Moneri Dube Protection (Pty) Ltd is fully committed to compliance with the Protection of Personal Information Act (POPIA), Act 4 of 2013. This page outlines our comprehensive data protection framework, policies, and procedures designed to safeguard personal information in accordance with South African law.
Last Updated: 16 July 2026 | Effective Date: 16 July 2026
The Protection of Personal Information Act (POPIA), Act 4 of 2013, is South Africa's comprehensive data protection legislation. It regulates the processing of personal information by public and private bodies, establishing rights for data subjects and obligations for responsible parties.
Our Commitment
Full compliance with all POPIA requirements
Moneri Dube Protection has implemented a comprehensive POPIA compliance program that covers all aspects of our operations, from data collection and processing to storage, retention, and destruction. Our compliance framework is regularly reviewed and updated to ensure ongoing adherence to the Act.
Registered
With Information Regulator
Audited
Annual compliance audits
Certified
Staff POPIA training complete
In terms of Section 55 of POPIA, Moneri Dube Protection has appointed an Information Officer who is responsible for ensuring compliance with the Act. The Information Officer serves as the primary point of contact for all data protection matters.
Role
Information Officer (IO)
info@moneridubeprotection.co.za
Response Time
Within 24 business hours
The Information Officer is responsible for: developing and implementing POPIA policies, handling data subject access requests, conducting privacy impact assessments, ensuring staff training, and liaising with the Information Regulator.
Moneri Dube Protection adheres to the eight conditions for lawful processing of personal information as set out in Chapter 3 of POPIA:
We remain responsible for all personal information under our control, including information transferred to third-party processors.
Personal information is processed only with the knowledge and consent of the data subject, or where permitted by law.
Personal information is collected for a specific, explicitly defined, and lawful purpose related to our security functions.
Further processing is compatible with the purpose for which the information was originally collected.
We take reasonable steps to ensure personal information is complete, accurate, not misleading, and updated where necessary.
We maintain documentation of all processing operations and notify data subjects as required by Section 18 of POPIA.
Appropriate technical and organizational measures protect personal information against loss, unauthorized access, and unlawful processing.
Data subjects have the right to access, correct, and request deletion of their personal information in accordance with POPIA.
Chapter 2 of POPIA establishes the rights of data subjects. Moneri Dube Protection respects and facilitates the exercise of these rights:
Request confirmation of whether we hold your personal information and obtain a copy, subject to applicable fees and verification requirements.
Request correction of inaccurate, misleading, or incomplete personal information. We will verify and update records within 30 days.
Request destruction or deletion of personal information where retention is no longer necessary for the purpose collected.
Object to the processing of personal information for direct marketing purposes or on reasonable grounds relating to your particular situation.
Lodge a complaint with the Information Regulator if you believe your rights have been infringed. We will cooperate fully with any investigation.
Request justification for processing decisions that affect you, particularly where automated decision-making is involved.
To exercise any of these rights, please contact our Information Officer at info@moneridubeprotection.co.za with proof of identity. We will respond within 30 days as required by POPIA.
Moneri Dube Protection has implemented appropriate, reasonable technical and organizational measures to prevent:
AES-256 encryption for data at rest; TLS 1.3 for data in transit. All sensitive communications are encrypted end-to-end.
Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege for all systems.
24/7 security operations center monitoring, comprehensive audit logging, and intrusion detection systems.
Annual penetration testing, vulnerability assessments, and third-party security audits.
POPIA defines special personal information as information concerning a data subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour. Moneri Dube Protection:
In the event of a data breach that compromises personal information, Moneri Dube Protection will:
Notify Information Regulator
As soon as reasonably possible after discovery
Notify Affected Data Subjects
Unless identity of intruder is unknown and notification would impede investigation
Implement Remediation
Immediate containment, investigation, and corrective action
Our incident response plan includes predefined communication templates, escalation procedures, and post-incident review processes to ensure compliance with Section 22 of POPIA.
Moneri Dube Protection primarily operates within South Africa. Where cross-border transfers of personal information are necessary:
Moneri Dube Protection respects your right to privacy in direct marketing communications:
We obtain explicit consent before sending any direct marketing communications. Pre-ticked boxes or implied consent are not used.
Every marketing communication includes a clear, free, and easy-to-use opt-out mechanism. Opt-out requests are processed within 7 days.
Electronic marketing communications are sent only during reasonable hours (08:00 - 20:00) unless explicitly requested otherwise.
We maintain an internal do-not-contact register and respect the National Consumer Commission's opt-out register.
Personal information is retained only for as long as necessary to fulfill the purpose for which it was collected, or as required by law:
Client Records
Duration of agreement + 5 years
Security Incident Logs
Per PSIRA requirements
Website Analytics
Anonymized after period
Marketing Data
Until unsubscribed
Upon expiration of the retention period, personal information is securely destroyed using methods that prevent reconstruction, including secure shredding for physical documents and cryptographic erasure for electronic data.
All Moneri Dube Protection employees and contractors who process personal information receive comprehensive POPIA training:
For POPIA-related inquiries, data subject access requests, or complaints, please contact our Information Officer:
info@moneridubeprotection.co.za
Registration
PSIRA-Registered Provider
Response Time
Within 24 business hours
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa. Contact details: inforeg@justice.gov.za | JD House, 27 Stiemens Street, Braamfontein, Johannesburg.
Review our other compliance and legal policies