POPIA Compliance Policy
My Accountant (Pty) Ltd
1. Purpose of this Policy
My Accountant (Pty) Ltd (“the Company”) is committed to safeguarding personal information in line with the Protection of Personal Information Act, 4 of 2013 (POPIA). This policy outlines how we collect, process, store, share, and safeguard personal information to ensure compliance with POPIA and to maintain the trust of our clients, partners, and employees.
2. Scope
This policy applies to:
- All directors, employees, contractors, and service providers of My Accountant (Pty) Ltd.
- All personal information processed by the Company relating to clients, prospective clients, suppliers, employees, and third parties.
3. Definitions
- Personal Information: Any information relating to an identifiable, living individual or juristic person.
- Processing: Any operation concerning personal information, such as collection, storage, use, or sharing.
- Data Subject: The person to whom the personal information relates.
- Responsible Party: My Accountant (Pty) Ltd, determining the purpose and means of processing.
- Operator: A third party processing information on behalf of My Accountant (Pty) Ltd.
4. Principles of Processing Personal Information
My Accountant (Pty) Ltd undertakes to comply with POPIA’s eight conditions:
- Accountability – We accept responsibility for lawful processing.
- Processing Limitation – We process personal information lawfully, minimally, and with consent or other justification.
- Purpose Specification – Personal information is collected for defined, legitimate business purposes.
- Further Processing Limitation – Further use will be compatible with the original purpose.
- Information Quality – We ensure information is complete, accurate, and up to date.
- Openness – We maintain transparency and provide data subjects with information about their rights.
- Security Safeguards – We implement technical and organisational security controls to protect personal information.
- Data Subject Participation – Data subjects may access, correct, or request deletion of their personal information.
5. Collection of Personal Information
We may collect personal information directly from data subjects or from third parties (with consent or lawful justification). Information collected may include:
- Identification details (names, ID numbers, company registration numbers).
- Contact information (addresses, phone numbers, email).
- Financial details (banking, tax, compliance records).
- Employment or contractual details.
6. Purpose of Processing
Personal information is processed for purposes including:
- Delivering accounting, tax, and compliance services.
- Fulfilling statutory obligations (e.g., SARS, CIPC, NCR).
- Communicating with clients, employees, and stakeholders.
- Business administration and HR management.
- Marketing our services (with consent).
7. Sharing of Personal Information
We may share personal information with:
- Regulatory authorities (e.g., SARS, CIPC, Department of Labour).
- Professional service providers and subcontractors (e.g., auditors, IT support, outsourced compliance specialists).
- Only where necessary, under strict confidentiality and in line with POPIA.
We will not sell personal information to third parties.
8. Safeguarding Personal Information
My Accountant (Pty) Ltd employs physical, technical, and administrative safeguards, including:
- Secure filing systems and restricted access.
- Encryption, firewalls, and secure passwords.
- Confidentiality agreements with staff and service providers.
- Regular training on data protection.
9. Rights of Data Subjects
Under POPIA, data subjects have the right to:
- Be informed of personal information collected.
- Access, correct, or delete their information.
- Object to certain processing activities (e.g., direct marketing).
- Lodge complaints with the Information Regulator.
Requests must be made in writing to the Information Officer.
10. Information Officer
The appointed Information Officer for My Accountant (Pty) Ltd is:
Name: Kevin William Freese
Email: info@myacc.co.za
Address: 369 Oak Avenue, Ferndale, Randburg, Johannesburg
The Information Officer is responsible for compliance with POPIA, maintaining records of processing activities, and managing data subject requests.
11. Retention of Records
Personal information will only be retained for as long as necessary to fulfil business and legal obligations. Records no longer required will be securely destroyed or anonymised.
12. Breach Notification
In the event of a data breach, the Company will notify affected data subjects and the Information Regulator as required by law, and take corrective measures to minimise risks.
13. Review of Policy
This policy will be reviewed annually or when there are material changes in business processes or legislation.
14. Acceptance
All employees and contractors must familiarise themselves with this policy and confirm compliance as a condition of employment or engagement with My Accountant (Pty) Ltd.