing should continue and our reasons.
15.6 Objections to Direct Marketing
Special Rule for Direct Marketing: If you object to direct marketing, we must cease that processing. We do not have the option to continue direct marketing based on another lawful basis.
How to Object to Direct Marketing:
The easiest way is to:
(a) Click "Unsubscribe" in any marketing email we send you;
(b) Reply "STOP" to any SMS we send;
(c) Request removal when we call;
(d) Contact us directly (as per details above).
We will remove you from our direct marketing lists within 10 business days.
15.7 Objections to Legitimate Interest Processing
If you object to processing based on our legitimate interest (e.g., analytics, fraud prevention), we will:
(a) Assess whether your objection is based on reasonable grounds;
(b) Balance your privacy rights against our legitimate interests;
(c) Determine if we can continue processing on another lawful basis (e.g., contractual necessity, legal obligation);
(d) Inform you of our decision and reasons.
Example: You object to Google Analytics on the basis that you don't want your browsing tracked. We will consider your objection. If we determine that analytics is important for website improvement, we might continue collecting analytics data on the basis of legitimate interest, provided it is proportionate and we have implemented appropriate safeguards.
15.8 Cost
No Fee — We process objections at no cost to you.
15.9 Your Rights if We Overrule Your Objection
If we overrule your objection, you have the right to:
(a) Request detailed reasons in writing;
(b) Request an internal review (we will reconsider);
(c) Lodge a complaint with the Information Regulator;
(d) Seek legal advice or court intervention if necessary.
16. COMPLAINTS PROCEDURE
16.1 Our Internal Complaints Process
If you believe we have violated your privacy rights under POPIA, we encourage you to contact us to try to resolve the matter informally before escalating to the Information Regulator.
16.2 How to Lodge an Internal Complaint
Step 1 — Submit Your Complaint
Write to:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
Your complaint should include:
(a) Your full name and contact details;
(b) Clear description of the alleged POPIA violation;
(c) Specific details: - What personal information is involved? - How have we violated POPIA? - What section(s) of POPIA do you believe we have breached?
(d) What outcome are you seeking? (e.g., correction of information, deletion, cessation of processing, compensation);
(e) Copies of any relevant evidence or documentation;
(f) Dates when the alleged violation occurred.
Step 2 — Our Acknowledgment
We will acknowledge receipt of your complaint within 5 business days and provide:
(a) A reference number for your complaint;
(b) Confirmation of what we understand the complaint to be;
(c) Outline of our investigation process;
(d) Expected timeframe for our response.
Step 3 — Our Investigation
We will investigate your complaint thoroughly:
(a) Review the facts and circumstances;
(b) Gather evidence from our systems and staff;
(c) Assess whether POPIA has been breached;
(d) Determine appropriate remedial action (if necessary).
Step 4 — Our Response
Within 30 days of receipt, we will provide you with:
(a) If your complaint is upheld — A detailed explanation of the breach, corrective action we will take, and how we will prevent recurrence.
(b) If your complaint is not upheld — A detailed explanation of why we do not believe we have breached POPIA, with reference to relevant legislation and facts.
(c) If the matter is complex — A revised timeframe (not exceeding 60 days) if we need more time to investigate.
16.3 Remedies We May Offer
If we uphold your complaint, we may:
(a) Correct your information — Update inaccurate or incomplete information;
(b) Delete your information — Remove personal information from our systems;
(c) Cease processing — Stop processing your information for a specified purpose;
(d) Security improvements — Enhance our security measures to prevent recurrence;
(e) Compensation — In some cases, provide compensation for harm you have suffered (we will discuss this with you).
16.4 Your Right to Escalate
If you are dissatisfied with our response to your complaint, you have the right to escalate to the Information Regulator (see Section 17 below).
17. INFORMATION REGULATOR
17.1 What Is the Information Regulator?
The Information Regulator (officially the "South African Human Rights Commission — Information Regulator") is an independent office established under POPIA to:
(a) Oversee compliance with POPIA across South Africa;
(b) Investigate complaints about POPIA violations;
(c) Enforce data protection rights;
(d) Issue compliance orders;
(e) Impose administrative fines;
(f) Provide guidance and education about POPIA.
17.2 When to Contact the Information Regulator
You may lodge a complaint with the Information Regulator if:
(a) You have contacted us about a POPIA violation and are dissatisfied with our response;
(b) We have refused to grant your data subject rights without valid reason;
(c) You believe we have committed a serious or persistent breach of POPIA;
(d) We have failed to notify you of a security breach;
(e) You wish to report us for non-compliance with POPIA.
17.3 How to Lodge a Complaint with the Information Regulator
Contact Details:
Information Regulator South African Human Rights Commission Private Bag X2700 Houghton 2041 South Africa
Telephone: +27 (0)10 023 0911 Email: complaint.IR@sahrc.org.za Website: https://www.justice.gov.za/inforeg/
To Lodge a Formal Complaint:
(a) Obtain the Complaint Form — Download the POPIA complaint form from the Information Regulator's website or request one via email;
(b) Complete the Form — Provide: - Your full name and contact details - Name of the organization you are complaining about (Isango Enterprises (Pty) Ltd) - Clear description of the alleged violation - Evidence supporting your complaint - Details of any attempts to resolve the matter with us - The outcome you are seeking
(c) Pay the Complaint Fee — South African residents must pay a fee (currently R100; fees may vary for international complainants). Include proof of payment.
(d) Submit the Complaint — Submit the completed form with supporting documents and proof of payment to the Information Regulator.
17.4 What the Information Regulator Can Do
The Information Regulator has significant powers to:
(a) Investigate — Conduct a formal investigation into your complaint;
(b) Request Information — Require us to provide information and documentation;
(c) Audit — Conduct compliance audits of our data protection practices;
(d) Conciliation — Facilitate settlement between you and us;
(e) Issue Orders — Issue binding compliance orders requiring us to take specific action;
(f) Impose Fines — Impose administrative fines (up to 10% of our annual turnover for serious breaches);
(g) Refer to Police — In cases of criminal conduct, refer matters to law enforcement;
(h) Appeal — Review decisions on appeal.
17.5 Outcomes of an Information Regulator Investigation
Possible outcomes include:
(a) Complaint Dismissed — The Information Regulator finds no breach of POPIA;
(b) Settlement — We agree to resolve the matter (e.g., correct information, provide compensation);
(c) Compliance Order — The Information Regulator orders us to take specific corrective action;
(d) Administrative Fine — We are required to pay a financial penalty;
(e) Escalation — In serious cases, referral to law enforcement or courts.
17.6 Your Rights During an Investigation
While the Information Regulator investigates:
(a) You have the right to participate in the process;
(b) You can submit additional evidence or information;
(c) You can request updates on progress;
(d) You have the right to appeal any decision;
(e) You can request legal representation.
18. CONTACT DETAILS
18.1 Data Subject Requests and Complaints
For any data subject requests, POPIA-related inquiries, or complaints:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd
Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
18.2 Alternative Contact
For general enquiries:
Isango Enterprises (Pty) Ltd General Inquiries
Email: info@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Website: https://www.isangoenterprises.co.za
18.3 Response Commitments
We commit to:
(a) Acknowledging all requests and complaints within 5 business days;
(b) Providing substantive responses within 30 days (60 days for complex matters);
(c) Treating all communications respectfully and professionally;
(d) Providing clear explanations for any refusals or limitations;
(e) Assisting you in understanding your rights.
19. DOCUMENT REVIEW
This POPIA Compliance Notice will be reviewed and updated:
(a) Annually — Each year on 19 July 2027 and thereafter;
(b) Upon Regulatory Change — If POPIA regulations or Information Regulator guidance changes;
(c) Upon Operational Change — If our data processing practices materially change;
(d) Upon Request — If you or a data subject raises concerns about accuracy or completeness.
Version Control:
| Version | Date | Changes |
|---|---|---|
| 1.0 | 19 July 2026 | Initial publication-ready version |
← Back to Isango Enterprises