Privacy, in practice
Our POPIA approach
Better document collection includes being clear about responsibility.
Software supports good practice. It does not replace it.
The Protection of Personal Information Act, 2013 (POPIA) sets conditions for processing personal information in South Africa. Using GetDocs does not automatically make an organisation's collection lawful. We do not describe GetDocs as “POPIA certified” or “POPIA approved”.
Who does what?
The requesting organisation normally determines the purpose of collection and acts as the responsible party. It must choose an appropriate lawful basis, explain the request, collect only necessary information, authorise its team and determine justified retention. A template is only a starting point, not a legally complete checklist.
The GetDocs service provider normally acts as an operator for customer documents and must work within the agreed processing instructions and safeguards. Its role for its own account and operational information may differ. These roles and a written operator agreement must be reviewed for the actual service.
How the collection workflow helps
- Specific checklist items help a business ask for what it needs rather than an open-ended collection of files.
- Organisation-scoped access and private file storage separate business records.
- Expiring request links allow account-free access to a specific request. A live link is an access credential and must not be shared publicly.
- Review decisions and replacement history help explain what changed and why.
These are application controls, not a guarantee against unauthorised access. Production safeguards also depend on hosting, configuration, team practices, monitoring and independent security testing.
Medical certificates, children’s information and other sensitive documents
Medical fitness certificates may contain health information, which POPIA treats as special personal information. Children’s personal information is also subject to additional restrictions. An industry example on our landing page is not authorisation to collect these documents.
Before these uses, complete a separate legal and security review: establish the applicable lawful justification and authorisation requirements, minimise what is requested, restrict access, and agree appropriate retention, deletion and incident procedures. Do not assume that a generic consent checkbox is sufficient. GetDocs is a document collection tool, not a medical-records platform.
Consult the Information Regulator’s guidance on special personal information and children’s information and obtain advice for your actual use case. Passports, IDs, photos and financial records also require lawful, limited and secure handling.
Before production use
The launch review must confirm the following for the actual service operator and deployment:
- A final privacy notice, service terms, operator agreement and any applicable PAIA manual.
- Information Officer responsibilities, required registration and working privacy, support and incident contacts.
- A verified subprocessor list, hosting locations and assessment of any international transfers.
- Working security controls, including production file scanning, protected transport, access testing and monitoring.
- Documented retention, deletion and backup schedules, with a tested restoration process.
- A practical process for access, correction, objection, deletion and security-incident handling.
Read the privacy notice for the currently disclosed operator details. Missing details must not be treated as an assurance that a requirement has been met.
If personal information may be exposed
Escalate a suspected incident promptly, limit further sharing and preserve relevant evidence securely. An operator must inform the responsible party immediately when the statutory notification trigger is met. The responsible party handles required notifications to the Regulator and affected people, subject to the Act. Do not wait for a routine support reply to begin an organisation's incident process.
The Regulator's security-compromise guidance explains responsibilities and the current reporting process. Use our safe reporting guidance to avoid disclosing more information in a report.
Need to exercise a privacy right?
Start with the organisation that requested your documents, or the GetDocs privacy contact for service-provider matters. The privacy notice explains the contact route. The Information Regulator also publishes POPIA forms and complaint guidance.