Legal & Compliance

POPIA Compliance

Moneri Dube Protection (Pty) Ltd is fully committed to compliance with the Protection of Personal Information Act (POPIA), Act 4 of 2013. This page outlines our comprehensive data protection framework, policies, and procedures designed to safeguard personal information in accordance with South African law.

Last Updated: 16 July 2026 | Effective Date: 16 July 2026

POPIA Overview

The Protection of Personal Information Act (POPIA), Act 4 of 2013, is South Africa's comprehensive data protection legislation. It regulates the processing of personal information by public and private bodies, establishing rights for data subjects and obligations for responsible parties.

Our Commitment

Full compliance with all POPIA requirements

Moneri Dube Protection has implemented a comprehensive POPIA compliance program that covers all aspects of our operations, from data collection and processing to storage, retention, and destruction. Our compliance framework is regularly reviewed and updated to ensure ongoing adherence to the Act.

Registered

With Information Regulator

Audited

Annual compliance audits

Certified

Staff POPIA training complete

Information Officer

In terms of Section 55 of POPIA, Moneri Dube Protection has appointed an Information Officer who is responsible for ensuring compliance with the Act. The Information Officer serves as the primary point of contact for all data protection matters.

Role

Information Officer (IO)

Email

info@moneridubeprotection.co.za

Response Time

Within 24 business hours

The Information Officer is responsible for: developing and implementing POPIA policies, handling data subject access requests, conducting privacy impact assessments, ensuring staff training, and liaising with the Information Regulator.

Processing Principles (Section 11)

Moneri Dube Protection adheres to the eight conditions for lawful processing of personal information as set out in Chapter 3 of POPIA:

1

Accountability

We remain responsible for all personal information under our control, including information transferred to third-party processors.

2

Processing Limitation

Personal information is processed only with the knowledge and consent of the data subject, or where permitted by law.

3

Purpose Specification

Personal information is collected for a specific, explicitly defined, and lawful purpose related to our security functions.

4

Further Processing Limitation

Further processing is compatible with the purpose for which the information was originally collected.

5

Information Quality

We take reasonable steps to ensure personal information is complete, accurate, not misleading, and updated where necessary.

6

Openness

We maintain documentation of all processing operations and notify data subjects as required by Section 18 of POPIA.

7

Security Safeguards

Appropriate technical and organizational measures protect personal information against loss, unauthorized access, and unlawful processing.

8

Data Subject Participation

Data subjects have the right to access, correct, and request deletion of their personal information in accordance with POPIA.

Data Subject Rights

Chapter 2 of POPIA establishes the rights of data subjects. Moneri Dube Protection respects and facilitates the exercise of these rights:

Right to Access (Section 23)

Request confirmation of whether we hold your personal information and obtain a copy, subject to applicable fees and verification requirements.

Right to Correction (Section 24)

Request correction of inaccurate, misleading, or incomplete personal information. We will verify and update records within 30 days.

Right to Deletion (Section 24)

Request destruction or deletion of personal information where retention is no longer necessary for the purpose collected.

Right to Object (Section 11(3))

Object to the processing of personal information for direct marketing purposes or on reasonable grounds relating to your particular situation.

Right to Complain (Section 74)

Lodge a complaint with the Information Regulator if you believe your rights have been infringed. We will cooperate fully with any investigation.

Right to Justification

Request justification for processing decisions that affect you, particularly where automated decision-making is involved.

To exercise any of these rights, please contact our Information Officer at info@moneridubeprotection.co.za with proof of identity. We will respond within 30 days as required by POPIA.

Security Safeguards (Section 19)

Moneri Dube Protection has implemented appropriate, reasonable technical and organizational measures to prevent:

  • Loss of, damage to, or unauthorized destruction of personal information
  • Unlawful access to or processing of personal information

Encryption

AES-256 encryption for data at rest; TLS 1.3 for data in transit. All sensitive communications are encrypted end-to-end.

Access Control

Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege for all systems.

Monitoring & Logging

24/7 security operations center monitoring, comprehensive audit logging, and intrusion detection systems.

Regular Assessments

Annual penetration testing, vulnerability assessments, and third-party security audits.

Special Personal Information (Section 26)

POPIA defines special personal information as information concerning a data subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour. Moneri Dube Protection:

  • Does not process special personal information unless specifically required for security vetting of personnel, with explicit consent
  • Maintains enhanced security measures for any special personal information under our control
  • Limits access to special personal information to authorized personnel with a legitimate need
  • Retains special personal information only for as long as legally required or operationally necessary

Data Breach Notification (Section 22)

In the event of a data breach that compromises personal information, Moneri Dube Protection will:

Notify Information Regulator

As soon as reasonably possible after discovery

Required by Law

Notify Affected Data Subjects

Unless identity of intruder is unknown and notification would impede investigation

As Required

Implement Remediation

Immediate containment, investigation, and corrective action

Immediate

Our incident response plan includes predefined communication templates, escalation procedures, and post-incident review processes to ensure compliance with Section 22 of POPIA.

Cross-Border Information Flows (Section 72)

Moneri Dube Protection primarily operates within South Africa. Where cross-border transfers of personal information are necessary:

  • We ensure the recipient country has adequate data protection laws substantially similar to POPIA
  • Alternatively, we obtain express consent from the data subject for the transfer
  • We implement binding corporate rules or standard contractual clauses where applicable
  • All cross-border transfers are documented and subject to prior authorization where required by the Information Regulator

Direct Marketing (Section 69)

Moneri Dube Protection respects your right to privacy in direct marketing communications:

Opt-In Required

We obtain explicit consent before sending any direct marketing communications. Pre-ticked boxes or implied consent are not used.

Opt-Out Mechanism

Every marketing communication includes a clear, free, and easy-to-use opt-out mechanism. Opt-out requests are processed within 7 days.

Timing Restrictions

Electronic marketing communications are sent only during reasonable hours (08:00 - 20:00) unless explicitly requested otherwise.

Do Not Contact Register

We maintain an internal do-not-contact register and respect the National Consumer Commission's opt-out register.

Retention & Disposal

Personal information is retained only for as long as necessary to fulfill the purpose for which it was collected, or as required by law:

Client Records

Duration of agreement + 5 years

7 Years

Security Incident Logs

Per PSIRA requirements

7 Years

Website Analytics

Anonymized after period

26 Months

Marketing Data

Until unsubscribed

Variable

Upon expiration of the retention period, personal information is securely destroyed using methods that prevent reconstruction, including secure shredding for physical documents and cryptographic erasure for electronic data.

Training & Awareness

All Moneri Dube Protection employees and contractors who process personal information receive comprehensive POPIA training:

  • Induction Training: All new personnel complete POPIA awareness training as part of their onboarding process.
  • Annual Refresher: Mandatory annual POPIA refresher training for all staff with access to personal information.
  • Role-Specific Training: Specialized training for personnel in roles with elevated data access (e.g., operations managers, IT administrators).
  • Incident Response: Regular tabletop exercises and simulations for data breach response scenarios.

Contact & Complaints

For POPIA-related inquiries, data subject access requests, or complaints, please contact our Information Officer:

Email

info@moneridubeprotection.co.za

Registration

PSIRA-Registered Provider

Response Time

Within 24 business hours

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa. Contact details: inforeg@justice.gov.za | JD House, 27 Stiemens Street, Braamfontein, Johannesburg.

Related Legal Documents

Review our other compliance and legal policies

Home Services Contact More