Technical & organisational safeguards

Information Security & IT Policy

The controls K Gcolotela & Peter Incorporated applies to protect the confidentiality, integrity and availability of client, personal and business information — and how we demonstrate ongoing compliance to our clients and partners.

Last updated: 16 September 2026 Version 2.0 Next review: September 2027

1. Purpose and scope

This Policy sets out the minimum information security and information technology standards that apply at K Gcolotela & Peter Incorporated ("the Firm"). Its purpose is to protect the confidentiality, integrity and availability of all information entrusted to us — in particular personal information and confidential client information — and to give effect to the security safeguards required by section 19 of the Protection of Personal Information Act 4 of 2013 ("POPIA").

This Policy applies to:

  • all directors, attorneys, candidate attorneys, conveyancing and litigation secretaries, administrative and support staff, whether permanent, temporary or part-time;
  • all contractors, subcontractors, consultants, correspondents and service providers (operators) who access, store or process information on the Firm's behalf; and
  • all information assets, including paper files, electronic files, email, practice-management and accounting systems, devices, networks, cloud services and removable media, at every office of the Firm and when working remotely.

Information received from clients — including personal information of a client's customers, employees, debtors or account holders shared with us for the purposes of a mandate — is treated as Restricted information and is subject to the strictest controls in this Policy as well as any additional requirements set out in the client's contract or supplier code of conduct.

2. Governance and responsibilities

RoleResponsibilities
Board of DirectorsApproves this Policy, provides resources for its implementation, and retains ultimate accountability for information security and POPIA compliance.
Information Officer
Khanyiswa Gcolotela, Managing Director
Owns this Policy and the Privacy Policy; ensures compliance with POPIA and PAIA; liaises with the Information Regulator; approves risk decisions; signs off on breach notifications.
Deputy Information Officer
Yolanda Sineke, Office Manager
Day-to-day administration of the compliance programme: maintains the registers in section 16, coordinates training, receives and logs incident reports, handles data-subject and client requests, and prepares compliance evidence for clients and auditors.
IT Service ProviderImplements and maintains the technical controls (endpoint protection, patching, backups, email security, access management, monitoring) under a written service agreement and operator agreement; reports security events to the Deputy Information Officer.
Heads of Department / Supervising AttorneysEnsure that staff in their teams comply with this Policy, approve access requests, and confirm that client-specific security requirements are applied on their matters.
All staff, contractors and subcontractorsComply with this Policy, complete required training, protect the information they handle, and report incidents immediately.

3. Compliance framework

This Policy is designed to ensure compliance with, and is reviewed against, the following:

  • Protection of Personal Information Act 4 of 2013 (POPIA) and its Regulations, including the Information Regulator's guidance;
  • Promotion of Access to Information Act 2 of 2000 (PAIA);
  • Cybercrimes Act 19 of 2020;
  • Electronic Communications and Transactions Act 25 of 2002;
  • Financial Intelligence Centre Act 38 of 2001 (record-keeping and confidentiality of client identification records);
  • Legal Practice Act 28 of 2014 and the Rules and Code of Conduct of the Legal Practice Council, including the duty of confidentiality and attorney-client privilege;
  • contractual data protection and information security obligations owed to our clients, including supplier codes of conduct and service level agreements of financial-services clients; and
  • recognised good-practice frameworks (ISO/IEC 27001 and 27002 controls) as a reference for the design of our controls.

4. Our commitments as a supplier and partner

Many of our clients — including regulated financial institutions — require their suppliers to demonstrate specific POPIA and information security practices. The table below summarises how the Firm meets each of these expectations and the evidence we can provide on request.

Client expectationHow the Firm compliesEvidence available
Compliance with all applicable POPIA requirements and related data protection legislation Designated and registered Information Officer and Deputy; published Privacy Policy; this Policy; PAIA manual; processing register; annual compliance review. §3, §16, §17 Information Officer registration; policy set; processing register; review minutes
Personal information processed only for authorised business purposes and in accordance with contractual obligations Purpose is recorded per matter at file opening; client information is used solely for the instructed mandate; further use requires client authorisation; client-specific security terms are recorded on the matter. §5, §8 Matter opening checklist; client mandate; processing register
Prompt reporting of any actual or suspected data breach, privacy incident or unauthorised disclosure involving client information Mandatory immediate internal reporting; affected clients notified without undue delay and in any event within 24 hours of confirmation (or any shorter period stipulated by contract); Information Regulator and data subjects notified per section 22 of POPIA. §15 Incident response procedure; incident register; notification templates
Employees, contractors and subcontractors handling personal information receive privacy and security awareness training Induction training before access to client information is granted; annual refresher for all staff; contractors and subcontractors complete the same training or provide equivalent proof; periodic phishing awareness exercises. §14 Training register; attendance records; training material
Documents containing personal information password-protected before transmission via email Mandatory rule: every attachment containing personal information is password-protected or encrypted before sending, and the password is shared through a separate channel (SMS, telephone or separate message). Secure file-sharing links used for large or highly sensitive files. §7 Email standard; staff acknowledgement; spot-check records
Only the minimum necessary information shared for the specific purpose Need-to-know access; staff instructed to request, attach and disclose only what the matter requires; irrelevant personal information redacted; no personal information in email subject lines; distribution lists checked before sending. §6, §8 Access matrix; redaction guidance; access review records
Regular review of processes to ensure adherence to data protection laws and contractual obligations Policies reviewed at least annually and after any incident, legal change or new client requirement; quarterly access reviews; annual internal compliance assessment; management review of results. §17 Review schedule; assessment reports; version history
Adequate records and controls demonstrating ongoing compliance with POPIA Registers of processing activities, information assets, operators, access rights, training, incidents, data-subject requests and policy acknowledgements are maintained by the Deputy Information Officer and made available to clients and auditors on request. §16 Compliance registers; audit trail; operator agreements

5. Information classification and handling

All information is classified and handled according to its sensitivity:

ClassDescriptionHandling requirements
PublicInformation intended for publication (website content, marketing material, published articles).No restrictions, subject to approval before publication.
InternalOperational information not intended for the public (internal procedures, templates, staff directories).Available to staff only; not to be shared externally without approval.
ConfidentialClient matter information, correspondence, contracts, financial and trust account information, employee records.Need-to-know access; password-protected when emailed; stored only on Firm-approved systems; locked away when in paper form.
RestrictedPersonal information and special personal information, including information supplied by clients about their customers, employees or account holders; identity and FICA documents; bank details; health or criminal information.All Confidential requirements plus: encrypted at rest and in transit; access logged; not stored on removable media or personal devices; shared only with the minimum necessary recipients; securely destroyed at end of retention period.

6. Access control and authentication

  • Least privilege and need-to-know. Access to systems, folders and matter files is granted only to the extent required for a person's role and current matters, and is approved by the relevant head of department.
  • Unique accounts. Every user has a unique, personal account. Shared or generic accounts are prohibited for access to client or personal information.
  • Multi-factor authentication (MFA) is enforced on email, remote access, cloud services and practice-management systems.
  • Password standard. Minimum 12 characters, not reused across systems, changed immediately if compromise is suspected, and managed with an approved password manager. Passwords may never be shared or written down in the open.
  • Joiners, movers and leavers. Access is provisioned on written request at onboarding, adjusted on change of role, and revoked on the last working day. Devices and access cards are returned and accounts disabled before final pay is released.
  • Access reviews. User accounts and access rights are reviewed quarterly by the Deputy Information Officer with the IT Service Provider, and dormant accounts are disabled.
  • Privileged access. Administrative rights are limited to the IT Service Provider and named individuals, used only for administrative tasks, and logged.
  • Session controls. Screens lock automatically after 10 minutes of inactivity; staff must lock their workstations when leaving their desks.

7. Email and secure transmission of information

Mandatory rule: Any document containing personal information — including identity documents, bank details, FICA records, statements of account, contracts, pleadings, schedules of debtors or any data supplied by a client — must be password-protected or encrypted before it is transmitted via email. The password must be communicated to the recipient through a separate channel (SMS, telephone call or a separate message), never in the same email.

In addition, all staff, contractors and subcontractors must:

  • use PDF or Microsoft Office password protection (AES-256 where available), an encrypted archive, or a secure file-sharing link with expiry and access controls, for all Confidential and Restricted attachments;
  • use the Firm's secure file-transfer platform rather than email for large volumes of personal information (for example, bulk debtor schedules or discovery bundles);
  • verify recipient addresses before sending, avoid auto-complete errors, and use "Bcc" when writing to multiple external recipients;
  • never place personal information (names, identity numbers, account numbers, case details) in email subject lines;
  • never forward Firm email automatically to personal or external mailboxes, and never use personal email, messaging apps or personal cloud storage for Firm or client information;
  • treat unexpected requests to change bank details, make payments or share information as suspected fraud, and verify them by telephone using known contact numbers before acting;
  • report suspicious emails (phishing, spoofing, malware) to the IT Service Provider and Deputy Information Officer without opening links or attachments; and
  • include the Firm's confidentiality disclaimer on all outgoing email.

Email is protected by spam and malware filtering, link and attachment scanning, sender authentication (SPF, DKIM and DMARC), transport-layer encryption (TLS) and MFA. Mailboxes are retained and backed up in accordance with the retention schedule in the Privacy Policy.

8. Data minimisation and purpose limitation

  • Personal information is collected, used, stored and shared only to the extent necessary for the specific, authorised purpose of a matter or business process.
  • Client information is processed strictly in accordance with the client's instructions, mandate and contractual requirements; it is not used for any other purpose, combined with other data, or retained beyond the period required, without the client's written authorisation.
  • When information is shared with courts, counterparties, experts or other third parties, staff share only the documents and fields required, and redact personal information that is not relevant to the purpose.
  • Requests to clients for information must be limited to what the matter genuinely requires.
  • Personal information is de-identified or aggregated where the purpose can be achieved without identifying individuals (for example, in reports, precedents and training material).

9. Devices, endpoints and removable media

  • All laptops and desktops are Firm-owned or Firm-approved, enrolled in central management, and protected by full-disk encryption, endpoint detection and response (anti-malware), a host firewall and automatic security updates.
  • Operating systems and applications are patched within 14 days of the release of security updates (critical vulnerabilities within 72 hours). Unsupported software is not permitted.
  • Users do not have local administrator rights and may not install unapproved software.
  • Mobile phones used for Firm email must have a passcode or biometric lock, encryption and remote-wipe capability enabled.
  • Restricted information may not be stored on USB drives, external hard drives or personal devices. Where removable media is unavoidable, it must be Firm-issued, encrypted and logged.
  • Devices must never be left unattended in vehicles or public places. Loss or theft must be reported immediately so that the device can be remotely wiped.
  • Devices and media are securely wiped or physically destroyed by an accredited provider before disposal, and a certificate of destruction is retained.

10. Network, systems and remote working

  • Office networks are protected by managed firewalls with intrusion prevention, and administrative interfaces are not exposed to the internet.
  • Guest Wi-Fi is segregated from the internal network. Internal Wi-Fi uses WPA2/WPA3-Enterprise or equivalent with strong credentials.
  • Remote access to Firm systems is permitted only via approved, MFA-protected connections (VPN or secure cloud services). Public Wi-Fi may only be used with the VPN enabled.
  • When working remotely, staff must work in a private space, use privacy screens where appropriate, and not allow family members or others to view or use Firm devices.
  • Systems are monitored for security events; logs are retained for at least 12 months and reviewed by the IT Service Provider.
  • Cloud services are used only where approved by the Information Officer, hosted by reputable providers with recognised security certifications (for example ISO/IEC 27001 or SOC 2), and covered by an operator agreement.

11. Backup and business continuity

  • Practice-management, accounting, document and email data are backed up at least daily to encrypted, off-site or cloud storage, with a copy isolated from the production network to protect against ransomware.
  • Backup restores are tested at least quarterly and results recorded.
  • A business continuity and disaster recovery plan sets out how the Firm will restore critical systems and continue to serve clients following a major incident, with a recovery time objective of 24 hours for critical systems.

12. Physical security and clean desk

  • Offices are access-controlled; visitors sign in, are escorted, and do not have unaccompanied access to work areas or file rooms.
  • Paper files containing Confidential or Restricted information are stored in locked cabinets or secured file rooms, and are not left on desks, printers or in meeting rooms when unattended (clean desk / clear screen rule).
  • Printing of Restricted information is limited to what is necessary, collected immediately, and shredded when no longer required using cross-cut shredders or an accredited document destruction service.
  • Archived files are stored with an accredited off-site storage provider under an operator agreement, and destroyed at the end of their retention period with a certificate of destruction.
  • CCTV is used at office premises for security purposes and footage is retained for up to 90 days.

13. Contractors, subcontractors and operators

The Firm remains accountable under POPIA for personal information processed on its behalf. Accordingly:

  • Every operator (IT support, cloud, archiving, tracing, correspondent attorneys, counsel, experts, document destruction and similar providers) is assessed for its security and privacy practices before engagement.
  • A written agreement is concluded with every operator, requiring it to process personal information only on the Firm's instructions and for the mandated purpose, maintain confidentiality, implement security measures at least equivalent to this Policy, notify the Firm immediately of any actual or suspected security compromise, return or destroy information at the end of the engagement, and permit the Firm to verify compliance.
  • Client information may not be subcontracted or transferred to any third party without the client's authorisation where the client's contract so requires.
  • Contractors and subcontractors with access to personal information sign confidentiality undertakings, complete the Firm's privacy and security awareness training (or provide equivalent evidence) before access is granted, and are included in access reviews.
  • An operator register is maintained, recording each operator, the information it processes, the agreement in place and the date of last review.

14. Training and awareness

Induction

All new employees, contractors and subcontractors complete POPIA and information security training before they are given access to client or personal information, and acknowledge this Policy in writing.

Annual refresher

Every person covered by this Policy completes refresher training at least once a year, covering POPIA obligations, secure email and document handling, phishing and fraud, incident reporting and client-specific requirements.

Ongoing awareness

Periodic security reminders, phishing awareness exercises, and briefings whenever the law, this Policy or a client requirement changes.

Training completion, dates and attendees are recorded in the training register maintained by the Deputy Information Officer. Staff who have not completed required training may have their access to client information suspended until it is completed.

15. Security incident and data breach management

A security incident is any actual or suspected event that compromises, or could compromise, the confidentiality, integrity or availability of information — including lost or stolen devices or files, emails sent to the wrong recipient, unauthorised access, malware or ransomware, phishing that results in credential disclosure, and unauthorised disclosure of personal information.

StepWhat happensTimeframe
1. ReportAnyone who becomes aware of an actual or suspected incident reports it to the Deputy Information Officer and the IT Service Provider. Staff will never be penalised for reporting in good faith.Immediately, and within 1 hour of discovery
2. Contain & assessThe incident is logged, contained (accounts disabled, devices isolated, recalls attempted), evidence preserved, and the scope, affected data subjects and clients, and severity are assessed by the Information Officer.Within 24 hours of report
3. Notify clientsAny client whose information is involved is notified of the actual or suspected breach, privacy incident or unauthorised disclosure — with the known facts, the information affected, the containment measures taken and a named contact — and kept updated.Without undue delay and within 24 hours of confirmation, or any shorter period required by the client's contract
4. Notify Regulator & data subjectsWhere personal information has been accessed or acquired by an unauthorised person, the Information Regulator and affected data subjects are notified in writing in accordance with section 22 of POPIA, unless a public body responsible for law enforcement requests a delay.As soon as reasonably possible after discovery
5. Remediate & reviewRoot cause is identified, corrective and preventive actions are implemented, and the incident register is updated. A post-incident review is presented to the Board and lessons are built into training and this Policy.Within 30 days of closure

Report an incident: officemanager@gcolotela.co.za · 031 312 0036 (ask for the Office Manager).

16. Records and controls demonstrating compliance

The Deputy Information Officer maintains the following records, which are available to clients, auditors and the Information Regulator on request:

RecordContentReviewed
Register of processing activitiesCategories of data subjects and personal information, purposes, lawful basis, recipients, cross-border transfers and retention periods for each business process.Annually
Information asset registerSystems, devices, cloud services and paper archives, their owners, classification and security controls.Annually
Operator / third-party registerEach operator, the information processed, the agreement in place, due-diligence outcome and review date.Annually
Access rights register and review recordsWho has access to which systems and matter categories; evidence of quarterly reviews and leaver de-provisioning.Quarterly
Training registerInduction and refresher training completed by each employee, contractor and subcontractor, with dates and material versions.Annually
Policy acknowledgement registerSigned acknowledgements of this Policy and the Privacy Policy.On issue of each version
Incident registerAll reported incidents, assessment, notifications made (clients, Regulator, data subjects), remediation and closure.Per incident and annually
Data-subject and client request registerAccess, correction, objection and deletion requests, response dates and outcomes.Per request and annually
Backup and restore test logBackup completion and quarterly restore tests.Quarterly
Compliance assessment reportsResults of annual internal assessments, external audits and client due-diligence questionnaires, with action plans.Annually

17. Monitoring, review and audit

  • This Policy, the Privacy Policy and supporting procedures are reviewed by the Information Officer at least annually, and additionally after any significant incident, change in legislation or regulatory guidance, change in systems, or new client requirement.
  • An internal compliance assessment against POPIA, this Policy and client contractual requirements is conducted annually, and findings are tracked to closure in an action plan approved by the Board.
  • The Firm cooperates with client audits and due-diligence reviews and responds to supplier questionnaires within the agreed timeframes.
  • Technical controls are monitored continuously by the IT Service Provider, who reports on patch status, backup status, security alerts and access reviews to the Deputy Information Officer at least monthly.
  • Compliance with this Policy is also monitored through periodic spot checks (for example, of email attachments and clean desk compliance).

18. Non-compliance

Failure to comply with this Policy exposes the Firm, its clients and data subjects to legal, financial and reputational harm. Breaches by employees are dealt with under the Firm's disciplinary code and may constitute serious misconduct. Breaches by contractors, subcontractors or operators may result in termination of the engagement and recovery of losses. Deliberate unlawful processing of personal information may also be an offence under POPIA and the Cybercrimes Act.

19. Contact

Questions about this Policy, requests for compliance evidence, and security incident reports may be directed to:

Information Officer / Deputy Information Officer — K Gcolotela & Peter Incorporated

99 Adelaide Tambo Drive, Durban North, 4051

Tel: 031 312 0036

Email: officemanager@gcolotela.co.za