top of page

Frequently Asked Questions
Legal FAQ's
You can, but biometrics are special personal information and attract heightened protection. Conduct a PIIA first, document why a less intrusive method will not do, and offer an alternative where reasonable.
Both
We are the Operator regarding the data captured by ATG devices at the sites of our customers
We are the Responsible Party regarding the data we collect through our normal business operations (Customer, Supplier, Staff)
Yes we are, as both an Operator and a Responsible Party
Yes, as an Operator regarding the data we collect on behalf of customers
Yes we do, and this IO will also need to be registered with the Regulator
Yes, in order to show how we intend to handle requests for information
Yes we do
Scanned Data from Customer Sites
Customer Data (Names, Reg Numbers, Banking Details, Contact Details)
Supplier Data (Names, Reg Numbers, Banking Details, Contact Details)
Staff Data (Names, ID Numbers, Bank Details, Special Personal Information, Contact Details)
Yes
Yes
Yes
Only for the information we gather as the Responsible Party
For the information we collect as an Operator, our customer will determine the Retention Periods.
Only as long as necessary for the purpose. For routine visitor registers that is typically a matter of weeks rather than years, set a defined period, justify anything longer, and enforce deletion.
Be very careful. Information collected for access control may not be casually repurposed or circulated. Sharing footage of an individual in a community WhatsApp group, for example, is a common and serious misstep. Share only where there is a lawful basis and a genuine need.
Yes. Data subjects have the right to access their personal information, subject to verification of their identity and the limited grounds for refusal set out in POPIA. Have a documented process and a designated contact person so you can respond within the required timeframes.
The Information Regulator, on the prescribed form, and the affected data subjects, as soon as reasonably possible after you have reasonable grounds to believe a compromise occurred. Decide in advance who will assess, draft and approve the notifications.
No. Sharing for the prevention, detection or investigation of an offence is contemplated by the Act. Record what you shared, with whom and why, and share only what is relevant to the request.
The obligations apply regardless of size, but the response should be proportionate. A small complex needs the same building blocks, an Information Officer, a data map, a notice, retention, operator agreements, just at a scale that fits. Smaller does not mean exempt, it means simpler.
bottom of page
