POPIA Compliance Procedure
Personal Information Protection and POPIA Compliance Procedure for the ACCESS Programme, administered through Engaged Scholarship within the Division of Student Affairs at the University of the Free State.
University of the Free State
ACCESS Programme — POPIA Compliance Procedure
1. Purpose
This Procedure establishes the operational requirements for the collection, processing, storage, sharing, protection, retention and disposal of personal information processed through the ACCESS Programme of the University of the Free State (UFS).
The Procedure is intended to ensure that ACCESS personnel and other authorised persons handle personal information consistently, responsibly and lawfully.
This Procedure supports the implementation of the: Protection of Personal Information Act 4 of 2013 (POPIA); Promotion of Access to Information Act 2 of 2000 (PAIA), where applicable; Applicable UFS policies and procedures; UFS information-security requirements; Applicable research and ethics requirements; and Other relevant South African legislation.
This document should be read together with the ACCESS Privacy Statement and Personal Information Protection Policy and the ACCESS Privacy Notice and Consent Form.
2. Scope
This Procedure applies to all ACCESS activities involving personal information, regardless of whether the information is: Collected electronically; Collected in physical form; Collected directly from an individual; Received from another UFS unit; Received from a programme partner; Collected through a website; Collected through an online application; Collected through surveys or questionnaires; Collected during interviews or focus groups; Collected during community-engagement activities; Generated through programme monitoring and evaluation; or Obtained through another lawful means.
It applies to: ACCESS employees; UFS staff working on ACCESS; Student Affairs personnel; Engaged Scholarship personnel; Student volunteers; Researchers; Interns; Facilitators; Programme coordinators; Consultants; Contractors; Service providers; and Other persons authorised to access ACCESS information.
3. Governance and Accountability
ACCESS operates as a programme of the University of the Free State and is administered through Engaged Scholarship within Student Affairs.
The University remains responsible for ensuring that the processing of personal information through ACCESS is appropriately governed.
The ACCESS Programme should designate an appropriate Privacy/POPIA Coordinator or responsible programme official who serves as the operational point of contact for privacy matters.
The Programme's responsibilities include: (1) Ensuring that personal information is collected lawfully; (2) Maintaining appropriate records of processing; (3) Ensuring that personnel understand their privacy obligations; (4) Restricting access to authorised persons; (5) Maintaining appropriate security controls; (6) Monitoring third-party processing; (7) Managing privacy incidents; (8) Facilitating data-subject requests; (9) Ensuring appropriate retention and disposal; (10) Reporting significant privacy matters through the appropriate UFS structures; and (11) Supporting institutional POPIA compliance.
4. Core Privacy Principles
ACCESS personnel must apply the following principles whenever personal information is processed.
4.1 Accountability — ACCESS and responsible UFS personnel must be able to demonstrate that appropriate privacy measures are being implemented.
4.2 Processing Limitation — Only information that is reasonably required for a legitimate purpose should be collected.
4.3 Purpose Specification — Information should be collected for a specific, explicitly defined and lawful purpose.
4.4 Further Processing Limitation — Information should not subsequently be used for an incompatible purpose unless permitted by law.
4.5 Information Quality — Reasonable steps must be taken to ensure that personal information is accurate, complete and up to date where necessary.
4.6 Openness — Individuals should be informed about how their personal information is being processed.
4.7 Security Safeguards — Appropriate technical and organisational measures must be used to protect personal information.
4.8 Data-Subject Participation — Individuals must be provided with appropriate mechanisms to exercise their rights concerning their personal information.
5. Personal Information Inventory
ACCESS should maintain an internal inventory of the categories of personal information it processes. The inventory should identify, where applicable, the information category, examples, purpose, storage location, and access controls.
Categories include: Identification (Name, ID/student number — Registration — Approved UFS system — Authorised staff); Contact (Email, phone — Communication — Approved system — Programme staff); Academic (Faculty, programme, year — Programme administration — Approved system — Authorised staff); Participation (Attendance, activities — Monitoring — Programme records — ACCESS staff); Evaluation (Survey/interview responses — Impact assessment — Approved storage — Authorised staff); Media (Photographs/video — Communication/documentation — Approved storage — Authorised staff); and Sensitive information (Health/disability where necessary — Support/accessibility — Restricted storage — Specifically authorised personnel).
The inventory must be reviewed periodically and whenever ACCESS introduces a new information-processing activity.
6. Data Minimisation
ACCESS personnel must collect only information that is reasonably necessary for the stated purpose.
Before creating a new form, survey or database, the responsible official should ask: (1) Why is this information required? (2) Is the information necessary? (3) Can the purpose be achieved with less information? (4) Is the information particularly sensitive? (5) Who needs access to it? (6) How long will it need to be retained? (7) What will happen to it after the purpose has been fulfilled?
If information is not reasonably necessary, it should not be collected.
7. Personal Information Collection Procedure
Before collecting personal information, the responsible ACCESS official should follow these steps:
Step 1: Define the purpose — Clearly establish why the information is required.
Step 2: Identify the information — Specify exactly what information will be collected.
Step 3: Determine the lawful basis — Establish the applicable lawful basis for processing.
Step 4: Prepare the privacy notice — Provide individuals with appropriate information about the processing.
Step 5: Obtain consent where required — Where consent is required, obtain valid consent before processing.
Step 6: Secure the information — Ensure that the collection mechanism is appropriately protected.
Step 7: Record the processing activity — Record the activity in the ACCESS information-processing register where appropriate.
8. Consent Management
Where consent is relied upon, consent should be: Voluntary; Specific; Informed; Unambiguous where required; Documented; and Capable of being withdrawn.
ACCESS must avoid using a general consent statement to cover unrelated purposes. For example, consent to participate in an ACCESS programme should not automatically be treated as consent to: Publicly publish photographs; Use testimonials; Conduct unrelated research; Share information with unrelated third parties; or Use information for marketing.
Separate consent should be obtained where necessary.
9. Withdrawal of Consent
Where processing is based on consent, an individual may withdraw consent through the appropriate ACCESS or UFS channel.
Upon receiving a withdrawal request, the responsible official should: (1) Verify the identity of the requester; (2) Record the request; (3) Identify the processing affected; (4) Determine whether another lawful basis permits continued processing; (5) Stop consent-based processing where required; (6) Update relevant systems; (7) Notify relevant personnel where necessary; and (8) Document the action taken.
Withdrawal does not necessarily require deletion where UFS has a lawful reason to retain the information.
10. Access Control
Access to ACCESS personal information must be based on role, necessity and authorisation. Personnel should only access information required to perform their duties.
ACCESS should implement, where appropriate: Individual user accounts; Strong passwords; Multi-factor authentication; Role-based permissions; Access reviews; Secure devices; Screen-locking; Restricted physical access; and Removal of access when personnel leave or change roles.
Shared passwords or shared user accounts should not be used for systems containing personal information unless specifically authorised and appropriately secured.
11. Physical Records
Physical records containing personal information must be protected against: Unauthorised access; Theft; Loss; Damage; Unauthorised copying; and Unauthorised disclosure.
Physical records should, where appropriate, be: Stored in locked cabinets; Accessible only to authorised personnel; Removed from offices only when necessary; Returned promptly after use; and Securely destroyed when no longer required.
12. Electronic Records
Electronic personal information should be stored only on UFS-approved or appropriately authorised systems.
Personnel should not store sensitive ACCESS information on: Personal cloud accounts; Personal email accounts; Unauthorised USB devices; Unsecured messaging applications; Publicly accessible folders; or Unapproved external platforms.
Where external systems are necessary, the responsible UFS authority should assess whether the platform is appropriate before personal information is uploaded.
13. Email and Communications
When sending personal information by email, personnel should: Verify the recipient; Use the minimum information necessary; Avoid unnecessary sensitive information; Use appropriate security measures; Avoid sending information to personal email accounts where possible; and Consider secure alternatives where information is particularly sensitive.
Before sending an attachment containing personal information, personnel should verify that the recipient is authorised to receive it.
14. Cloud Storage and Online Platforms
Before ACCESS uses a cloud platform, survey platform, database, AI service, collaboration tool or other external digital system to process personal information, the responsible UFS authority should consider: The purpose of the platform; The type of information being processed; Security measures; User access controls; Data location; Cross-border processing; Retention and deletion; Third-party access; Contractual protections; and Applicable UFS requirements.
Sensitive personal information should not be uploaded to an external platform without appropriate authorisation and safeguards.
15. Third-Party Processors
Where an external organisation processes personal information on behalf of UFS/ACCESS, the responsible officials should ensure that an appropriate agreement or contractual arrangement is in place where required.
The agreement should address, where applicable: Confidentiality; Permitted processing; Security safeguards; Access controls; Incident reporting; Data retention; Data deletion; Sub-processing; Cross-border transfers; and Return or destruction of information.
Third parties should not use ACCESS personal information for their own unrelated purposes unless a lawful basis exists.
16. Data Sharing with Programme Partners
Before sharing personal information with a partner, ACCESS personnel must determine: (1) Why the information is being shared; (2) Whether the sharing is lawful; (3) Whether the recipient genuinely requires the information; (4) What minimum information is required; (5) Whether consent is required; (6) Whether a data-sharing agreement is necessary; (7) How the recipient will protect the information; and (8) How long the recipient will retain it.
Only the minimum necessary information should be shared.
17. Cross-Border Data Transfers
Where an external service provider or platform stores or processes personal information outside South Africa, the responsible official must identify this before the service is used.
The relevant UFS authority should assess compliance with POPIA's requirements concerning cross-border transfers and ensure that an appropriate lawful mechanism and safeguards are in place where required.
18. Special Personal Information
ACCESS personnel must exercise additional caution when handling: Health information; Disability information; Biometric information; Religious information; Race or ethnic information; Criminal-record information; Political information; Trade-union information; and Other categories protected under POPIA.
Such information should: Only be collected when reasonably necessary; Have a clear lawful purpose; Be accessible only to authorised personnel; Be securely stored; Not be unnecessarily copied; Not be unnecessarily disclosed; and Be securely disposed of when no longer required.
19. Children's Information
Where ACCESS activities involve children, personnel must ensure that appropriate safeguards are implemented.
Before collecting information from children, the responsible official must determine: Whether the person is a child; Whether consent from a competent person is required; What information is necessary; Whether photography or recording will occur; Who will have access; How information will be stored; and How long it will be retained.
Personnel must never casually publish identifying information concerning children.
20. Photography and Media Procedure
Where photographs, videos or audio recordings are collected, the following applies:
Before the activity — The responsible ACCESS official should determine: Why recording is necessary; How the material will be used; Whether individuals will be identifiable; Whether consent is required; Where the material will be published; Who will have access; and How long the material will be retained.
During the activity — Participants should be informed that recording is taking place where appropriate. Individuals who have not consented should not be deliberately included in identifiable promotional material where consent is required.
After the activity — Media files must be stored securely and used only for authorised purposes.
21. Research and Data Analysis
Where ACCESS data is used for research, evaluation or academic purposes, the responsible personnel must determine whether: Research ethics approval is required; Participant consent is required; Personal information can be anonymised; De-identification is appropriate; Access should be restricted; Data should be aggregated; and Additional UFS research-governance requirements apply.
Where possible, research outputs should avoid unnecessary identification of individuals.
22. Anonymisation and De-identification
Where individual identification is not necessary, ACCESS should use: Aggregated statistics; Anonymous survey responses; Unique participant codes; De-identified datasets; or Other privacy-preserving approaches.
The key linking a code to an identifiable individual should be stored separately and securely.
23. Data Accuracy
Personnel who identify inaccurate personal information should take reasonable steps to correct it.
Where an individual requests correction, the responsible official should: (1) Verify the requester's identity; (2) Locate the relevant record; (3) Assess the requested correction; (4) Update the record where appropriate; (5) Record the action; and (6) Notify relevant systems or authorised parties where necessary.
24. Data-Subject Access Requests
An individual may request access to personal information held about them.
When an ACCESS official receives such a request, they should: (1) Record the request immediately; (2) Refer it to the appropriate UFS information/privacy official; (3) Avoid making an informal commitment to disclose or refuse information; (4) Verify the identity of the requester through the appropriate process; (5) Preserve relevant records; (6) Assist with locating the information; and (7) Follow the applicable UFS and legal procedure.
Personnel should not independently delete or alter records merely because an access request has been received.
25. Correction, Deletion and Objection Requests
Requests concerning: Correction; Deletion; Objection; Withdrawal of consent; Restriction of processing; or Other privacy rights — must be referred to the appropriate UFS authority where necessary.
The request and outcome should be documented.
26. Data Breach and Security Incident Procedure
A privacy incident may include: Lost laptop containing personal information; Lost or stolen documents; Email sent to the wrong person; Unauthorised database access; Hacking; Malware; Phishing; Accidental disclosure; Unauthorised downloading; Unauthorised sharing; Compromised passwords; or Any other event that may compromise personal information.
Immediate action — Personnel who become aware of a suspected incident must: (1) Report it immediately to the designated ACCESS/UFS authority; (2) Preserve evidence; (3) Avoid deleting relevant records; (4) Change compromised credentials where instructed; (5) Disconnect compromised devices where appropriate; (6) Avoid discussing the incident publicly; and (7) Follow the UFS incident-response procedure.
The responsible authority will assess whether notification to affected individuals and/or the Information Regulator is required.
27. Privacy Incident Register
ACCESS should maintain an internal register of material privacy incidents.
The register should record, where appropriate: Date of incident; Date discovered; Nature of incident; Information affected; Number of individuals affected; Cause; Immediate containment; Risk assessment; Notifications; Corrective action; Responsible official; and Closure date.
The register must itself be securely protected.
28. Retention and Records Management
ACCESS must establish appropriate retention periods for different categories of information in accordance with applicable UFS records-management requirements and legal obligations.
A retention schedule should identify the record type, purpose, retention period, and disposal method. Categories include: Applications (Programme administration — Secure deletion); Consent records (Evidence of consent — Secure destruction); Participation records (Programme monitoring — Secure deletion); Evaluation data (Impact assessment — Secure deletion); Media files (Communication/documentation — Secure deletion); and Financial records (Compliance/audit — Secure destruction).
When personal information is no longer required, appropriate steps must be taken to securely delete, destroy, anonymise or otherwise dispose of it in accordance with UFS records-management requirements.
29. Training and Awareness
ACCESS personnel should receive appropriate training and awareness on privacy responsibilities, including this Procedure, POPIA requirements, and applicable UFS policies.
Training should be provided to new personnel during onboarding and refreshed periodically as needed.
30. Review of This Procedure
This Procedure should be reviewed periodically and whenever there are significant changes to legislation, UFS policy, ACCESS operations, or data-processing activities.
Any amendments will be subject to the appropriate UFS approval and governance processes before implementation.
31. Related Documents
This Procedure should be read together with: The ACCESS Privacy Statement and Personal Information Protection Policy; The ACCESS Privacy Notice and Consent Form; Applicable UFS Information Security Policies; The UFS Records Management Policy; Applicable UFS Research Ethics Policies; and POPIA and PAIA where applicable.
32. Contact Details
ACCESS Programme, University of the Free State — Division: Student Affairs, Unit: Engaged Scholarship, Programme: ACCESS.
Physical Address: Examination Centre, Office Door No. 27, Food Environment Office.
Email: dikotsems@ufs.ac.za
Telephone: +27 51 401 9241
UFS Information Officer — Email: dikotsems@ufs.ac.za, Telephone: +27 51 401 9241
Document Control
End of Procedure