About POPIA
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's principal data-protection law. It promotes the protection of personal information processed by public and private bodies and establishes minimum requirements for lawful processing.
POPIA also provides for the Information Regulator, protects rights relating to unsolicited electronic communications and automated decision-making, and regulates certain transfers of personal information outside South Africa.
This page is a practical overview of how POPIA relates to DotBlack. It does not replace the Act or legal advice.
Our role under POPIA
DotBlack Projex Pty (Ltd) may act as a responsible party when we determine why and how personal information is processed—for example, when handling a website enquiry, client relationship, supplier engagement or recruitment enquiry.
We may act as an operator when processing personal information for a client under that client's instructions. The applicable agreement, purpose and security requirements guide our role in each engagement.
Eight conditions for lawful processing
Our privacy approach is informed by the eight conditions in Chapter 3 of POPIA:
- Accountability — taking responsibility for compliance.
- Processing limitation — processing lawfully, reasonably and only what is adequate, relevant and not excessive.
- Purpose specification — collecting information for a specific, defined purpose and retaining it only as permitted.
- Further processing limitation — using information in a way compatible with the original purpose, unless another lawful basis applies.
- Information quality — taking reasonable steps to keep information complete, accurate and up to date.
- Openness — maintaining appropriate records and informing people about relevant processing.
- Security safeguards — using reasonable technical and organisational measures and managing security compromises.
- Data subject participation — enabling access, correction and other applicable rights.
Your POPIA rights
Subject to the Act and any lawful limitations, a data subject may:
- ask whether we hold personal information about them;
- request access to personal information and information about relevant third parties;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing in circumstances provided by POPIA;
- withdraw consent where consent is the basis for processing;
- object to or opt out of certain direct marketing; and
- lodge a complaint with the Information Regulator.
The Information Regulator publishes official POPIA request and objection forms.
Making a request
Send a POPIA request or privacy question to mufk@dotblack.co.za. Please explain the information or processing concerned and the outcome requested. We may need to verify your identity before disclosing or changing personal information.
We will consider each request under POPIA and other applicable law. Some information may need to be retained or access may be limited where another legal obligation, privilege or permitted ground applies.
Security compromises
We use reasonable safeguards appropriate to the information and risks involved. If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will assess the incident and make notifications required by section 22 of POPIA, subject to any lawful direction or permitted delay.
Information Regulator
If you believe that your personal information has been handled unlawfully, contact us so that we can try to resolve the concern. You may also submit a complaint to the Information Regulator (South Africa).
General enquiries: enquiries@inforegulator.org.za
Toll-free: 0800 017 160
Telephone: 010 023 5200
Read the official Act
For the authoritative legal text, read the Protection of Personal Information Act 4 of 2013 on the South African Government website.
You can also access the official POPIA PDF and current guidance and forms from the Information Regulator.