Glenwood Tax Consultants

Popia Policy

Policy on the protection of personal information (POPI ACT)

  1. Purpose
    1. The policy purpose and objective is to give effect to the provisions of POPIA to safeguard personal information.
    2. GTC is responsible for registering persons in accordance with Section 19 of the NSP Act in the natural science profession and in doing so, it collects and processes personal information. The policy sets out the manner in which GTC deals with Client’s and regitered person’s personal information and the purpose for the said information to be used.
  2. Outcomes / aims and objectives The objective and goal of this policy is to:
    1. Guarantee GTC’s commitment to protecting personal information of registered persons and Clients.
    2. Ensure that registered persons’ and Clients’ personal information in GTC’s possession is adequately protected to avoid unauthorised access and use.
    3. Undertake to protect personal information of all SACNSP’s Council and Committee members and employees. The personal information will be used appropriately, transparently, and securely in accordance with applicable laws.
  3. Definitions
    In this document, unless contrary to the context, reference to the male gender includes the female gender; a word or expression to which a meaning has been assigned in the NSP Act shall bear the same meaning unless the context otherwise indicates, and –
    1. “GTC” means ( Glenwood Tax Consultants (Pty) Ltd and its subsidiaries
    2. “CEO” means the Chief Executive Officer and refers to the position as outlined in section 8(1) of the NSP Act.
    3. “POPIA” means the Protection of Personal Information Act, 2013 (Act No. 4 of 2013)
    4. “Information Officer” refers to the person registered with the Information Regulator who is responsible for ensuring that the organisation complies with the POPI Act
    5. “Data Subject” means any person to whom personal information relates.
    6. “Personal information” means information about an identifiable individual including, but not limited to:
      1. Information relating to the race, gender, sex, pregnancy, marital status, national, ethnic, or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language, identity document/passport number, phone number, email address, financial information, physical address, date of birth, criminal record, and private correspondence;
      2. Information relating to the educational or the medical, criminal or employment history of the individual or information relating to financial transactions in which the individual has been involved; and
      3. The name of the individual, where it appears with other personal information relating to the individual or where the disclosure of the name itself would reveal information about the individual.
    7. “Processing” means any operation or activity or any set of activities, whether or not by automatic means, concerning personal information including:
      1. The collecting, receipting, recording, organizing, collation, storing, updating or modification, retrieval, alteration, consultation or use;
      2. Dissemination by means of transmission, distribution, or making available in any other form; or
      3. Merging, linking, as well as restriction, degradation, erasure or destruction of information.
    8. “Responsible party” means a member of the public or private body or any other persons which alone or in conjunction with others, determines the purpose of and means for processing personal information.
  4. Policy statements and policy directives
    1. Rationale of Protection of Personal Information (POPI Act)
      1. The Protection of Personal Information Act, (Act 4 of 2013) (POPIA) gives effect to the constitutional right to privacy, regulates the manner in which personal information may be processed, and provides rights and remedies to protect personal information.
      2. POPIA applies to processing of personal information in any form by a responsible party who is domiciled in South Africa or if not domiciled in South Africa, makes use of automated or non-automated means, unless the processing relates only to the forwarding of personal information.
      3. The main rationale of POPIA is to promote the protection of personal information and to bring South Africa's privacy laws in line with international standards. It limits the rights of businesses and public bodies to collect, process, store, and share personal information and to only do so in line with the law.
    2. Lawful processing of information
      POPIA sets out the following conditions for the lawful processing of information:
      1. Duty by a public body.
      2. Legal obligation to perform the processing of personal information.
      3. Processing limitation – information may only be processed if it is adequate relevant and not excessive given the purpose for which it is collected.
      4. Purpose specification – personal information must be collected for a specific, explicitly defined and lawful purpose related to the activity of the responsible party.
      5. Further processing limitation – where information is received from a third party and passed on to the responsible party for further processing, the further processing must be compatible with the purpose for which it was initially processed.
      6. Information quality – information must be complete, accurate, not misleading and updated where necessary.
      7. Openness – the data subject must be informed when collecting information and the specific nature thereof.
      8. Security safeguards – the responsible party must ensure the integrity of the personal information by taking measures to prevent the loss, damage or unauthorised destruction of the information.
      9. Data subject specification – the data subject has the right to request a responsible person to confirm, free of charge, whether they hold personal information about them.
  5. Procedures
    1. The personal information collected
      1. In terms of section 9 of POPIA, personal information may only be processed if given the purpose for which it is processed, it is adequate, relevant and not excessive. Consequently, GTC collects personal information for the following reasons:
        1. Registration of persons who apply and qualify for registration in theNatural Science Profession;
        2. Personal information is collected for human resources and financial purposes, contractual relationships with third-party service providers who process personal data on behalf of GTC.
      2. GTC collects personal information for clients
        1. Client’s name
        2. Registered professionals’ names;
        3. Client’s names;
        4. Identity number;
        5. Date of birth;
        6. Gender;
        7. Race;
        8. Physical and Postal addresses;
        9. Contact numbers;
        10. Client’s financial transactions and records
        11. Clients source documents and record
        12. Email addresses;
        13. Academic information and records;
      3. GTC collects employees’ personal information
        1. Name, address, phone number, marital status, date of birth;
        2. Next of kin;
        3. Doctor’s name;
        4. spouse/partner contact information;
        5. Curriculum Vitae
        6. Letters of reference;
        7. Employment status and history
        8. Academic records;
        9. Banking details;
        10. Disciplinary information;
        11. Salary information; and
        12. Criminal records.
      4. GTC collects the following information from the public:
        1. Names, telephone numbers,
        2. Company from which the visitor comes from;
        3. Names of persons lodging complaints of improper conduct against registered persons;
        4. Email addresses, identity number;
        5. Physical addresses;
        6. Email correspondence;
        7. Proof of payments;
        8. Personal information used on Service level agreements; and
        9. Service provider personal information
    2. How personal information is used
      1. Clients, and employees’ personal information will only be used for purposes for which it was collected and intended. This includes:
        1. Continuing Professional Development points;
        2. For audit and record keeping purposes;
        3. Investigations;
        4. Disciplinary processes;
        5. Communicating with registered persons;
        6. Employee contracts;
        7. Communication with employees;
        8. Communication with client
        9. Providing the service requested by the client Employee personal information is used to establish, manage and terminate employment; and
        10. Analysis and review of service provider contracts, in terms of which personal information is processed for and on behalf of GTC.
      2. According to section 10 of POPIA, personal information may only be processed if certain conditions are met, for instance:
        1. Consent is obtained to process personal information- in GTC’s case consent obtained during client requesting the service and sending the information, employment and entering into a service level agreement with service providers;
        2. Processing complies with an obligation imposed by law (NSP Act).
    3. Disclosure of personal information
      1. GTC may disclose personal information where it has a duty or a right to disclose in terms of applicable laws;
    4. Safeguarding registered person’s personal information
      1. In terms of section 19 of POPIA, a responsible party must ensure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent: loss of, damage to or unauthorised destruction of personal information, unlawful access to or processing of personal information. POPIA requires that personal information should be adequately protected to avoid unauthorised access. Therefore, GTC continuously reviews security controls and procedures to ensure that personal information is secured.
      2. The following security controls are in place to protect personal information:
        1. Personal information is treated as confidential and not disclosed unless required by law;
        2. High level Information Technology controls are in place to maintain the protection of personal information; POPI Act Policy
        3. High level anti-virus programs;
        4. Access rights in place;
        5. Computer passwords in place;
        6. Assessment of data quality controls in place to ensure the accuracy and completeness of personal information;
        7. A third party service provider is mandated to ensure safeguarding of registered persons personal information;
        8. Personal information is stored at a third-party service provider who is subject to POPIA provision in the Service Level Agreement;
        9. GTC internal server hard drives are protected by firewalls;
        10. Employees, of GTC sign confidentially agreements which is part of the employment contract;
        11. Hardcopy files are archived at a secured place;
        12. Hardcopy are disposed off via shredding machine and not in the refuse bin
    5. Access and correction of personal information
      1. Registered persons have a right to request for access to personal information in GTC’s possession;
      2. Registered persons’ personal information should be continuously updated.
    6. Information Officer:
      Lionel Murisi
      Email: admin@gfaccounts.com
      Telephone: +27 31 765 1166
    7. Amendment of the policy
      Amendment to this policy will take place on an ad hoc basis or when needed. Registered Persons are advised to regularly update their personal information electronically on the GTC portal online