Data Protection

POPIA
Compliance

Your privacy is fundamental. Learn how REALNET Web Solutions protects your personal information in full compliance with South Africa's Protection of Personal Information Act (Act 4 of 2013).

Information Regulator RegisteredPAIA Manual AvailableISO 27001 Aligned
8
POPIA Conditions
72h
Breach Notification
30
Day Response Time
100%
Compliance Commitment

Eight Conditions for Lawful Processing

We adhere to all eight conditions for lawful processing as mandated by Chapter 3 of POPIA.

Accountability

We take full responsibility for protecting your personal information and have appointed an Information Officer to ensure POPIA compliance.

Our Information Officer oversees all data protection matters, conducts regular audits, and ensures staff training on privacy practices.

Processing Limitation

We only process personal information for lawful purposes and in a manner that is adequate, relevant, and not excessive.

Data minimization is practiced—we collect only what is necessary and retain it only for as long as legally required.

Purpose Specification

We collect personal information for specific, explicitly defined, and legitimate purposes related to our services.

Before any data collection, we clearly state the purpose and obtain consent where required by law.

Further Processing Limitation

We do not use your personal information for purposes other than those originally specified without your consent.

If new purposes arise, we notify affected individuals and obtain fresh consent before proceeding.

Information Quality

We take reasonable steps to ensure personal information is complete, accurate, and not misleading.

Regular data validation processes and easy correction mechanisms for data subjects.

Openness

We maintain documentation of all processing operations and make privacy practices transparent.

Our PAIA manual and privacy policy are publicly available, and we notify regulators of processing activities.

Security Safeguards

We implement appropriate technical and organizational measures to protect personal information.

Encryption, access controls, regular security assessments, and incident response protocols.

Data Subject Participation

We respect your rights to access, correct, and delete your personal information.

Streamlined processes for handling data subject requests within statutory timeframes.

Detailed Privacy Policy

Expand each section to learn more about our specific privacy practices.

Incident Response

Data Breach Response Protocol

In the unlikely event of a personal data breach, we follow strict procedures to contain, assess, and notify affected parties in compliance with Section 22 of POPIA.

1

Immediate containment and assessment of the breach scope

2

Documentation of all facts surrounding the breach

3

Notification to the Information Regulator within 72 hours if required

4

Notification to affected data subjects without undue delay when high risk

5

Implementation of remediation measures and system improvements

6

Post-incident review and policy updates

Children's Privacy

We do not knowingly collect personal information from children under 18 without parental consent. If we become aware that we have collected personal data from a child without verification of parental consent, we take steps to remove that information from our servers.

Parents or guardians who believe their child has provided us with personal information may contact us to request deletion.

Cross-Border Data Flows

Transfers outside South Africa only occur to countries with adequate data protection laws (EU, EEA, UK) or under Standard Contractual Clauses approved by the Information Regulator.

Frequently Asked Questions

Common questions about our privacy practices.

What is POPIA?

The Protection of Personal Information Act (POPIA) is South Africa's data protection law that gives effect to the constitutional right to privacy. It regulates how organizations collect, process, store, and share personal information.

How do I request my data?

Submit a data subject access request to our Information Officer via email at info@realnet-web.co.za. We will respond within 30 days as required by law.

Do you use cookies?

Yes, we use essential cookies for website functionality and analytical cookies to improve our services. You can manage preferences through our cookie banner.

Is my data transferred outside South Africa?

Limited transfers occur to service providers in the EU and USA, all under adequacy decisions or standard contractual clauses approved by the Information Regulator.

What happens if there's a data breach?

We have a comprehensive breach response plan including 72-hour regulator notification and direct communication with affected individuals for high-risk breaches.

Contact Our Information Officer

For privacy-related inquiries, data subject access requests, or to exercise your POPIA rights, please contact our appointed Information Officer.

Physical Address

Matsau Street, Ivory Park, Midrand, 1689

Response Commitment

We respond to all privacy requests within 30 days as required by POPIA. Complex requests may require additional time, with notification provided.

Information Regulator

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa.

Phone

+27 10 023 5207

Last Updated: January 2024
Version: 2.1
Next Review: July 2024