Draft policy
Personal information, privacy & records
Collect less, protect it well and use it only for a defined purpose.
For governing-body review. No effective date or adoption resolution has been recorded for this draft. Confirm responsible people, procedures and applicable requirements before implementation.
1. Purpose and scope
This draft addresses personal information handled in programme administration, fundraising, employment, volunteering, events and communications. The website privacy page separately describes how the current website works. This framework must be aligned with the Foundation’s actual systems and applicable South African requirements before adoption.
2. Accountability and lawful purpose
Confirm the responsible party, the relevant Information Officer arrangements and the people authorised to handle records. Maintain an inventory of information collected, why it is needed, where it is held, who can access it and how long it is retained. Identify an appropriate lawful basis for each activity rather than assuming consent is always the only basis.
3. Minimal collection and clear notices
Collect only what is necessary for the defined purpose. Explain the use of information in plain language, including relevant sharing and contact routes. Do not request identity documents, medical details or sensitive case records through the general website enquiry form. Consider additional requirements before processing children’s or other specially protected information.
4. Security and service providers
Use role-based access, strong authentication, secure storage, reliable backups and prompt removal of access when a role ends. Keep paper records in controlled storage. Assess service providers and document their security and confidentiality responsibilities. Review cross-border processing before using an external service.
5. Retention, requests and incidents
Approve a retention schedule that accounts for legal, funding and operational needs, then securely dispose of information when no longer required. Record access, correction and objection requests and route them to the responsible person. Contain suspected security incidents, preserve relevant evidence, assess notification duties and follow the Information Regulator’s applicable process.
6. Adoption requirements
Appoint accountable roles, approve notices and retention rules, document approved systems and providers, train users and test the incident process. Do not claim POPIA compliance merely because this draft exists. Review the framework at least annually and after a material change or incident.
Reference framework
Prepared with reference to the Department of Social Development’s NPO Codes of Good Practice and the Information Regulator’s POPIA resources. Review against the Foundation’s circumstances and applicable requirements before adoption.
