Legal
Protection of Personal Information Act
- Act
- Act 4 of 2013
- Information Officer
- Named and registered
- Established at
- Start of every engagement
- Recorded in
- The contract
The two roles
Where GoTo Communications determines the purpose of processing, for example enquiries submitted through this website, we act as a responsible party. Where we process personal information on a client’s documented instruction, for example administering a client’s database, running a client’s campaign platform, or indexing a client’s content into an assistant, we act as an operator.
Our operator obligations
Where we act as an operator we process only on documented instruction, keep the information secure using the measures described in our security standard, and notify the client immediately of any compromise. We do not use client personal information for our own purposes, and we do not retain it after the engagement closes except where a legal obligation requires it.
Information Officer
A named Information Officer is responsible for compliance and is registered with the Information Regulator. Contact via hello@gotocommunications.co.za, marked for the attention of the Information Officer.
Artificial intelligence and personal information
Client confidential material is never indexed into a system with wider access than the engagement it belongs to. Hosted commercial AI models are accessed under a recorded no-training commitment, and the tool, the provider and the data location are recorded on the supplier register. Where personal information would be processed by an assistant, that is treated as a processing activity in its own right and assessed before implementation.
Incidents
A data breach, loss of client information or POPIA incident escalates immediately to the Managing Director and the Information Officer. That escalation trigger is documented in the operating manual with no discretion attached to it.
What an institutional buyer can request
Universities, government departments and municipalities increasingly ask suppliers for evidence of POPIA compliance, and the request is not ceremonial. The following can be produced as part of any bid or due diligence process.
| Document | What it covers |
|---|---|
| POPIA and data protection policy | Both responsible party and operator roles, with a named Information Officer. |
| Supplier register | Tool, provider, data location and no-training commitment for every processor used. |
| Incident response procedure | Detection, escalation, notification and remediation, with named owners. |
| Records and document control standard | Classification, retention schedules and disposal authority. |
| Operator agreement template | The contractual terms applied where GoTo processes on client instruction. |