Published in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and the Regulations relating to the Protection of Personal Information.
Infotech Solutions is committed to processing personal information lawfully, reasonably and transparently, while maintaining appropriate technical and organisational safeguards throughout the information lifecycle.
Where Infotech determines the purpose and means of processing personal information, we act as the Responsible Party as contemplated in POPIA. Where we process personal information on behalf of a client in delivering services, our role may instead be that of an Operator, subject to the applicable contractual and statutory requirements.
Our privacy and information-governance practices are informed by POPIA’s eight conditions for lawful processing and are designed to embed privacy, security and accountability into our business operations and technology environments.
Name: Kgaogelo MM Madileng
Position: Information Officer
Information Officer Registration Number: 2026-024619
Company Registration Number: 2020/190559/07
Email:
[email protected]
The Information Officer is responsible for promoting organisational compliance with POPIA, facilitating Data Subject requests, maintaining appropriate governance measures and coordinating engagement with the Information Regulator where required.
Infotech Solutions processes only personal information that is adequate, relevant and not excessive for the purpose for which it is collected.
Depending on the nature of an interaction or engagement, this may include:
We do not intentionally collect special personal information through our general website enquiry facilities unless there is a lawful and necessary reason for doing so.
We process personal information only for a specific, explicitly defined and lawful purpose and where an appropriate justification for processing exists under POPIA.
This may include processing necessary to:
Where consent is relied upon, a Data Subject may withdraw that consent subject to applicable legal and contractual limitations.
Infotech applies the principles of purpose limitation and data minimisation to the processing of personal information.
Access to personal information is limited according to legitimate business need and appropriate authorisation. We seek to avoid collecting or retaining personal information that is unnecessary for the purpose of an engagement.
Where information is obtained from a source other than the Data Subject, we process such information only where permitted by POPIA.
Where personal information is subsequently processed for a purpose other than the purpose for which it was originally collected, Infotech assesses whether the further processing is compatible with the original purpose in accordance with POPIA, unless an applicable exception permits otherwise.
Infotech applies a risk-based approach to information security and maintains appropriate, reasonable technical and organisational measures designed to preserve the confidentiality, integrity and availability of personal information.
Depending on the environment and processing risk, safeguards may include:
Security measures are selected according to the nature of the information, the processing activity, reasonably foreseeable risks and applicable contractual or regulatory requirements.
Infotech may engage appropriately authorised Operators and service providers to process personal information where necessary for business operations or service delivery.
Where an Operator processes personal information on our behalf, we require appropriate contractual and security arrangements consistent with POPIA, including obligations relating to confidentiality, authorised processing, appropriate security safeguards and notification of security compromises.
We remain accountable for ensuring that processing performed on our behalf is governed appropriately.
Infotech may use cloud infrastructure, technology providers or other service providers that involve the transfer or processing of personal information outside South Africa.
Cross-border transfers are governed in accordance with Section 72 of POPIA.
Before personal information is transferred to a third party in another country, Infotech considers whether an appropriate basis for the transfer exists, including whether the recipient is subject to a law, binding corporate rules or binding agreement that provides an adequate level of protection, or whether another ground permitted by Section 72 applies.
Where Microsoft Azure or other global cloud services form part of an environment, data residency, processing location, access pathways and applicable transfer mechanisms are considered as part of the relevant architecture and governance requirements.
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Infotech will assess and manage the incident in accordance with Section 22 of POPIA and its incident-response procedures.
Where notification is legally required, Infotech will notify the Information Regulator and affected Data Subjects as soon as reasonably possible, subject to any lawful delay permitted under POPIA.
Our response process may include containment, investigation, impact assessment, remediation, preservation of relevant evidence and review of affected security and governance controls.
Infotech takes reasonably practicable steps to ensure that personal information under our control is complete, accurate, not misleading and updated where necessary, having regard to the purpose for which the information is processed.
Data Subjects may request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained personal information as provided for by POPIA.
Personal information is not retained for longer than authorised or necessary to achieve the purpose for which it was collected, unless:
Where personal information is no longer lawfully required, it will be destroyed, deleted or de-identified in accordance with applicable requirements and appropriate information-governance procedures.
Infotech recognises that the use of artificial intelligence and automated processing can introduce additional privacy, security and accountability considerations.
Where personal information is processed using AI or automated systems, Infotech applies appropriate governance measures having regard to the purpose of processing, information sensitivity, access controls, security, transparency and applicable requirements under POPIA.
Infotech will not subject a Data Subject to a decision solely on the basis of automated processing where doing so would contravene the protections applicable under Section 71 of POPIA.
Infotech manages electronic direct marketing in accordance with POPIA.
Where prior consent is required, marketing communications will only be sent after the necessary consent has been obtained, subject to the circumstances in which POPIA permits communication with an existing customer.
Recipients may object to or opt out of direct marketing communications at any time.
Subject to POPIA and applicable legal limitations, a Data Subject may:
Prescribed forms may be required for certain requests.
Requests concerning access, objection, correction or deletion may be directed to the Information Officer:
Email: [email protected]
Infotech may take reasonable steps to verify the identity and authority of a person submitting a request before disclosing, amending or deleting personal information.
Requests will be handled in accordance with POPIA, PAIA where applicable, and relevant regulatory requirements.
Privacy compliance at Infotech is treated as an ongoing governance obligation rather than a once-off administrative exercise.
Our approach incorporates appropriate policies, assigned accountability, access governance, security safeguards, incident management, information lifecycle controls and periodic review of processing activities and associated risks.
Where the nature or risk of a processing activity warrants additional assessment, privacy and security considerations are incorporated into the design and implementation of the relevant technology or business process.
Privacy-related enquiries and Data Subject requests should first be directed to our Information Officer:
A Data Subject who is not satisfied with the outcome of a request or complaint may lodge a complaint with the Information Regulator (South Africa).
Information Regulator (South Africa)
Website:
https://inforegulator.org.za
Telephone: 010 023 5200