Hein Wagner Academy NPC · Reg. 2019/025161/08

POPIA Compliance Policy &
Incident Response Protocol

Adopted and approved: 28 August 2026 · Information Officer: Frederika Manefeldt

1.Purpose of Policy

1.1 Hein Wagner Academy NPC (“the Academy”) is an educational non-profit organization providing specialized training, skills development, and hosting facilities for visually impaired and other learners.

1.2 The Academy is committed to protecting the privacy, confidentiality, and integrity of all personal information processed in the performance of its educational and administrative functions.

1.3 This Policy implements the statutory requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”), establishing institutional standards for collecting, holding, sharing, retaining, and securely destroying personal and special personal information.


2.Scope and Designated Officers

2.1 This Policy applies to all directors, staff members, lecturers, administrative personnel, contractors, and students across all Academy operations and facilities.

2.2 Designated Institutional Officers:

Designated institutional officers
RoleOfficerContact
Information OfficerFrederika Manefeldt[email protected] | +27 (0)23 346 6800
IT ManagerPhilip Crouse[email protected]

2.3 The appointment of a Deputy Information Officer remains under active institutional consideration.


3.Definitions

In this Policy and in matters pertaining to the Processing of Personal Information generally, unless the context otherwise requires, the following expressions shall have the meanings assigned to them hereunder:

3.1
"Academy" means Hein Wagner Academy, a non-profit company incorporated in terms of the laws of the Republic of South Africa under registration number 2019/025161/08.
3.2
"AI Tool" means any software application, platform, system or service that utilises artificial intelligence to generate, analyse, translate, summarise, classify, transform or otherwise process content or information, including, but not limited to, Microsoft 365 Copilot, ChatGPT, Google Gemini and Claude.
3.3
"Child" and/or "Minor" means a natural person under the age of 18 (eighteen) years who is not legally competent to consent to the Processing of their Personal Information without the assistance of a Competent Person.
3.4
"Competent Person" means a person who is legally competent to consent to the Processing of Personal Information relating to a Child.
3.5
"Consent" means any voluntary, specific and informed expression of will in terms of which a Data Subject, or a Competent Person acting on behalf of a Child, agrees to the Processing of Personal Information relating to the Data Subject or Child, as the case may be.
3.6
"Data Subject" means the person to whom Personal Information relates, including a living natural person or an existing juristic person, and, for purposes of this Policy, includes students, prospective students, parents, guardians, employees, prospective employees, donors, service providers and other external stakeholders.
3.7
"GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council.
3.8
"Information Officer" means the person designated and registered as the Academy's Information Officer in accordance with the relevant provisions of POPIA, who is responsible for performing the duties and responsibilities prescribed by POPIA, including encouraging and ensuring compliance by the Academy with the provisions of POPIA.
3.9
"Information Regulator" means the Information Regulator established in terms of the provisions of POPIA.
3.10
"Operator" means a person who Processes Personal Information for and/or on behalf of a Responsible Party in terms of a mandate or contract, without coming under the direct authority of that Responsible Party.
3.11
"PAIA" means the Promotion of Access to Information Act 2 of 2000.
3.12
"PAIA Manual" means the manual compiled by the Academy in terms of section 51 of PAIA.
3.13
"Personal Information" means information relating to an identifiable, living natural person and, where applicable, an identifiable, existing juristic person, as defined in section 1 of POPIA.
3.14
"POPIA" means the Protection of Personal Information Act 4 of 2013, together with any regulations, codes of conduct and other subordinate legislation issued or promulgated thereunder, as amended from time to time.
3.15
"Processing" means any operation or activity, or any set of operations, whether or not performed by automatic means, concerning Personal Information, as contemplated and defined in section 1 of POPIA.
3.16
"Responsible Party" means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for Processing Personal Information. For purposes of this Policy, the Academy is the Responsible Party in respect of Personal Information that it Processes in determining the purposes and means of such Processing.
3.17
"Special Personal Information" means Personal Information referred to in section 26 of POPIA, including Personal Information concerning a Data Subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour to the extent that it relates to the alleged commission of an offence or proceedings in respect of the alleged commission of an offence.
3.18
"Personal Information Breach" means any unauthorised access to, acquisition, disclosure, loss, destruction or alteration of Personal Information, or any other incident that compromises the confidentiality, integrity or availability of Personal Information Processed by or on behalf of the Academy.

4.Interpretation Provisions & Interaction with Institutional Policies

4.1 In the interpretation of this Policy, unless the context clearly indicates a contrary intention:

4.1.1Clause headings and sub-headings are inserted for ease of reference only and shall not affect the interpretation or construction of any provision contained herein.

4.1.2Words importing the singular shall include the plural and vice versa; words importing one gender shall include the other genders; and words importing natural persons shall include juristic persons and entities.

4.1.3Any reference to a statute, regulation or statutory provision shall be construed as a reference to such statute, regulation or provision as amended, re-enacted or replaced from time to time.

4.1.4Where a number of days is prescribed, such period shall be calculated by excluding the first day and including the last day, unless the last day falls on a Saturday, Sunday or public holiday in the Republic of South Africa, in which case the last day shall be the next succeeding business day.

4.1.5The rule of construction that an agreement or policy shall be interpreted against the party responsible for its drafting or preparation (contra proferentem) shall not apply.

4.1.6This Policy shall, at all times, be interpreted and applied in a manner that promotes and is consistent with the objects, principles and requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), to the extent applicable, and any other applicable legislation, regulations, codes of conduct, regulatory requirements and recognised compliance standards relating to the protection, Processing and security of Personal Information.

4.1.7In the event of any inconsistency between any provision of this Policy and any applicable legislation, regulation, statutory requirement, regulatory directive or other binding legal requirement, the relevant legislation, regulation, statutory requirement, regulatory directive or other binding legal requirement shall prevail, and this Policy shall, to the extent reasonably possible, be interpreted and applied so as to give effect to and remain consistent with such requirement.

4.1.8Should any provision of this Policy, or any part thereof, be found to be unlawful, invalid, unenforceable or inconsistent with any applicable legislation, regulation, statutory requirement, regulatory directive or other binding legal or compliance requirement, such provision shall, to the extent reasonably possible, be read down, severed or otherwise interpreted so as to give effect to the applicable legal or compliance requirement, without affecting the validity, enforceability or continued operation of the remaining provisions of this Policy.

4.1.9No provision of this Policy shall be interpreted or applied in a manner that permits the Academy, or any person acting on its behalf, to act contrary to any applicable law, statutory requirement or binding regulatory requirement relating to the protection of Personal Information.

4.1.10This Policy shall be read together with the Academy's other applicable institutional policies, procedures, codes, standards and guidelines relating to, inter alia, information security, cybersecurity, acceptable use of technology, records management, human resources, safeguarding, student welfare and the use of artificial intelligence.

4.2 This Policy forms an integral part of the Academy's overall governance framework and must be read and considered in conjunction with other institutional policies as inter alia set out in the Acceptable Use Policy, including:

4.2.1The Acceptable Use Policy (AUP);

4.2.2The AI Tools Usage and/or AI Policy;

4.2.3The Cyber Security Programme — Authorised Training Activities Addendum (for enrolled Cyber Security students);

4.2.4The Section 51 PAIA Manual; and

4.2.5Any other policies, protocols, and procedures that form part of the governance framework regulating the day-to-day operations of the Academy, its staff members, students, and other affected parties.

4.3 Where any conflict, inconsistency or contradiction arises between the provisions of this POPIA Compliance Policy and any other institutional policy, protocol or guideline regarding matters pertaining to Personal Information, Special Personal Information or data protection, the provisions of this POPIA Compliance Policy shall prevail and supersede such other policy, protocol or guideline, unless such other provision contained elsewhere provides a better and more secure mechanism for the protection of Personal Information, in which event such other provision shall prevail.


5.Conditional Processing of Personal Information

The Academy processes personal information strictly in accordance with the eight statutory conditions under POPIA:

  1. 5.1
    Condition 1 – Accountability: Ensuring all measures giving effect to POPIA are complied with.
  2. 5.2
    Condition 2 – Processing Limitation: Processing lawfully, reasonably, and minimally without infringing on privacy.
  3. 5.3
    Condition 3 – Purpose Specification: Collecting data for explicit, defined, and lawful educational/administrative purposes.
  4. 5.4
    Condition 4 – Further Processing Limitation: Ensuring secondary processing remains compatible with the initial collection purpose.
  5. 5.5
    Condition 5 – Information Quality: Maintaining accurate, complete, and updated records.
  6. 5.6
    Condition 6 – Openness: Ensuring transparency and notifying Data Subjects of data collection.
  7. 5.7
    Condition 7 – Security Safeguards: Securing physical and digital integrity and confidentiality.
  8. 5.8
    Condition 8 – Data Subject Participation: Honoring statutory rights of access, correction, and deletion.

6.Categories of Data Subjects & Processing Specifications

6.1 Pursuant to POPIA Condition 3 (Purpose Specification), the Academy processes personal information across five primary operational categories:

6.1.1
Technical and Vocational Education and Training (“TVET”) College Students: The Academy processes names, identity numbers, contact details, medical records, academic results, and financial intake forms. This processing is necessary for contractual performance, educational administration, and compliance with partnership agreements, such as those with Boland College.
6.1.2
Cyber Security Students: The Academy processes names, identity numbers, medical records, academic files, sponsorship records, and assessment data. This processing supports educational administration and corporate sponsorship reporting requirements for sponsors such as ABSA.
6.1.3
Staff & Job Applicants: The Academy processes curriculum vitae, qualifications, identity numbers, tax numbers, payroll data, banking details, and general human resources records. This processing is conducted for employment contract performance and compliance with the Basic Conditions of Employment Act, Labour Relations Act, and tax legislation.
6.1.4
Active & Prospective Donors: The Academy processes contact details, correspondence records, payment or donation histories, and tax certificate details. This processing supports NPO governance, financial reporting, Section 18A tax receipting, and donor communications.
6.1.5
Hostel Residents: The Academy processes names, emergency contact details, room allocation records, and residential intake forms. This processing is required for residential accommodation management, safety, and health protocols across the Katie van Rensburg and Seminari hostels.

6.2 These five primary categories do not constitute a closed list, and the Academy acknowledges that the Processing of information that does not fall within any of these five defined categories may only take place for a specific and defined purpose.


7.Special Personal Information (Health & Disability Records)

7.1 Student medical files, disability assessments, and visual impairment diagnostic records are classified as Special Personal Information under Section 26 of POPIA. Processing is conducted under the explicit statutory exceptions of Section 27, based on data subject or guardian consent and the institutional obligation to secure disability benefits.

7.2 Storage and Access for TVET College Student Health Records: Digital health records for TVET College students are saved securely on the Information Officer's OneDrive. Hardcopy health records are kept in a locked cabinet in Corné du Bois's office. This information is shared exclusively with NSFAS, Boland College, and the Department of Higher Education and Training (DHET) for the processing of student disability benefits.

7.3 Storage and Access for Cyber Security Student Health Records: Digital health records for Cyber Security students are saved securely on the Information Officer's OneDrive. Hardcopy health records are kept in a locked cabinet in the Information Officer's office. This information is shared exclusively with ABSA (as corporate sponsor), ICITP, and relevant SETAs for the processing of student disability benefits and sponsorship administration.

7.4 Special personal information may not be disclosed to any third party not explicitly authorized above without prior written authorization from the Information Officer or competent person consent.


8.Retention and Secure Destruction Schedule

8.1 Pursuant to Section 14 of POPIA, personal records must be retained only for as long as necessary to fulfill operational purposes or legal obligations.

8.2 Financial & SARS Records: As the Academy was established approximately eight years ago, all historical financial records are retained. All old invoices and accounting records are securely stored in a walk-in safe.

8.3 Personnel & Donor Records: All employee human resources records and donor details are currently maintained in locked cabinets in the Information Officer's office. Employee files are retained for the duration of employment plus three years pursuant to applicable labour legislation. Donor records are retained for the duration of the active relationship plus five years for NPO auditing compliance.

8.4 Student & Alumni Records (Special Exception): Student files are managed under a specific operational exception. Due to socioeconomic circumstances, many visually impaired students do not have reliable personal storage for their original documentation, making the Academy the primary repository for copies of their matric certificates and qualifications. Alumni documents are safeguarded in a walk-in safe for permanent custody.

8.5 Destruction & De-identification Protocols: Routine disposal of individual hardcopy pages is executed on-site by tearing documents into unreadable strips. Bulk historical financial and SARS document disposal is executed through an accredited third-party shredding service. Operational digital file deletions are performed by authorized personnel, while permanent server purges and system de-identifications are managed by the IT Manager.


9.Physical and Operational Security Safeguards

9.1 Clean Desk Policy: All staff and students must comply with physical data security rules. Physical files containing personal information must be stored in locked filing cabinets or the walk-in safe when unattended. Computer screens must be locked (Windows Key + L) whenever a user steps away from a workstation.

9.2 Institutional Messaging Protocol: Staff members may only make use of a designated, official WhatsApp Business account of the Hein Wagner Academy to communicate with prospective or enrolled students, or prospective or active donors. Staff are strictly prohibited from using personal WhatsApp accounts or unapproved channels to contact individuals or collect personal information. Intake details collected via WhatsApp Business must immediately be transferred to the Academy's secure server or Microsoft 365 environment.

9.3 AI Tools & Data Protection: Staff and students may use Microsoft 365 Copilot within the secure institutional tenant. Entering personal information, health records, or employee details into public AI chatbots (such as ChatGPT, Gemini, or Claude) is strictly prohibited.

9.4 Direct Marketing Stance: The Academy does not currently send electronic newsletters or conduct direct electronic marketing campaigns. Any future direct marketing must strictly comply with Section 69 of POPIA, requiring opt-in consent for non-customers and functional unsubscribe mechanisms on all communications.


10.Incident Response Plan (Data Breach Protocol)

10.1 Pursuant to Section 22 of POPIA, the Academy enforces a five-stage protocol upon suspecting or discovering a security compromise or personal data breach:

  1. 10.1.1
    Stage 1 — Identification & EscalationAny staff member, contractor, or student who detects a lost device, unauthorized system access, phishing breach, missing physical file, or clean desk exposure must report the incident within two hours to the IT Manager ([email protected]) and Information Officer ([email protected]).
  2. 10.1.2
    Stage 2 — Immediate Containment & RemediationThe IT Manager must isolate affected network segments, revoke compromised user credentials, apply security patches, or initiate remote device wipes. Physical security breaches, such as missing keys or compromised locks, require immediate physical containment and lock replacement.
  3. 10.1.3
    Stage 3 — Risk AssessmentThe Information Officer, supported by technical and legal advisors, must evaluate the nature and scope of data exposed, assess the risk of identity fraud or financial loss to data subjects, and determine whether affected records were adequately encrypted or de-identified.
  4. 10.1.4
    Stage 4 — Mandatory Statutory Notifications (POPIA Section 22)Where reasonable grounds exist to believe personal information was accessed by an unauthorized person, the Information Officer must notify the Information Regulator in writing as soon as reasonably possible. Written notification must also be issued to affected data subjects, detailing the breach consequences, mitigation measures taken, recommended user actions, and Information Officer contact details.
  5. 10.1.5
    Stage 5 — Post-Incident Governance & ReportingThe Information Officer must record the incident in the Academy POPIA Register, conduct a forensic root-cause analysis, and strengthen security controls to prevent recurrence.

10.2 The Academy's POPIA Register may be maintained either electronically or in hardcopy format. Any incident or suspected breach recorded therein in accordance with clause 10.1.5 (Step 5) above shall reflect the date on which the incident occurred and/or the suspected breach was reported or discovered, the identity of the person by whom it was reported or discovered, and the manner in which the Academy addressed and dealt with the incident in accordance with the five-step process set out hereinabove.


11.Data Subject Rights and PAIA Interface

11.1 Data subjects retain statutory rights to request access to, correction of, or deletion of their personal information maintained by the Academy under Section 23 and Section 24 of POPIA.

11.2 Access requests must be submitted using Form 2 of the POPIA Regulations to the Information Officer. Requests regarding official institutional records are processed in alignment with the Academy's PAIA Manual.


12.International Data Transfers, GDPR Alignment & Compliance

12.1 General Data Protection Regulation (GDPR) Overview: The General Data Protection Regulation (EU) 2016/679 (“GDPR”) is the comprehensive data privacy and protection regulation of the European Union. It regulates the processing of personal data relating to individuals (“data subjects”) within the European Economic Area (EEA), as well as the extraterritorial transfer and processing of EU residents' personal data by entities operating outside the EU. The GDPR mandates strict principles regarding lawful processing, data minimization, transparency, data subject rights, security safeguards, and legal mechanisms for cross-border data transfers.

12.2 Alignment Between POPIA and the GDPR: Although the Academy operates primarily within South Africa under POPIA, its processing operations and data protection standards align directly with the provisions and core principles of the GDPR for the following legal and structural reasons:

12.2.1Harmonised Core Processing Principles: POPIA was benchmarked directly against international privacy frameworks, including the GDPR. The eight statutory conditions for lawful processing under Section 4 of POPIA (such as Accountability, Purpose Specification, Information Quality, and Security Safeguards) mirror the core principles set out in Article 5 of the GDPR.

12.2.2Protection of Data Subject Rights: Both frameworks guarantee fundamental privacy rights, including the right to access personal data, request correction or erasure, object to unauthorized processing, and be notified in the event of a security compromise or data breach (POPIA Section 22; GDPR Articles 33–34).

12.2.3Cross-Border Transfer Protections: Pursuant to Section 72 of POPIA, personal information may only be transferred to a third party in a foreign country if the recipient is subject to a law or binding agreement that provides an adequate level of protection substantially similar to POPIA. The GDPR is internationally recognized as meeting and exceeding these adequacy standards. Consequently, processing activities involving international donors, foreign educational partners, or global cloud service infrastructure (such as Microsoft 365) naturally satisfy both POPIA Section 72 requirements and GDPR cross-border transfer mechanisms.

12.2.4Institutional Governance: By maintaining full compliance with POPIA, the Academy ensures operational readiness and legal alignment with GDPR expectations when interacting with European donors, international grant funding bodies, and global corporate sponsors.


13.Policy Review

13.1 This POPIA Compliance Policy and Incident Response Plan shall be formally reviewed at least annually by the Information Officer and IT Manager.

13.2 Interim reviews shall be conducted immediately upon:

13.2.1Material legislative or regulatory modifications to POPIA, PAIA, or related privacy legislation;

13.2.2Findings, recommendations, or vulnerabilities identified during a data breach or security incident; or

13.2.3Material operational changes in processing activities or IT infrastructure.


14.Amendment

14.1 Notwithstanding any institutional governance process or any provision to the contrary contained in this Policy or any other institutional policy, the Information Officer shall have delegated authority and exclusive operational responsibility for reviewing, updating, amending and formally approving this Policy at least annually, or alternatively, as and when the need arises.

14.2 Any proposed amendment shall undergo a formal compliance review by the Information Officer, in consultation with technical and/or legal advisers where necessary, and shall take effect upon the Information Officer's formal approval and sign-off, without requiring prior submission to, or ratification by, the Board of Directors.

14.3 Following any material amendment approved by the Information Officer pursuant to this Policy, a copy of the revised Policy shall be tabled before the Chief Executive Officer and the Board of Directors at their next scheduled meeting for noting and alignment with the Academy's broader operational governance framework.

14.4 Amendments to this Policy may be initiated by the Information Officer as operational, technical, legislative or regulatory requirements dictate and shall not be subject to unnecessarily rigid committee procedures, formal institutional notices or third-party advisory involvement, unless such procedures, notices or involvement are required by applicable law or considered necessary by the Information Officer in the circumstances.

14.5 The Information Officer retains exclusive operational authority to adjust, update, amend or rewrite any provision of this Policy ex officio, provided that any material amendment is documented in writing and brought to the attention of all affected parties as soon as reasonably practicable thereafter.


15.Adoption of Policy

15.1 This Policy is formally adopted and shall come into effect upon signature by the Information Officer, subject to the requirement that the Policy be brought to the attention of all affected parties as soon as reasonably practicable thereafter.

15.2 Notwithstanding the date on which this Policy is formally adopted and signed, it is acknowledged and recorded that the Academy has at all relevant times recognised and remained aware of its statutory obligations under POPIA since the commencement of the Act and has, prior to the formal adoption of this written Policy, taken reasonable, practical and good-faith measures aimed at ensuring compliance with its obligations under POPIA.

15.3 The Academy's compliance history shall accordingly be considered in the context of the measures and controls implemented by it prior to the formal adoption of this written Policy, including the registration of the Academy's Information Officer with the Information Regulator on a date preceding the signature and formal adoption of this Policy.


16.Training

16.1 Institutional training on this Policy and general POPIA awareness shall, as far as reasonably practicable, be conducted in a practical and accessible manner on an ongoing basis. Such training may be integrated into general staff meetings, student orientation sessions, onboarding processes and other appropriate institutional activities, and may be supplemented by concise digital briefings or other appropriate awareness materials.

16.2 Newly appointed staff members and newly enrolled students shall receive an appropriate POPIA briefing and/or a copy of this Policy as part of the Academy's standard onboarding or administrative intake processes. Alternatively, they shall be informed that a copy of this Policy is available on the Academy's designated digital storage platforms, thereby enabling them to familiarise themselves with its contents and the obligations applicable to them.


17.Execution and Sign-Off

Adopted and approved at WORCESTER on 28 August 2026.

FREDERIKA MANEFELDT

Information Officer

Hein Wagner Academy NPC

Registration No. 2019/025161/08

$/$