POPI POLICY
22 June 2021
INTRODUCTION
The Protection of Personal Information (POPI) Act is the comprehensive data protection legislation that obliges organisations to deal with the processing of personal information appropriately by applying specific principles and conditions. Millenium Star Capital (“MSC”) is an authorised financial services provider of
Through the provision of these services and as part of our integral service offering, MSC is required to collect, use, and disclose certain aspects of the personal information of our data subjects, employees, and other stakeholders. Respecting and protecting personal information is not only important to MSC but also a constitutional right, as well as both a legal and good business practice requirement. A person’s right to privacy entails having control over their personal information and being able to conduct their affairs relatively free from unwanted intrusions. Given the importance of privacy, the MSC is committed to protecting the privacy of our data subjects as well as ensuring that personal information is used appropriately, transparently, securely, and in accordance with applicable laws. This policy and our compliance framework establishes measures and standards for the protection and lawful processing of personal information within our organisation provides principles regarding the right of individuals to privacy and to reasonable safeguarding of their personal information. |
LEGISTLATIVE AND GOVERNANACE FRAMEWORK
|
MSC operates under the following framework:
|
PURPOSE AND SCOPE
|
The purpose of this policy is to:
|
WHAT IS PERSONAL INFORMATION?
|
Personal information is defined by the Protection of Personal information Act (the Act) as: “means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to –
|
OTHER DEFINITIONS IN THE POPI ACT
|
Child |
A natural person under the age of 18 years who is not legally competent, without the assistance of a competent |
|
Competent person |
Any person who is legally competent to consent to any action or decision being taken in respect of any matter |
|
Consent |
Any voluntary, specific and informed expression of will in terms of which permission is given for the processing |
|
Data subject |
The person to whom personal information relates – can be a client or an employee. |
|
De-identify and |
In relation to personal information of a data subject, means to delete any information that:
|
|
Electronic |
Any text, voice, sound, image or message, sent over an electronic communications network, which is stored in the |
|
Information |
The head of a business is the Information Officer who can delegate the IO responsibilities to any other duly authorised |
|
Operator |
A person who processes personal information for a responsible party in terms of a contract or mandate, without coming |
|
Person |
A natural person or a juristic person. |
|
Processing |
Processing means, if effect, doing something with the data. Any operation or activity or any set of operations, whether
|
|
Public record |
A record that is accessible in the public domain and which is in the possession of, or under the control of, a public body, |
|
Record |
Any recorded information, regardless of form or medium, including:
|
|
Regulator |
The Information Regulator, established in terms of section 39 of the POPI Act |
|
Re-identify and |
In relation to personal information of a data subject, means to resurrect any information that has been de-identified that:
|
|
Responsible party |
A public or private body, or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information. |
|
Restriction |
To withhold or restrict from circulation, use or publication, any personal information that forms part of a filing system but not to delete or destroy the information. |
|
Special personal information |
Personal information, as referred to in section 26 of the POPI Act:
|
|
Unique identifier |
Any identifier that is assigned to a data subject and is used by a responsible party for the purposes of the operations of that responsible party and that uniquely identifies that data subject for that responsible party. |
RIGHTS OF A DATA SUBJECT
|
The data protection laws give certain rights in relation to the personal information held on you. These are:
|
HOW IS PERSONAL INFORMATION OBTAINED
|
WHAT PERSONAL INFORMATION DOES MSC PROCESS?
|
WHO DOES MSC SHARE DATA SUBJECT’S PERSONAL INFORMATION WITH?
|
MSC needs to share data subject’s personal information with contracted service providers and partners to implement proposed solutions. MSC may also share personal information when specialised or additional guidance is required. A data subject’s personal information can be sent from South Africa to a third party in a foreign country provided that country:
MSC may also share personal information when required by any regulatory authority or any legislation or legal process as well as when we have been given express permission by a data subject to do so. MSC does not sell your personal information or share it with other parties for marketing use. |
INFORMATION OFFICER
|
MSC must appoint an Information Officer who will be responsible for ensuring that the information protection principles within the POPI Act and the controls that are in place to enforce them are complied with. Lisa Rodel is the appointed and registered Information Officer for MSC. The Information Officer is responsible for:
All employees and individuals directly associated with MSC are responsible for adhering to this policy and for reporting any security breaches or incidents to the Information Officer. |