POPIA Data Protection Policy

Purpose

  1. This policy says how Sparrows meets its duties under the Protection of Personal Information Act, 2013 (POPIA). It covers all the personal information that Sparrows processes.
  2. Processing means anything done with the information. It includes collecting, storing, using, sharing and deleting it.

Sparrows as a Responsible Party

  1. Under POPIA, Sparrows is a "responsible party". This is because Sparrows decides why and how the information it holds is processed. It covers donor records, information about staff, volunteers and Board members, and any other personal information Sparrows holds.
  2. This policy applies wherever the information is kept. That means paper files, spreadsheets, email and any system Sparrows uses.

The Conditions for Lawful Processing

  1. Sparrows follows the eight conditions that POPIA sets for lawful processing:
    1. Accountability — Sparrows makes sure the conditions in this policy are met at all times.
    2. Processing limitation — information is processed lawfully. Only as much is used as the purpose needs. The basis may be consent, a legal duty, a contract or Sparrows' legitimate interest. Sparrows names that basis before processing starts.
    3. Purpose specification — information is collected for a clear and lawful purpose. It is not kept longer than that purpose needs (see the Records and Retention Policy).
    4. Further processing limitation — information is not used for a new purpose that does not match why it was collected.
    5. Information quality — Sparrows tries to keep the information it holds complete, correct and up to date.
    6. Openness — a data subject is the person the information is about. They are told what is collected from them and why, unless POPIA makes an exception (see §3.3).
    7. Security safeguards — Sparrows takes reasonable steps to protect information from loss, damage and misuse. It also protects it from being destroyed or opened without permission.
    8. Data subject participation — a data subject may ask what information Sparrows holds about them. They may ask for it to be corrected or deleted. POPIA has some exceptions (§7 says how a request is handled).
  2. Staff and volunteer payroll information is used to carry out the person's contract or volunteer arrangement, to meet a legal duty, and for Sparrows' legitimate interest (§3.1.2). Sparrows does not ask the person each time before it shares it with these recipients. The Department of Social Development gets it, as the financial reporting rules of the Transfer Payment Agreement require. So does Sparrows' external auditor, for the annual audit. So do the South African Revenue Service (SARS) and any other body the law names, and whoever processes payroll and bank payments for Sparrows. Anyone else gets payroll information only with the person's express permission, as Financial Policy §10.9 says.
  3. When Sparrows collects personal information, it takes reasonable steps to make sure the person knows:
    1. what information is being collected, and its source if not the person;
    2. who Sparrows is, and its address;
    3. why the information is collected;
    4. whether giving it is voluntary or compulsory, and what happens if the person does not give it;
    5. any law that requires the information to be collected;
    6. whether Sparrows plans to send it to another country, and how well it will be protected there;
    7. who will receive it, and what kind of information it is; and
    8. their right to see it, correct it and object to its use, their right to complain to the Information Regulator, and how to reach the Regulator.

Special Protection for Children's Personal Information

  1. POPIA protects a child's personal information more strictly than other personal information. Sections 34 and 35 bar processing it unless one of five grounds applies:
    1. a competent person for the child has agreed in advance (§4.4);
    2. it is necessary for a right or a duty in law;
    3. it is needed to meet a duty under international public law;
    4. it is for history, statistics or research. It must serve the public interest and be necessary, or asking for consent must be impossible or take too much effort. In either case the child's privacy must be properly protected; or
    5. the child has made the information public on purpose, with a competent person's consent.
  2. A child's information has no ground like the general "legitimate interest" ground in §3.1.2. Almost everything Sparrows does with a child's information in ordinary care is lawful under §4.1.2. That includes a daily record, an incident report, a court report and a handover between staff. It is necessary for Sparrows' legal duty under the Children's Act to care for, supervise, protect and report on a child in its care. A use that does not serve that duty needs its own ground under §4.1, usually the consent of a competent person. It is not lawful just because the child is in Sparrows' care.
  3. A photograph or a video of a child is personal information if the child can be identified from it, even when no name is given. This policy applies to it in full (§10 and §11 show how this works in practice). Sharing a child's information is a normal part of the work. Staff pass it on at handover, in case discussions, to the Social Worker and to the child's school. §4.1.2 covers this where it serves the child's care. It does not cover telling a person who has no part in that care, whoever they are.
  4. A child's "competent person" gives the consent in §4.1.1. This is usually a parent or legal guardian. Sparrows cares for a child under a placement made through the Children's Act. That makes Sparrows a care-giver, not a guardian. It does not pass a parent's or guardian's authority to Sparrows. A parent may keep full guardianship, share it, or have it limited or removed. This differs from child to child, and it can change while the child's case is in court. The Social Worker holds each child's case file and confirms who may consent for that child. A decision that depends on this goes to the Social Worker. Nobody else decides it.
  5. A request from outside the ordinary course of a child's care goes to the Social Worker or the Executive Director for a decision on consent before it goes ahead. This covers a request to photograph or record a specific child, or to use information about the child. It may come from a visitor, for a donor communication, from a school or from anyone else. No other member of staff decides it on the spot.
  6. Information about a child that staff give a staff AI assistant (AI Usage Policy §6) is recorded under §4.1.2, and only as far as the child's care, supervision, protection or reporting needs it. It is recorded under the child's first name only, without any detail barred by AI Usage Policy §6.4. It is not used to train or tune an AI tool, and it is not used to answer another person's questions.

Operators and Third-Party Processors

  1. An "operator" is an outside party that stores or processes information for Sparrows, but is not under Sparrows' direct control. A cloud storage service is an example.
  2. Sparrows uses an operator only under a written contract. The contract makes the operator keep the same security standard as this policy requires of Sparrows. It also makes the operator tell Sparrows at once of any real or suspected security breach.
  3. The Executive Director decides whether to use an operator, and agrees the contract. A staff member does not set up outside storage for Sparrows' records on their own, for example with a personal cloud account or a free app. That would create an operator with no contract, which this policy does not allow.
  4. Sparrows keeps an Operator Register. It records each operator used under §5.2, and whether a written contract or data processing agreement is in place. For an operator outside South Africa, it also records which ground in §14.1 the transfer relies on.
  5. The provider of an AI tool, and a messaging service that carries staff messages to one, are operators under this heading. Each is entered in the Operator Register before it handles any personal information. If it is outside South Africa, the entry records the ground relied on under §14.1.
  6. The contract with an operator is made in Sparrows' name, not in the name of a person who signs up for the service.

Responsibility for Compliance

  1. The Executive Director makes sure Sparrows follows this policy and POPIA. This is the Executive Director's job because they run the organisation.
  2. The Executive Director is Sparrows' Information Officer. POPIA gives this job to the head of a private body, unless someone else is formally named.
  3. The Information Officer must be registered with the Information Regulator before they start the job (POPIA section 55(2)). The registration names the person, not only the role. When the Executive Director changes, Sparrows updates it. The Regulator's record then always names the person who holds the role.
  4. POPIA's civil claims and administrative fines are made against Sparrows, as the responsible party, and not against an individual member of staff. This does not lessen what is expected of staff. A breach caused by not following this policy is still one Sparrows must answer for, and it is dealt with under the Disciplinary Code and Procedure. A person can also commit an offence under POPIA, for example by obstructing the Information Regulator.

Data Subject Requests

  1. A request by a data subject to confirm what personal information Sparrows holds about them, or to correct or delete it, goes to the Executive Director as Information Officer. The Executive Director first confirms who the requester is and that they are entitled to ask. POPIA's own exceptions to this right still apply.
  2. Where the data subject is a child, the request is made by the child's competent person, confirmed under §4.4.
  3. Sparrows replies to a request in writing within 30 days of receiving it.
  4. The reply says what Sparrows has done. When Sparrows gives a person their information, it also tells them they may ask for it to be corrected. Every reply tells the person they may complain to the Information Regulator if they are unhappy.
  5. Confirming whether Sparrows holds a person's information is free. If Sparrows charges a fee for a copy, it gives a written estimate first.

Data Breach Response

  1. Sparrows may have good reason to believe that someone without permission has got into information it holds. The Executive Director then:
    1. finds out how far the breach goes, as soon as reasonably possible;
    2. takes immediate steps to contain it and stop further loss;
    3. tells the Information Regulator as soon as reasonably possible, in the form POPIA asks for; and
    4. tells each affected person as soon as reasonably possible, unless it is not possible to find out who they are.
  2. The Board is told of any data breach at its next meeting, or sooner if the breach is serious.
  3. Sparrows may delay telling the affected people only if the police, or another public body that investigates crime, says it would harm the investigation. The Information Regulator may say the same.
  4. The notice to an affected person is in writing. It is sent in at least one of the ways POPIA allows: by post to their last known address, by email to their last known address, in a prominent notice on Sparrows' website, in the news media, or as the Information Regulator directs.
  5. A staff member who sees a possible security problem reports it as the IT Security and Acceptable Use Policy §8 says.

Relationship to Other Governing Documents

  1. This policy governs how Sparrows processes personal information once it holds it. A separate right lets anyone ask for access to a record Sparrows holds, whether or not it is about them. The PAIA / Access to Information Policy governs that right, not this one. Sparrows' website privacy notice summarises both policies for visitors and donors in plain language. It is a summary, not a separate source of rights.

CCTV and Surveillance Footage

  1. Sparrows has CCTV cameras on its property and in shared indoor areas, such as passages and communal spaces. They protect the children in its care, including from harm by another person in the house. They also protect staff, volunteers, visitors and the property. The Department of Social Development's district office told Sparrows to install security cameras in October 2025. Footage of a person is personal information, and the conditions in §3 apply to it in full.
  2. For footage of adults, the lawful basis is Sparrows' legitimate interest. That interest is the safety of the children in its care, staff, volunteers and visitors, and the security of its property. A person who enters is not asked to consent. Consent does not work for ordinary security cameras on a property where people are told on entry that cameras are in use.
  3. CCTV footage is kept for up to one year from the recording. It is then securely deleted or recorded over. This follows §3.1.3 and the Records and Retention Policy. Footage linked to an open incident, investigation, disciplinary matter, dispute or police request is kept until that matter is closed, even after the year has passed.
  4. Only these people may view CCTV footage: the Executive Director, the Board Chairperson, the Social Worker, and a Department of Social Development official acting in their official capacity. The Executive Director may allow any other person to view specific footage for a stated purpose. Examples are a staff member who reviews an incident, or the police who investigate a crime. The cameras watch children, and the footage can show them. Footage is not open to casual viewing.
  5. Cameras are never put in a bedroom or bathroom, or anywhere else a child would expect privacy. Recordings are stored on the recorder on Sparrows' own premises.
  6. Footage of a child is the child's personal information. Sparrows processes it under §4.1.2, because it is necessary for Sparrows' legal duty to protect the children in its care (§4.2). The legitimate interest in §10.2 applies only to footage of adults.
  7. When the Executive Director lets someone view footage under §10.4, the Executive Director writes down who viewed it, which footage, why, and when.
  8. The Executive Director may view footage remotely, on a phone, through the app of the recorder's maker. That connection runs through the maker's cloud service. The service is an operator under §5, and its servers may be outside South Africa, so heading 14 applies. It is entered in the Operator Register. Remote viewing follows these rules:
    1. the remote-viewing account is held in Sparrows' name (§5.6), not a personal one;
    2. the phone has a screen lock, and the account is not shared with anyone else; and
    3. footage is not saved to the phone or screen-recorded (§3.1.7).

Visitors and Other Third Parties

  1. A visitor does not photograph, film or otherwise record a child, under any circumstances. An image or recording of a child is personal information. One taken by a visitor falls outside the consent and limits in the Media and Photography Consent Policy. That policy governs Sparrows publishing an image with consent. This clause governs a visitor taking one at all.
  2. What a visitor sees or hears at Sparrows stays private. A visitor does not discuss a specific child, their circumstances, or anything seen during a visit outside Sparrows, including on social media. A visitor's casual observation of a child is still personal information about that child. The conditions in §3 apply to it in substance, even though a visitor is not a Sparrows employee.

Direct Marketing

  1. Sparrows sends newsletters, appeals and updates to donors and supporters by email, SMS or similar. Section 69 of POPIA applies. Sparrows sends them without separate opt-in consent only to an existing donor or supporter. The message must be about Sparrows' own similar activities. The person must have been offered a clear way to opt out when their details were first collected, and in every message since.
  2. Sparrows keeps a Direct-Marketing Register. For each donor or supporter contacted electronically, it records whether they have opted out, and the date. A person who opts out is not contacted again by that channel.
  3. If a communication goes to someone who is not yet an existing donor or supporter, Sparrows gets their consent first. The existing-relationship rule in §12.1 does not apply to them.

Special Personal Information

  1. POPIA treats some information as "special". It bars processing it unless a specific ground applies (sections 26 and 27). Special information covers religion or beliefs, race or ethnic origin, trade union membership, political views, health, sex life and biometric information. It also covers an alleged crime, and court cases about one.
  2. Sparrows processes special personal information only where POPIA allows it, and only as far as it needs to. Where no other ground applies, it needs the consent of the person the information is about.
  3. Information about a child's health is processed because Sparrows' care of the child needs it (POPIA section 32(1)(d)). That section lets a body that manages the care of a child process it where necessary for its lawful duties. This includes medical, medication and menstruation records. A child's information is also processed on the ground in §4.1.2.
  4. Sparrows requires every employee, volunteer and Board member to be cleared before they have contact with a child. Safe Recruitment Policy §5 and Fit and Proper Person Standard §5.1 set out the checks. Sparrows keeps each person's clearance certificates and register results on their file. It may hold them because the law requires the checks and because Sparrows obtained the information lawfully. The laws are the Children's Act (section 126), the Criminal Law (Sexual Offences and Related Matters) Amendment Act (section 45) and regulation 84 of the General Regulations. POPIA sections 27(1)(b) and 33 allow the processing.
  5. A staff member's sick note or other health information is used only to apply the law on rights that depend on health, such as sick leave (POPIA section 32(1)(f)).

Cross-Border Transfer of Personal Information

  1. Information is not sent to a third party in another country unless one of the five grounds in section 72 of POPIA applies:
    1. the recipient is bound by a law, company rules or an agreement that gives about the same protection as this policy, and the same applies if the recipient passes it on;
    2. the data subject consents to the transfer;
    3. the transfer is needed to carry out a contract with the data subject, or a step the data subject asked for before a contract;
    4. the transfer is necessary to make or carry out a contract with a third party that is in the data subject's own interest; or
    5. the transfer is for the data subject's benefit, asking for consent is not practical, and they would probably agree if asked.
  2. This applies to any operator under §5 whose own infrastructure is outside South Africa, including a hosting provider for Sparrows' own systems and records, not only a service that is obviously foreign by name. The Executive Director records in the Operator Register which ground in §14.1 applies, and the evidence for it, as part of the written contract §5.2 requires. Where the evidence is not yet in place, the register says so, and the Executive Director closes the gap.
  3. Giving Sparrows' information to an AI tool that stores or processes it outside South Africa is a transfer under this heading in the same way. The test in AI Usage Policy §4.1 and the grounds in this heading are applied together to that disclosure. They are not two separate approvals for the same thing.

Review

  1. This policy is reviewed annually by the Board.