# Nkwenkwezi Foundation
## Personal information, privacy & records

Document: NKF-POL-04 | Version 1.0 | 29 September 2026
Status: Draft for governing-body review; not yet adopted.
Proposed approval authority: the Foundation’s governing body.
Effective date: to be recorded following formal adoption.
Review: annually and after material changes.

### 1. Purpose and scope

This draft addresses personal information handled in programme administration, fundraising, employment, volunteering, events and communications. The website privacy page separately describes how the current website works. This framework must be aligned with the Foundation’s actual systems and applicable South African requirements before adoption.

### 2. Accountability and lawful purpose

Confirm the responsible party, the relevant Information Officer arrangements and the people authorised to handle records. Maintain an inventory of information collected, why it is needed, where it is held, who can access it and how long it is retained. Identify an appropriate lawful basis for each activity rather than assuming consent is always the only basis.

### 3. Minimal collection and clear notices

Collect only what is necessary for the defined purpose. Explain the use of information in plain language, including relevant sharing and contact routes. Do not request identity documents, medical details or sensitive case records through the general website enquiry form. Consider additional requirements before processing children’s or other specially protected information.

### 4. Security and service providers

Use role-based access, strong authentication, secure storage, reliable backups and prompt removal of access when a role ends. Keep paper records in controlled storage. Assess service providers and document their security and confidentiality responsibilities. Review cross-border processing before using an external service.

### 5. Retention, requests and incidents

Approve a retention schedule that accounts for legal, funding and operational needs, then securely dispose of information when no longer required. Record access, correction and objection requests and route them to the responsible person. Contain suspected security incidents, preserve relevant evidence, assess notification duties and follow the Information Regulator’s applicable process.

### 6. Adoption requirements

Appoint accountable roles, approve notices and retention rules, document approved systems and providers, train users and test the incident process. Do not claim POPIA compliance merely because this draft exists. Review the framework at least annually and after a material change or incident.

### Reference framework

Department of Social Development, Codes of Good Practice for South African NPOs: https://www.dsd.gov.za/index.php/documents?catid=78&id=395&m=0&task=download.send
Information Regulator, POPIA resources: https://inforegulator.org.za/popia/

This is a proposed organisational framework. It must be checked against the Foundation’s circumstances before adoption; it is not legal certification.
