{"id":3,"date":"2023-05-03T08:13:55","date_gmt":"2023-05-03T08:13:55","guid":{"rendered":"https:\/\/dsfurniture.co.za\/?page_id=3"},"modified":"2023-05-07T15:08:17","modified_gmt":"2023-05-07T15:08:17","slug":"popia-policy","status":"publish","type":"page","link":"https:\/\/dsfurniture.co.za\/index.php\/popia-policy\/","title":{"rendered":"POPIA Policy"},"content":{"rendered":"<p class=\"p1\"><b>BACKGROUND TO DATA PRIVACY IN SOUTH AFRICA<\/b><\/p>\n<p class=\"p3\">The Protection of Personal Information Act, 4 of 2013, (\u201cPOPIA\u201d), which came into force on 1 July 2021, is a law which regulates the use and processing of a person and \/ legal entity\u2019s personal information, this being in response to, and in order to protect and give effect to a person and\/or legal entity\u2019s rights to privacy, including the right not to have their \/ its personal information and related data misused, abused or used for ulterior purposes.<\/p>\n<p class=\"p3\">POPIA applies to personal information which belongs to individuals and legal entities (\u201cData Subjects\u201d) which is processed, be it in an automated or non-automated manner in South Africa, by another (\u201cResponsible Party\u201d) and places on any Responsible Party who is processing a data Subject\u2019s personal information, a duty to use it lawfully and only for a specific and defined purpose(s).<\/p>\n<p class=\"p3\">In terms of POPIA, Douglas Stokes Furniture , as a Responsible Party, is required to appoint an Information Officer (\u201cIO\u201d) and Deputy Information Officers (\u201cDIOs\u201d), to be responsible for establishing a POPIA Compliance Framework, and who following this, are required to assess, analyse and understand what types of personal information Douglas Stokes Furniture is processing which belongs to Data Subjects and to thereafter develop certain processes and procedures, including a POPIA Policy, which have to be followed by all Douglas Stokes Furniture personnel when they process and use another\u2019s personal information.<\/p>\n<p class=\"p3\">A Personal Information Impact Assessment as per the Douglas Stokes Furniture POPIA Compliance Framework has been carried out and created, which has indicated that Douglas Stokes Furniture , during the course of its business activities does and will continue to collect, store and process personal information about Douglas Stokes Furniture employees, its customers, suppliers and other third parties.<\/p>\n<p class=\"p3\">Furthermore, the Impact Assessment has defined and revealed that Douglas Stokes Furniture processes a large amount of different types of personal information including names, addresses, opinions, financial details, medical details and the like which pertain to current, past and prospective employees and customers, suppliers, and others who Douglas Stokes Furniture communicates and deals with and which processing is carried out for a variety of purposes, including for business, compliance and legal purposes.<\/p>\n<p class=\"p3\">Douglas Stokes Furniture also processes special purpose information including gender, sex, marital status, colour, age, race or ethnic origin, religious beliefs, trade union membership and the like for the purposes of recruitment, employment equity statistics, legal compliance and for the facilitation of union fees and memberships.<\/p>\n<p class=\"p3\">Following the Personal Information Impact Assessment, Douglas Stokes Furniture is confident that whilst this personal information is held on paper or on a computer or other media, such storage is subject to the prescribed legal safeguards as specified in POPIA and other regulations.<\/p>\n<p class=\"p3\">This Policy which applies to Douglas Stokes Furniture CC, and related South African subsidiaries, sets out how Douglas Stokes Furniture personnel are to go about processing and using another\u2019s personal information, which information needs to be processed lawfully and in accordance with POPIA.<\/p>\n<ol class=\"ol1\">\n<li class=\"li1\"><b>1. STATEMENT FROM THE Douglas Stokes Furniture BOARD OF DIRECTORS<\/b><\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">1.1 Douglas Stokes Furniture has a long and proud tradition of conducting business with the highest level of integrity, in accordance with the highest ethical standards and in full compliance with all applicable laws, including the law known as the Protection of Personal Information Act, 4 of 2013, (POPIA), which regulates the Processing of Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">1.2 The Protection of Personal Information Policy has been developed at the direction of Douglas Stokes Furniture \u2019s Board of Directors in order to provide clear guidance to all directors, employees and those who Process Personal Information on behalf of Douglas Stokes Furniture on how they are to Process Personal Information, thereby ensuring that all Personal Information Processed by Douglas Stokes Furniture is done in a lawful, transparent and consistent manner and in full compliance with all and any applicable data protection laws which may from time to time apply to its operations, including POPIA and the General Data Protection Regulation 2016\/679 (GDPR) applicable in the EU (hereinafter referred collectively as the \u201cData protection laws\u201d).<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">1.3 Douglas Stokes Furniture requires compliance with all its policies, including this Protection of Personal Information Policy.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>2. INFORMATION PROCESSING TERMS AND DEFINITIONS<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"p1\">POPIA makes use of certain terms and references, which will be used in this Policy, which are explained below:<\/p>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.1 \u201c<b>Consent\u201d <\/b>means in relation to POPIA, any freely given, specific, informed and unambiguous indication of the Data Subject&#8217;s wishes by which they, by a statement or by a clear positive action, signify agreement to the Processing of Personal Information about them;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.2 <b>\u201cData Subject\u201d <\/b>means any individual or legal entity;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.3 <b>\u201cOperator\u201d <\/b>means any person who Processes Personal Information on behalf of a Responsible Party as a contractor or sub-contractor, in terms of a contract or mandate, without coming under the direct authority of the Responsible Party;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.4 <b>\u201cProcessing Notices\u201d <\/b>means a notice setting out the prescribed information that must be provided to Data Subjects before collecting his, her or its Personal Information, (also known as \u201csection 18 POPIA notices\u201d, \u201cprivacy notices\u201d or \u201cdata protection notices\u201d).<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.5 <b>\u201cPersonal Information\u201d <\/b>means Personal Information relating to any identifiable, living, natural person, and an identifiable, existing juristic person, including, but not limited to:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 name, address, contact details, date of birth, place of birth, identity number, passport number;<\/li>\n<li class=\"li1\">\u2022 bank details;<\/li>\n<li class=\"li1\">\u2022 qualifications, expertise, employment details;<\/li>\n<li class=\"li1\">\u2022 tax number;<\/li>\n<li class=\"li1\">\u2022 vehicle registration;<\/li>\n<li class=\"li1\">\u2022 dietary preferences;<\/li>\n<li class=\"li1\">\u2022 financial details including credit history;<\/li>\n<li class=\"li1\">\u2022 next of kin \/ dependants;<\/li>\n<li class=\"li1\">\u2022 education or employment history; and<\/li>\n<li class=\"li1\">\u2022 <b>Special Personal Information<\/b>, being including race, gender, pregnancy, national, ethnic or social origin, colour, physical or mental health, disability, criminal history, including offences committed or alleged to have been committed, membership of a trade union and biometric information, such as images, fingerprints and voiceprints, blood typing, DNA analysis, retinal scanning and voice recognition.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.6 <b>\u201cPersonnel\u201d <\/b>means Douglas Stokes Furniture directors, employees and any other person who may Process Personal Information on behalf of Douglas Stokes Furniture .<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.7 \u201c<b>Processing, Process, Processed\u201d <\/b>means in relation to Personal Information, the collection, receipt, recording, collation, storage, updating or modification, retrieval, alteration, consultation or use; dissemination by means of transmission, distribution or making available in any other form; merging, linking, as well as restriction, degradation, erasure or destruction of information; or sharing with, transfer and further Processing, including physical, manual and automatic and in relation thereto which may be held on a <b>\u201cRecord\u201d <\/b>which means any recorded information housing Personal Information Processed by Douglas Stokes Furniture , or its Personnel, regardless of form or medium.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.8 <b>\u201cPurpose\u201d <\/b>means the underlying reason why a Responsible Party or Controller needs to Process a Data Subject\u2019s Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">2.9 <b>\u201cResponsible Party\u201d <\/b>means, in relation to POPIA, the person or legal entity who is Processing a Data Subject\u2019s Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>3. SCOPE AND APPLICATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"p3\">This Policy applies to any persons who Process Personal Information on behalf of Douglas Stokes Furniture , including Douglas Stokes Furniture directors, employees and Operators, who will hereinafter be referred to collectively as \u201cPersonnel\u201d.<\/p>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>4. LAWFUL BASIS FOR PROCESSING<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"p3\">In terms of POPIA, where Personal Information is Processed such Processing must be done lawfully and in a reasonable manner that does not infringe on the privacy of the Data Subject. In order to discharge the above obligations, Personnel must comply with the Processing guides, rules and procedures set out below.<\/p>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>5. CONSENT<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.1 A Data Subject does not have to Consent to the Processing of his, her or its Personal Information where there is a lawful basis for such Processing. A lawful basis for Processing in terms of the Data Processing laws, is where:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Processing is necessary to conclude a contract to which the Data Subject is a party and to perform contractual obligations or give effect to contractual rights;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Processing is necessary in order to comply with a law or to comply with certain legal obligations imposed by a law;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Processing is necessary to protect Douglas Stokes Furniture \u2019s legitimate interests or rights, the Data Subject\u2019s legitimate interests or rights or a third party\u2019s legitimate interests or rights, unless there is a good reason to protect the Data Subject\u2019s Personal Information which overrides those legitimate interests;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Processing is necessary in order to perform a public duty or to perform tasks carried out in the public interest or the exercise of official authority.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.2 Where there is no lawful basis for the Processing, then the Data Subject, has to Consent to the Processing.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.3 Personnel must ensure that prior to Processing a Data Subject\u2019s Personal Information, that there is either a lawful reason for the Processing, or alternatively that the Data Subject has Consented to such Processing, which lawful reason will be described under the specific and informative Douglas Stokes Furniture Processing notice, or in the absence of a lawful reason, will call for the Data Subject\u2019s consent.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.4 A Data Subject may withdraw his, her, its Consent so long as it provides Douglas Stokes Furniture with a \u201cwithdrawal of consent notice\u201d, which notice is available on the Douglas Stokes Furniture website, which request will be handled and actioned directly by the duly appointed Douglas Stokes Furniture Information Officer or Deputy Information Officer, (Information Officer), which outcome in turn, will be relayed to the respective Personnel who has been Processing such Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.5 A Data Subject may not withdraw Consent where no Consent is required, i.e., where Douglas Stokes Furniture can show that there is a lawful basis for the Processing. In such a case the Data Subject may only object to such Processing, provided that an \u201cObjection notice\u201d is sent to Douglas Stokes Furniture , which notice is available on the Douglas Stokes Furniture website, which request will be handled and actioned directly by the Information Officer and which outcome will be relayed to the respective Personnel who has been Processing such Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.6 Where a Data Subject withdraws Consent or objects to the Processing, in such case Douglas Stokes Furniture and the respective Personnel who has been Processing the impacted Personal Information, will have to stop Processing the Personal Information, unless Douglas Stokes Furniture can show compelling legitimate grounds for the Processing which overrides the interests, rights and freedoms of the Data Subject, or the Processing is necessary for the establishment, exercise or defence of legal claims.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">5.7 The Information Officer will at the time of the withdrawal or objection referred to above, explain to the Data Subject the effects and consequences of any withdrawal or objection and relay the outcome to the respective Personnel who has been Processing such Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>6. PURPOSE SPECIFIC<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">6.1 Personal Information:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 may only be collected for a specified, explicit and legitimate purpose;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 must only be used for the purpose for which it was collected and for no other purpose, unless the Data Subject has been informed of the other purposes;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 may not be further Processed or used for any subsequent purpose, unless that Personal Information is required for a similar purpose; and such Processing is compatible with the initial purpose.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">6.2 Douglas Stokes Furniture for the purposes of carrying out its business and related objectives Processes Personal Information belonging to a vast range of Data Subjects, including employees and staff, prospective employees and job applicants, students and interns, service providers and contractors, vendors, clients, customers, and other third parties, which Processing is required for a variety of business-related purposes.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">6.3 Examples of these purposes are described below:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 to recruit and employ &#8211; employment;<\/li>\n<li class=\"li1\">\u2022 to sell or purchase goods and services &#8211; procurement and supply chain;<\/li>\n<li class=\"li1\">\u2022 concluding and managing a contract or business transaction &#8211; contract;<\/li>\n<li class=\"li1\">\u2022 conducting criminal reference checks &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 risk assessments &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 insurance and underwriting purposes &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 assessing and Processing queries, enquiries, complaints, and\/or claims &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 conducting credit checks &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 confirming, verifying and updating personal details &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 detection and prevention of fraud, crime, money laundering or other malpractices<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p class=\"p1\">&#8211; legitimate interest;<\/p>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 conducting market or customer satisfaction research &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 direct marketing &#8211; marketing;<\/li>\n<li class=\"li1\">\u2022 audit and record keeping purposes &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 managing debtor and creditors &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 complying with laws and regulations &#8211; laws;<\/li>\n<li class=\"li1\">\u2022 dealing with regulators &#8211; laws;<\/li>\n<li class=\"li1\">\u2022 paying taxes &#8211; laws;<\/li>\n<li class=\"li1\">\u2022 collecting debts or legal proceedings &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 communications &#8211; legitimate interest;<\/li>\n<li class=\"li1\">\u2022 managing employees &#8211; employment.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">6.4 Douglas Stokes Furniture personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensure that before Personal Information is Processed, there is a valid and legitimate reason for such Processing; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 advise all Data Subjects why the Personal Information is required, i.e., the purpose for the Processing, which purpose will be described under the Douglas Stokes Furniture Processing notices, housed on the Douglas Stokes Furniture website, which the Data Subject should be directed to.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>7. ACCURACY<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">7.1 All Personal Information Processed by Douglas Stokes Furniture must be accurate and, where necessary, kept updated.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">7.2 In order to ensure that Personal Information is accurate and is up to date, Personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 take all and every reasonable step to ensure that all Personal Information which they Process is accurate, having regard to the purposes for which it is Processed, and where it is found to be inaccurate, that it is where possible, updated and rectified without delay;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 implement procedures allowing Data Subjects to update their Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 send out regular communications to Data Subject requesting \u201cupdates to details\u201d which if responded to, should be acted on immediately by the relevant or responsible department;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 where appropriate, and possible, ensure that any inaccurate or out-of-date records are updated and the redundant information deleted or destroyed;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 take note of the rights of the Data Subject in relation to updates and rectifications of Personal Information, housed under the Douglas Stokes Furniture Processing Notices and give effect to any update request, when such request has been communicated through to it by the Information Officer.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>8. DATA MINIMISATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">8.1 Douglas Stokes Furniture may not Process Personal Information which is not necessary for the Purpose for which the Personal Information is Processed.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">8.2 Personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensure that when they process Personal Information on behalf of Douglas Stokes Furniture , that it is adequate, relevant and limited to what is necessary in relation to the purposes for which it is Processed; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 revisit all pre-populated questionnaires and forms which are currently used to collect or house Personal Information and consider the purpose or reason for the collection and thereafter analyse the types of Personal Information which is request or collected and where of the view that certain Personal Information is not needed for the defined purpose, then such information should no longer be called for, collected and\/or recorded and the relevant areas where this information is housed or asked for should be deleted.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>9. TRANSPARENCY AND PROCESSING NOTICES<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">9.1 Douglas Stokes Furniture has a duty to show that it has dealt with a Data Subject in a transparent manner.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">9.2 In order to demonstrate transparency, Douglas Stokes Furniture must refer all Data Subjects, to a specific and informed Processing Notice, at the time when Douglas Stokes Furniture collects and Processes a Data Subject\u2019s Personal Information or within a reasonable period thereafter, which Processing notice must set out:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the types of Personal Information Processed, and the purpose or reason for the Processing;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the lawful basis relied upon for such Processing or whether Consent is required for the Processing;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the period for which the Personal Information will be retained;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 who the Personal Information will be shared with, including external or cross border transfers and the mechanism(s) relied upon for such transfer;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the security measures which are in place to protect the Personal Information, including where the Personal Information is sent to parties cross border and the mechanism(s) relied upon for such protection; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the respective rights of the Data Subject and how these rights may be exercised.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">9.3 In order to meet its obligations under 9.2 above, Douglas Stokes Furniture has developed and placed on its website the following informed and specific Processing Notices which apply to the different Data Subject categories with whom it deals with:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a <b>Human Resources Processing Notice, <\/b>which applies to all employees \u2013 perspective and actual, all bursary or learnership beneficiaries &#8211; prospective or actual;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a <b>Procurement Processing Notice<\/b>, which applies to all participants in the Douglas Stokes Furniture supply chain, including persons who provide goods and services to Douglas Stokes Furniture (service providers), persons or entities who purchase goods or services from Douglas Stokes Furniture (Customers), and\/or other parties who Douglas Stokes Furniture may engage with and who make up the Douglas Stokes Furniture Procurement and supply chain, including Regulators;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a <b>Company Secretarial Processing Notice<\/b>, which applies to all Data Subjects who deal with Douglas Stokes Furniture from a company secretarial perspective, including directors, trustees, investors, Regulators, shareholders, stakeholders and\/or other parties who Douglas Stokes Furniture may engage with;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a <b>Security Processing Notice<\/b>, which applies to any persons who come onto the Douglas Stokes Furniture sites, facilities and offices who Douglas Stokes Furniture may engage with;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a <b>Website Privacy Notice <\/b>which applies to any persons who make use of the Douglas Stokes Furniture websites, social media websites, emails, and other IT related communications facilities and platforms.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">9.4 In order to give effect to the above transparency requirement, Personnel:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 must all understand the provisions of the Data Processing laws;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 familiarise themselves with the abovementioned Douglas Stokes Furniture Processing Notices and any others which Douglas Stokes Furniture may implement from time to time, and any changes made thereto;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 familiarise themselves with, where applicable, the Douglas Stokes Furniture standard binding corporate rules, its standard Personal Information transfer agreement and\/or its Operator agreement;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensure that all Douglas Stokes Furniture documents, forms or other records (Records) which house or call for Personal Information contain the following Data Processing details:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p class=\"p3\"><i>\u201cPlease note that in order for Douglas Stokes Furniture to engage with you, it will have to Process certain Personal Information which belongs to you, which Processing is described and explained under the specific and informative Douglas Stokes Furniture Processing Notices, housed for ease of reference on the Douglas Stokes Furniture \u2019s website which we ask that you download and read. By providing us with the required Personal Information, such act will be taken as an indication that you have read and agree with the provisions described under the Processing Notice and where applicable, you consent to the processing by us of your Personal Information.<\/i><\/p>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 at the time of Processing, direct the Data Subjects who you deal with to the applicable area of the Douglas Stokes Furniture website where the specific and informative Douglas Stokes Furniture Processing notices are housed.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>10. GENERAL DUTIES: CONFIDENTIALITY, INTEGRITY AND SECURITY OF PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">10.1 In order to safeguard, secure and ensure the confidentiality and integrity of all Personal Information held by or under the control of Douglas Stokes Furniture , Douglas Stokes Furniture together with its Personnel must;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 identify all reasonably foreseeable internal and external risks to Personal Information in its possession or under its control;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 document the identified risks;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 establish, in response to the identified risks, reasonable technical and organizational measures across all areas where Personal Information is held or stored, including electronic and physical mediums;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 implement and maintain all approved and required measures across all areas where Personal Information is held or stored, including electronic and physical measures, all which are designed to minimise the risk of loss, damage, unauthorised destruction and\/or unlawful access of Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 regularly verify that these measures are effectively implemented; and ensure that the measures are continually updated in response to new risks or deficiencies in previously implemented measures and safeguards, which measures include, where appropriate, among others, the following:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">o the pseudonymisation and encryption of Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">o ongoing efforts to ensure the long-term confidentiality, integrity, availability and resilience of Personal Information housed within the Douglas Stokes Furniture environment;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">o applications and processes which have the ability to rapidly restore the availability of and access to Personal Information in the event of a tangible or technical incident; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">o procedures for the regular review, assessment and evaluation of the effectiveness of the technical and organizational measures taken to ensure the security of Processing, including regular IT Security Audits.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">10.2 The duty to ensure data privacy, confidentiality and integrity of Personal Information starts when Douglas Stokes Furniture initially interacts with a Data Subject and will continue throughout the relationship, until the purpose for the Processing of the Personal Information comes to an end.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>11. RECORDS MANAGEMENT DUTIES: CONFIDENTIALITY, INTEGRITY AND SECURITY OF PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1 In order to ensure the confidentiality and integrity of all Records which house or contain Personal Information which are held by Douglas Stokes Furniture , and in order to safeguard and secure these Records, Personnel must ensure that:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.1 all Processing of Personal Information activities and communications are reduced to writing and retained in a Record, which Record may either be electronic, or paper based;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.2 each Record created is housed in a folder (Folder), and where applicable in sub folders of the Folder being a storage area, either electronic or paper based and in turn each Folder \/ subfolder is given an appropriate title or Folder name using the Douglas Stokes Furniture naming convention set out under <span class=\"s3\"><b>Annexure \u201cA<\/b><\/span>;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.3 Folders and Records must be named in a consistent and logical manner so they can be located, identified and retrieved as quickly and easily as possible;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.4 all Folders and Records must be stored and saved in a way that the contents are identifiable as per the agreed Douglas Stokes Furniture naming convention<b>;<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.5 the name of the Folder and related sub folders and Records held in such Folders must be recorded in a Department specific Records Register which has to be compiled for each department, using the Douglas Stokes Furniture standard Department Management Register set out under <span class=\"s3\"><b>Annexure \u201cA\u201d,<\/b><\/span><b> <\/b>including the following details:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the name of the Folder and related Records;<\/li>\n<li class=\"li1\">\u2022 format of the Folder and related Records;<\/li>\n<li class=\"li1\">\u2022 location of Record &#8211; including physical or electronic location;<\/li>\n<li class=\"li1\">\u2022 who has access to the Folder, and the Records;<\/li>\n<li class=\"li1\">\u2022 status of the Folder and the Records;<\/li>\n<li class=\"li1\">\u2022 retention period pertaining to the Folder and\/or Records; and<\/li>\n<li class=\"li1\">\u2022 destruction date of the Records, when available;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.6 their respective department head reviews their own department specific Records Register annually to ensure compliance with this Policy;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.1.7 each department provides a copy of its department specific Records Register to a Douglas Stokes Furniture Records Manager, or where there is no Manager, to the Information Officer, annually, or on request.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">11.2 Upon termination of employment, or change of job roles or responsibilities of Personnel, the affected line manager responsible for such Personnel must ensure that all access rights to any Douglas Stokes Furniture Folders or Records is removed immediately and that all Douglas Stokes Furniture assets used to access the Folders and or Records are returned to Douglas Stokes Furniture , and that all physical access rights to the Douglas Stokes Furniture premises and facilities are revoked or cancelled.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>12. RECORDS MANAGEMENT DUTIES: STORAGE OF RECORDS HOUSING PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">12.1 In order to ensure the confidentiality and integrity of all paper-based Records which house or contain Personal Information, which are held by Douglas Stokes Furniture , and in order to safeguard and secure these Records, Personnel must ensure that all paper-based Records:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 which are housed in physical storage areas are labelled and the details recorded in the Department Records Register;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 when in use, are not left around for others to access, and are not left in places where persons can view the contents e.g., on a printer or on unmanned desks;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 are stored securely when not in use, in Folders, which in turn are placed in locked boxes, drawers, cabinets, or similar structures or containers;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that only Personnel who are required, on an operational and need to know basis, are given access to such Records and\/or Folders; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 such Records and\/or Folders are only removed from Douglas Stokes Furniture premises if such removal is recorded in the Department Management Register and when removed off site, such Records are safeguarded and kept confidential.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">12.2 In order to ensure the confidentiality and integrity of all electronic Records which house or contain Personal Information, which are held by Douglas Stokes Furniture , and in order to safeguard and secure these Records, Personnel must ensure that:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 they comply with all applicable Douglas Stokes Furniture IT Policies and Procedures, especially the Douglas Stokes Furniture IT end user policy;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all electronic Records are stored and housed on Douglas Stokes Furniture servers which are protected by approved security software, and one or more firewalls under the direction of the Douglas Stokes Furniture IT Manager and where transferred or uploaded to cloud computing services from computers, devices and applications, that these services have been approved by the Douglas Stokes Furniture IT Manager;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all devices where electronic Folders and\/ or Records are stored, are password protected and that passwords are not written down or shared, irrespective of seniority or department, which passwords must be strong passwords which are changed regularly. If a password is forgotten, it must be reset using the applicable method;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all network devices and drives where electronic Folders and Records are stored have access control measures in place;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 electronic Folders and Records are not stored on mobile devices and removable media, which includes, but is not limited to: smart phones, tablets and Ipads, Digital media, USB sticks, external hard drives, CDs, DVDs, memory cards, tapes, unless the device is password protected and the content of such Record(s) is where possible encrypted;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 where one needs to use and access the contents of an electronic Folder or Record, off site, which will not be accessed using Douglas Stokes Furniture secured servers, and which will be downloaded on to portable device for off-site working purposes, such person must only remove the Folders and\/or Records or parts thereof if such removal is recorded in the Department Records Register; only the record(s) which are necessary for one\u2019s immediate needs are removed; where possible and feasible, the Personal Information to be removed is strongly encrypted; and when removed off site, such Records are safeguarded and kept confidential and when no longer needed, that the removed Folder and\/or Record, once dealt with is deleted from the portable device;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all electronic Records are regularly backed up using the Douglas Stokes Furniture provided systems and applications and in accordance with backup protocols. Such backups will be tested regularly in line with Douglas Stokes Furniture standard backup procedures and protocols under the direction of the IT Manager;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all device screens, when not in use are always locked especially when left unattended and password protected;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 electronic Records are only transmitted over secure networks, including wireless and wired networks.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>13. RECORDS MANAGEMENT DUTIES: RETENTION AND DISPOSAL OF RECORDS HOUSING PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">13.1 Folders and Records housing Personal Information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed, unless the longer retention of the Folder or Record:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 is required or authorised by law;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 is required by Douglas Stokes Furniture for lawful purposes related to its functions or activities;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 is required by a contract between the parties thereto; or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 is as per consent, received from the Data Subject who owns the Personal Information.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">13.2 Records housing Personal Information may be retained indefinitely for business, historical, statistical or research purposes provided that Douglas Stokes Furniture has established appropriate safeguards against the Records being used for any other purposes.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">13.3 Each Douglas Stokes Furniture department will be responsible for the correct management of their Folders and Records, including the closing and archiving of these Records when they are no longer needed.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">13.4 In order to ensure that the above duties are discharged, all Personnel must ensure that:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 on an ongoing basis they manage the respective life cycles of Folders and Records under their control;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 they establish what record retention periods and related requirements apply to the respective Folders and Records under their control, as per the Douglas Stokes Furniture Records Retention Policy;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the record retention periods and related requirements are recorded in the department\u2019s relevant Document Management Register;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a Folder and Record is formally closed when the matter housed in the Folder or Record comes to an end, which is documented in the relevant Document Management Register;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 a closed Folder or Record is moved to a dedicated archive storage area where the Folder or Record will be retained for the required retention period;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 Folders and Records are only archived in secure storage media;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 only authorized personnel are granted physical and system-based access to archived Folders and Records;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 Folders and Records in archived areas are regularly backed up;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 once the prescribed retention period in respect of an archived Folder or Record has expired, the Folder or Record is marked \u201cfor deletion or disposal\u201d;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 before a Folder or Record is deleted or destroyed, the department head must obtain permission to delete or destroy said Folder or Record from the Records Manager where applicable, and the Information Officer, which will be reflected in the relevant department Document Management Register;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 each department, once approval for the deletion \/ destruction of the Folder or Record has been received, via the head of the department, will be responsible for the deletion or destruction of such archived Folder or Record after the expiration of the retention period, unless instructed otherwise by the Records Manager where applicable, or the Information Officer, for example when there is a requirement to place the Folder or Record under a legal hold;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the legal hold status must be indicated under the relevant Folder or Record in the relevant Document Management Register;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 during a legal hold procedure, the affected Folder or Record must not be destroyed, even if the retention period has expired;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the deletion \/ disposal of Folders and Records must ensure the permanent and complete deletion \/ disposal of all originals and reproductions (including both paper and electronically stored records);<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the department head is responsible for documenting the destruction details under the relevant department Document Management Register.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>14. OPERATORS<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">14.1 Where Douglas Stokes Furniture makes use of an Operator, in terms of section 19-21 of POPIA, it must ensure that the Operator only uses the Personal Information as per the mandate to Process issued by Douglas Stokes Furniture , keeps the Personal Information placed under its control, confidential , secure and safe, and that a standard Douglas Stokes Furniture Operator agreement\/addendum is concluded between Douglas Stokes Furniture and the Operator, which sets out the above provisions and any other terms and rules which the Operator will have to followed when Processing Personal Information on behalf of Douglas Stokes Furniture , which Operator agreement\/addendum is housed on the Douglas Stokes Furniture website.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">14.2 All Personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 familiarise themselves with the standard Douglas Stokes Furniture Operator agreement\/addendum;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ascertain who they use as Operators, now and in the future, include such details under an Operator register, and ensure that all such Operators sign the standard Douglas Stokes Furniture Operator agreement\/addendum or a similar one which has been approved and signed off by the Douglas Stokes Furniture Legal Department;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensure that Operator agreement\/addendum is followed by an Operator and that where an Operator agreement\/addendum is breached, bring this to the attention of one\u2019s line manager and the Information Officer and following a decision reached by these parties, carry out the planned course of action, which ultimately must aim to protect and secure the Personal Information which is the subject matter of that Operator agreement\/addendum.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>15. SHARING PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">15.1 Douglas Stokes Furniture may not share Personal Information with third parties in South Africa, unless:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 there is a legitimate business need to share the Personal Information; or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Data Subject has been made aware that his, her or its Personal Information will be shared with others and has, where required, given consent to such sharing; or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the person receiving the Personal Information has agreed to keep the Personal Information confidential and to use it only for the purpose for which it was shared under the standard Douglas Stokes Furniture Personal Information transfer agreement, which is housed on the Douglas Stokes Furniture website or where acting as an Operator has concluded an Operator agreement with Douglas Stokes Furniture, before receipt of the Personal Information.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">15.2 In order to ensure that the above takes place, Personnel must ensure:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that where Personal Information is shared externally with a third party, there is a legitimate business need to share the Personal Information; or the Data Subject has been made aware that his, her or its Personal Information will be shared with others and has, where required, given consent to such sharing; or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 or in the absence of the above two situations, has, signed the standard Douglas Stokes Furniture Personal Information transfer agreement which is concluded with the recipient, before receipt of the Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that where Personal Information is shared with an Operator, that the standard Douglas Stokes Furniture Operator agreement\/addendum is concluded with the Operator before receipt of the Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that any requested deviations for the standard Douglas Stokes Furniture Personal Information transfer agreement or the Operator agreement\/addendum is vetted and approved by the Douglas Stokes Furniture Legal Department;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 when sending emails which contain Personal Information, that they are marked \u201cconfidential\u201d, do not contain the Personal Information in the body of the email, whether sent or received, but rather placed in an attachment, which attachment is password protected or encrypted before being transferred electronically;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that Personal Information is not transferred or sent to any entity not authorised directly to receive it;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that where Personal Information is to be sent by facsimile transmission, that the recipient has been informed in advance of the transmission and that he or she is waiting by the fax machine to receive the data;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that where Personal Information is transferred physically, whether in hardcopy form or on removable electronic media, that it is passed directly to the recipient or sent using recorded deliver services and housed in a suitable container marked \u201cconfidential\u201d;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 that where Personal Information is shared internally, that adequate measures are put in place to protect the confidentiality and integrity of such information.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>16. CROSS BORDER TRANSFERS OF PERSONAL INFORMATION<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">16.1 Douglas Stokes Furniture may not transfer Personal Information to another party who is situated outside South Africa, unless<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Data Subject Consents (under POPIA); or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the transfer is necessary in order to perform a contract between Douglas Stokes Furniture and a Data Subject, or for reasons of public interest, or to establish, exercise or defend legal claims or to protect the vital or legitimate interests of the Data Subject in circumstances where the Data Subject is incapable of giving Consent; or<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the country where the Personal Information is being transferred to provides the Data Subject with the same level of protection as is housed under the data processing laws applicable in South Africa; or alternatively,<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 Douglas Stokes Furniture has concluded a Personal Information data transfer agreement with the recipient of the Personal Information, either in the form of a standard binding corporate rule, or an Operator agreement\/addendum or a Personal Information transfer agreement, which sets out the rules which apply to the receipt and subsequent Processing of that Persona Information.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">16.2 In order to ensure that the above is followed, Personnel may not transfer Personal Information to areas outside South Africa, unless one of the following controls and safeguards are in place:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the South African Data Privacy \/Personal Information Regulator has issued an \u201cadequacy decision\u201d confirming that the territory or country where Douglas Stokes Furniture proposes transferring the Personal Information to, has adequate Data Protection laws in place which will afford the Data Subject with the same level of protection as that under POPIA;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the standard Douglas Stokes Furniture Personal Information data transfer agreement or Operator agreement\/addendum has been concluded with recipient of the Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the Data Subject has given Consent (POPIA) to the proposed transfer, having been fully informed of any potential risks;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the transfer is necessary in order to perform a contract between Douglas Stokes Furniture and a Data Subject, for reasons of public interest, to establish, exercise or defend legal claims or to protect the vital interests of the Data Subject in circumstances where the Data Subject is incapable of giving Consent (POPIA).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>17. DIRECT MARKETING<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">17.1 Direct marketing, including unsolicited direct electronic marketing is prohibited unless the Data Subject has consented to the receipt of this marketing material.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">17.2 In order to ensure that direct marketing is sent out in a lawful manner, all Personnel must ensure that:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 all Douglas Stokes Furniture customers, when approached or dealt with for the first time, are given the opportunity in an informal manner to agree or disagree to the receipt of any Douglas Stokes Furniture direct marketing material and that where consent is granted, and when marketing material is sent to these Data Subjects, that the material houses an \u201copt out\u201d form, allowing the Data Subject to opt out of any further marketing material should it so elect; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 before direct marketing is sent to a non-customer that such person provides his, her, or its consent thereto, which will be in the form of the prescribed \u201copt in\u201d notice, available on the Douglas Stokes Furniture website;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 when marketing material is sent to Data Subjects, who have \u201copted in\u201d that the material houses an \u201copt out\u201d form, allowing the Data Subject to opt out of any further marketing material; and<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 when a Data Subject exercises his, her or its right to object to receiving direct marketing, in the form of an opt out, that such opt out is recorded and given effect to, and that no further direct marketing is sent to the opted-out customer.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">17.3 All Personnel, especially those who engage in direct marketing must familiarise themselves with the Douglas Stokes Furniture marketing opt in and opt out forms which are available on the Douglas Stokes Furniture website.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>18. REPORTING PERSONAL INFORMATION BREACHES<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.1 In the event of a Personal Information breach, Douglas Stokes Furniture has a duty to give notice of such breach to the Regulator who is in charge of POPIA, being the Information Regulator (Information Regulator), and to the Data Subject(s) whose Personal Information has been affected as a result of such breach.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.2 Douglas Stokes Furniture has put in place appropriate procedures to deal with any Personal Information breach and will notify the Information Regulator and\/or the Data Subjects, as the case may be, when it is legally required to do so of any breach.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.3 Personnel have a duty to<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.3.1 immediately report through to the Information Officer, any suspected or known Personal Information breach; using the prescribed Douglas Stokes Furniture data breach report, which report must contain the following details:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 categories and approximate number of Data Subjects concerned;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 categories and approximate number of Personal Information records concerned;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 the likely cause of and the consequences of the breach;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 details of the measures taken, or proposed to be taken, to address the breach including, where appropriate, measures to mitigate its possible adverse effects;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 which report format is annexed hereto marked <span class=\"s3\"><b>Annexure B.<\/b><\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.3.2 keep such information strictly private and confidential;<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">18.3.3 ensure that they do not deal with any persons in relation to the Personal Information breach, including any officials to investigators, noting that only the Information Officer with the approval of the Douglas Stokes Furniture \u2019s Board has the right to report any Personal Information or security breach to the Information Regulator and\/or the affected Data Subjects, as the case may be and to deal with any person in connection with such matter.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>19. DATA SUBJECT RIGHTS AND REQUESTS<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">19.1 A Data Subject has a number of rights under POPIA in relation to his, her or its Personal Information, including the right to:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 withdraw Consent;<\/li>\n<li class=\"li1\">\u2022 object to Processing;<\/li>\n<li class=\"li1\">\u2022 obtain confirmation of Processing and\/or access to Personal Information;<\/li>\n<li class=\"li1\">\u2022 amend, update and delete Personal Information;<\/li>\n<li class=\"li1\">\u2022 to object to direct marketing;<\/li>\n<li class=\"li1\">\u2022 be notified of a personal information breach; and<\/li>\n<li class=\"li1\">\u2022 to complain.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">19.2 Douglas Stokes Furniture has developed, implemented and will maintain certain processes and related forms which give effect to these Data Subject rights, which processes and related forms are contained in the specific and informed Douglas Stokes Furniture Processing notices which can be found on the Douglas Stokes Furniture website. When a Data Subject is desirous of exercising these rights, then he, she or it must be directed to the Douglas Stokes Furniture website (<span class=\"s3\">www.dsfurniture.co.za<\/span><b>) <\/b>where the relevant Processing notices and related prescribed forms are housed, which form, once completed must be directed to and handled directly by the Information Officer or his or her deputy, and no other, who will be responsible for dealing with the request and advising the affected Data Subject and\/ or any affected Personnel of any decision and outcome in relation to such request.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">19.3 Personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 familiarise oneself with the Data Subjects\u2019 rights, and the related processes and forms which need to be followed and completed in order to access these rights;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 take note of and give effect to these processes;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 in particular note that where a Data Subject seeks advices on what Personal Information Douglas Stokes Furniture holds and which pertains to that Data Subject or where the Data Subject is desirous of accessing this Personal Information, that such right has to be exercised using the \u201crequest for access to information\u201d procedure which is described under a law known as the Promotion of Access to Information Act, 2000 (PAIA) and which request procedure is more fully set out under Douglas Stokes Furniture \u2019s PAIA Manual available on the Douglas Stokes Furniture website.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 where asked by any Data Subject to give effect to these rights, do not deal with the request directly but instead direct the Data Subject to the relevant process and form on the Douglas Stokes Furniture website, and provide assistance in so far as completing the form only.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>20. THE RIGHT TO COMPLAIN<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.1 A Data Subject has to right lodge a complaint with regards to the Processing of his, her or its Personal Information.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.2 Douglas Stokes Furniture has established for this purpose, an internal compliant resolution procedure.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.3 Should a Data Subject wish to submit a complaint, Personnel must, if contacted by the Data Subject, ask the Data Subject to complete the prescribed \u201cpersonal information processing complaint\u201d form, which is housed on Douglas Stokes Furniture website, and to submit the complaint, once completed, directly to the Information Officer.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.4 On receipt of the complaint, the Information Officer will attempt to hear and resolve the matter, internally and failing resolution will provide the Data Subject with a non- resolution notice.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.5 If the Information Officer and Data Subject are able to resolve the matter, a record setting out the solution will be compiled, and signed by the parties and any other affected persons provided with details of the resolution.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">20.6 Where the parties are unable to resolve the matter, the Data Subject on receipt of the non-resolution notice, will have the right to refer the complaint to the Information Regulator.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>21. GOVERNANCE<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">21.1 Douglas Stokes Furniture has appointed the below mentioned parties as its Information Officer(s) and Deputy Information Officers, who will be responsible for the following:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 developing, constructing and once prepared, implementing and overseeing an enterprise-wide Personal Information Processing framework and related roadmap including various Personal Information Processing procedures and policies, including this Policy;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 monitoring compliance with this Policy, the various Personal Information Processing procedures and the Data Processing law;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 providing all Personnel with the necessary and required Personal Information Processing training;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 providing ongoing guidance and advice on Personal Information Processing;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 conducting Personal Information impact assessments when required, including base line risk assessments of all the Douglas Stokes Furniture \u2019s Personal Information Processing activities;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensuring that all operational and technological Personal Information and data protection standards are in place and are complied with;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 working closely with IT in order to ensure that appropriate technological and operational measures have been implemented in order to ensure the safety and security of all electronically stored Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 receiving and considering reports from IT about compliance with all technological and operational data protection standards and protocols;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 be entitled and have authorisation in conjunction with the Douglas Stokes Furniture HR function, to initiate disciplinary proceedings against Personnel who breach any technological and\/or organizational and\/or operational data protection standard, rule, custom, instruction, policy, practice and\/or protocol (verbal, in writing or otherwise), including this Policy;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 review and approve any contracts or agreements which deviate from the standard Douglas Stokes Furniture Processing documentation;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 attend to requests and queries from Data Subjects, including requests for access to their Personal Information;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 liaising with and\/or co-operating with any regulators or investigators or officials who may be investigating a Personal Information or data privacy matter.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">21.2 All queries and concerns in relation to the Processing of Personal Information within the Douglas Stokes Furniture operations or concerning Douglas Stokes Furniture activities, must be taken up with the Information or Deputy Information Officers.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">21.3 The Douglas Stokes Furniture Information Officers and Deputy Information Officers are:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>COMPANIES<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Information Officer<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Name: <\/b>DOUGLAS STOKES FURNITURE CC<\/p>\n<p class=\"p1\"><b>Reg number: <\/b>CK98006533\/23<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Name: <\/b>Vanessa Stokes<\/p>\n<p class=\"p1\"><b>Address: <\/b>78a Pigot Road, Protea Ridge, Krugersdorp, 1739<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Address: <\/b>8 Koevoet Street, Kya Sands Ext 3, Randburg,2163<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Tel: <\/b>0117043124<\/p>\n<p class=\"p1\"><b>Cell: <\/b>0842500934<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Tel: <\/b>0117043124<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Identity number: <\/b>7102020145089<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p6\"><span class=\"s1\"><b>Email: <\/b><a href=\"mailto:vpstokes@gmail.com\"><span class=\"s2\">vpstokes@gmail.com<\/span><\/a><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">21.4 Douglas Stokes Furniture\u2019s IT department will be responsible for the following:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 conducting cyber security risk assessments including base line risk assessments of all Douglas Stokes Furniture information technology activities;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensuring that adequate and effective IT operational and technological data protection procedures and standards are in place in order to address all IT security risks;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensuring that all systems, services and equipment used for Processing and\/or storing data adheres to internationally acceptable standards of security and data safeguarding, and is regularly updated to continue to comply with such standards;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 issuing appropriate, clear, and regular rules and directives, whether for Douglas Stokes Furniture as a whole or a particular part of it, department, person or level of person in relation to any aspect of Douglas Stokes Furniture work, including password protocols, data access protocols, levels of persons who enjoy access to certain data sign-on procedures, password safeguarding protocols, sign-on and sign-off procedures, log-on and log-off procedures; the description of accessories, applications and equipment that will or may be used, and\/or that may not be used under any circumstances, and the like.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 evaluate any third-party services which Douglas Stokes Furniture is considering or may acquire to Process or store data, e.g., cloud computing services and ensuring that appropriate and effective operational and technological data protection procedures and standards are in place in order to address all IT security risks which may present themselves in respect of these external service providers.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>22. TRAINING<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">22.1 Douglas Stokes Furniture will conduct regular training sessions covering the contents of the data privacy laws and Douglas Stokes Furniture related Personal Information Processing policies and procedures, which will be available to all Personnel.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">22.2 Personnel must:<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 attend the scheduled and offered training;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 do all that is necessary in order to understand the data privacy laws and how they may impact on Douglas Stokes Furniture Personal Information Processing activities;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 familiarise themselves Douglas Stokes Furniture Personal Information Processing policies, procedures and prescribed forms;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">\u2022 ensure that they Process Personal Information in accordance with the Data Processing laws, this Policy, the training, the related policies and procedures and\/or any guidelines issued by Douglas Stokes Furniture from time to time.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\"><b>23. NON-COMPLIANCE<\/b><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">23.1 Compliance with this Policy and any related procedures and policies is mandatory.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">23.2 Any transgression of this Policy, and any related procedures and policies, will be investigated and may lead to action being taken against the transgressor.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol class=\"ol1\">\n<li style=\"list-style-type: none;\">\n<ol class=\"ol1\">\n<li class=\"li1\">23.3 Further information on the relevant Data protection laws, the Douglas Stokes Furniture Processing of Personal Information procedures and issues, including specific practical guidance on issues of particular relevance to Douglas Stokes Furniture staff, can be found on Douglas Stokes Furniture \u2019s website.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p class=\"p1\"><b>VERSION AND AMENDMENTS<\/b><\/p>\n<p class=\"p1\">This Policy is effective as of 1 May 2021.<\/p>\n<p class=\"p1\"><span class=\"s3\"><b>ANNEXURE A<\/b><\/span><\/p>\n<p class=\"p1\"><b>DOCUMENT CLASSIFICATION AND MANAGEMENT REGISTER FORMAT<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Author: <\/b>Your name<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Title: <\/b>Name of your project<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Duration: <\/b>Dates of project<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>1. File Structure<\/b><\/p>\n<p class=\"p1\">Describe the organization of computer folders for your project.<\/p>\n<p class=\"p1\">List the primary folders, and then summarize the organization of their sub-folders.<\/p>\n<p class=\"p1\">How will the computer folders for your project be distinguished from other projects and work that you might be involved with?<\/p>\n<p class=\"p1\"><b>Good Practice<\/b><\/p>\n<p class=\"p1\">Use a system that is logical to you, but simple and self-explanatory to others.<\/p>\n<p class=\"p1\">Avoid using the same name for sub-folders as this may lead to the over-writing of their contents.<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>2. File Names housed in folder<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Primary Folder name<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Location<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Sub Folder name<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Contents<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Sub Folder name<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Contents<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Sub Folder name<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Contents<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Signed: Version:<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Date Created:<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Date amended:<\/b><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>The record details must be extracted and inserted in the<\/b><\/p>\n<p class=\"p1\"><b>DOCUMENT CLASSIFICATION, MANAGEMENT AND RETENTION REGISTER<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>REF. NO<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>CATEGORY<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>NAME OF FILE<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>SP I<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>PI<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>CLASS<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>STATE AND DATES<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>FORMAT LOCATION<\/b><\/p>\n<p class=\"p1\"><b>SERVER \/ SYSTEM<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>DETAILS OF PERSONS WHO HAVE ACCESS<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>ARCHIVE PERIOD<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>SPECIFIC INSTRUCTI ON<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>DESTROYE D<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Dept-1<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Employees<\/p>\n<p class=\"p1\"><b>Folder<\/b><\/p>\n<p class=\"p1\">Current Employees<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Alison Lee \/ 2016<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Yes<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Yes<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Hi Confid<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Current Date<\/b><\/p>\n<p class=\"p1\">01\/02\/20<\/p>\n<p class=\"p1\">19<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Hard file<\/b><\/p>\n<p class=\"p1\">Detail location<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">7 years<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">i.e.<\/p>\n<p class=\"p1\"><b>Legal Hold<\/b><\/p>\n<p class=\"p1\"><b>Off Site Storage<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Date<\/b><\/p>\n<p class=\"p1\"><b>Manner<\/b><\/p>\n<p class=\"p1\"><b>Permission<\/b><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Electronic<\/b><\/p>\n<p class=\"p1\">Detail location<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Indefinite<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Copies<\/b><\/p>\n<p class=\"p1\">Detail where located<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Location<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Confid<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Legal hold<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">n\/a<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Not Confid<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Archive d<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">n\/a<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>Destroy ed<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>PERSON IN CHARGE<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\"><b>SIGNATURE<\/b><\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>Remark:<\/b><\/p>\n<p class=\"p1\">The records maintained by this department were reviewed on \u2026\u2026\u2026\u2026\u2026\u2026.<\/p>\n<p class=\"p3\">All records dated beyond their retention periods have to be destroyed. New record series now being filed have to be added to this schedule and those no longer being filed must have been deleted<\/p>\n<p class=\"p1\"><b>Company: Department:<\/b><\/p>\n<p class=\"p1\"><b>Valid for: Responsible person:<\/b><\/p>\n<p class=\"p3\"><b>Signed off by Information Officer:<\/b><\/p>\n<p class=\"p8\"><span class=\"s3\"><b>ANNEXURE B<\/b><\/span><\/p>\n<p class=\"p3\"><b>INCIDENT INVESTIGATION FORM<\/b><\/p>\n<p class=\"p3\">This incident report is to be used for all incidents relating to privacy and information security incident management.<\/p>\n<p class=\"p3\">Definition of an incident: A threat or event than compromises, damages, or causes a loss of confidential or protected information.<\/p>\n<p class=\"p3\">Confidential information: includes proprietary, technical, business, financial, joint-venture, customer and employee information that is not available publicly. It is the employee\u2019s responsibility to know what information is confidential and to obtain clarification when in doubt.<\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Person reporting the incident (can remain anonymous)<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Manager<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Date and time incident occurred<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Date and time incident reported<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p1\">Site\/ Region<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>INCIDENT SUMMARY (SHORT STATEMENT OF EVENT)<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>INCIDENT INVESTIGATION<\/b><\/p>\n<p class=\"p3\">The following five sections are intended to assist you to clarify the sequence of events immediately preceding the incident. They expand on the details already provided in the summary. Additional pages\/ documents can be attached when necessary.<\/p>\n<p class=\"p1\"><b>WHO WAS INVOLVED?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>WITNESSES?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>WHAT HAPPENED?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>WHEN DID THE INCIDENT OCCUR?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>WHERE DID THE INCIDENT OCCUR?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>THE EXISTENCE OR LOCATION OF ANY PROOF THAT MAY EXIST?<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\"><b>EXTENT OR CONSEQUENCES OF THE DAMAGE \/ COMPROMISE ETC<\/b><\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<tr>\n<td class=\"td1\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p3\"><b><i>Consequences of incidents: Those found in breach of this policy and any associated procedures and guidelines may result in disciplinary actions up to and including dismissal. Legal and criminal actions may also be penalties to individuals who intentionally obtain or disclose protected information without authorization.<\/i><\/b><\/p>\n<p class=\"p3\">Signature:<\/p>\n<p class=\"p1\">Date:<\/p>\n<p class=\"p1\"><b>POPIA DOCUMENTS IN SUPORT OF THE ABOVE POLICY<\/b><\/p>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">1. POPIA Compliance Framework\/Manual<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">2. Appointment of an Information Officer (IO) and Deputy Information Officer (DIO)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">3. Personal Information Impact Assessments and Data Maps where applicable<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">4. Processing Notices required under section 18<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">5. Operator Agreement<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">6. Data Transfer Agreement \u2013 cross border<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">7. Binding Corporate Rules<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">8. Opt out form<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">9. Withdrawal of consent<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">10. Objection notice<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">11. Complaint form<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">12. Update to or correction of Personal Information<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li style=\"list-style-type: none;\">\n<ul class=\"ul1\">\n<li class=\"li1\">13. PAIA Manual<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>BACKGROUND TO DATA PRIVACY IN SOUTH AFRICA The Protection of Personal Information Act, 4 of 2013, (\u201cPOPIA\u201d), which came into force on 1 July 2021, is a law which regulates the use and processing of a person and \/ legal entity\u2019s personal information, this being in response to, and in<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/comments?post=3"}],"version-history":[{"count":6,"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":3649,"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/pages\/3\/revisions\/3649"}],"wp:attachment":[{"href":"https:\/\/dsfurniture.co.za\/index.php\/wp-json\/wp\/v2\/media?parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}