GoTo.

Legal

Protection of Personal Information Act

The firm establishes and records at the start of every engagement whether it acts as a responsible party or as an operator, and reflects that in the contract, because the obligations differ materially.
Act
Act 4 of 2013
Information Officer
Named and registered
Established at
Start of every engagement
Recorded in
The contract
Why the role matters
A responsible party determines the purpose and means of processing. An operator processes on the instruction of a responsible party. The obligations differ materially, and getting the role wrong in a contract creates exposure for both parties. It is established and recorded before work begins, not negotiated afterwards.
01

The two roles

Where GoTo Communications determines the purpose of processing, for example enquiries submitted through this website, we act as a responsible party. Where we process personal information on a client’s documented instruction, for example administering a client’s database, running a client’s campaign platform, or indexing a client’s content into an assistant, we act as an operator.

02

Our operator obligations

Where we act as an operator we process only on documented instruction, keep the information secure using the measures described in our security standard, and notify the client immediately of any compromise. We do not use client personal information for our own purposes, and we do not retain it after the engagement closes except where a legal obligation requires it.

03

Information Officer

A named Information Officer is responsible for compliance and is registered with the Information Regulator. Contact via hello@gotocommunications.co.za, marked for the attention of the Information Officer.

04

Artificial intelligence and personal information

Client confidential material is never indexed into a system with wider access than the engagement it belongs to. Hosted commercial AI models are accessed under a recorded no-training commitment, and the tool, the provider and the data location are recorded on the supplier register. Where personal information would be processed by an assistant, that is treated as a processing activity in its own right and assessed before implementation.

05

Incidents

A data breach, loss of client information or POPIA incident escalates immediately to the Managing Director and the Information Officer. That escalation trigger is documented in the operating manual with no discretion attached to it.

06

What an institutional buyer can request

Universities, government departments and municipalities increasingly ask suppliers for evidence of POPIA compliance, and the request is not ceremonial. The following can be produced as part of any bid or due diligence process.

DocumentWhat it covers
POPIA and data protection policyBoth responsible party and operator roles, with a named Information Officer.
Supplier registerTool, provider, data location and no-training commitment for every processor used.
Incident response procedureDetection, escalation, notification and remediation, with named owners.
Records and document control standardClassification, retention schedules and disposal authority.
Operator agreement templateThe contractual terms applied where GoTo processes on client instruction.
Related
See the privacy policy for how this website itself handles personal information, and governance and compliance for the wider supplier credential set.