Privacy Policy & POPIA Notice
How K Gcolotela & Peter Incorporated collects, uses, protects, shares and retains personal information, and the rights you have as a data subject.
1. Introduction
K Gcolotela & Peter Incorporated ("KG&P", "the Firm", "we", "us" or "our") is a firm of attorneys, conveyancers and notaries. In the course of providing legal services we necessarily collect and process personal information about our clients, their employees and customers, counterparties, witnesses, suppliers, job applicants, website visitors and other persons.
We are committed to processing personal information lawfully, securely and responsibly, in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), the Legal Practice Act 28 of 2014, the rules of the Legal Practice Council, and our contractual obligations to our clients.
This Privacy Policy explains what personal information we collect, why we collect it, how we protect it, who we share it with, how long we keep it, and what rights you have. It should be read together with our Information Security Policy, which describes the technical and organisational measures we apply to safeguard personal information.
2. Who we are (Responsible Party)
For the purposes of POPIA, the responsible party is:
- Legal name
- K Gcolotela & Peter Incorporated
- Nature of business
- Attorneys, Conveyancers and Notaries Public (private body)
- Head office
- 99 Adelaide Tambo Drive, Durban North, KwaZulu-Natal, South Africa
- Other offices
- Sunninghill (Gauteng), Cape Town (Western Cape), East London and Gqeberha (Eastern Cape)
- Telephone
- 031 312 0036 (KZN) | 010 023 1875 (GP)
- reception@gcolotela.co.za
- Website
- www.gcolotela.co.za
3. Information Officer
In terms of section 55 of POPIA and section 17 of PAIA, the Firm has designated an Information Officer who is responsible for encouraging and ensuring compliance with POPIA, dealing with requests made under POPIA and PAIA, working with the Information Regulator, and ensuring that this Policy and our internal measures are implemented, maintained and reviewed.
Our Information Officer is registered with the Information Regulator (South Africa) as required by Regulation 4 of the POPIA Regulations.
4. Definitions
Terms used in this Policy carry the meaning given to them in POPIA. In particular:
- Personal information means information relating to an identifiable, living natural person and, where applicable, an identifiable existing juristic person, including (but not limited to) names, identity numbers, contact details, financial and employment history, biometric information, opinions, correspondence and any identifying number or symbol.
- Special personal information means information about a person's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour.
- Processing means any operation concerning personal information, including collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, distribution, merging, linking, restriction, erasure or destruction.
- Data subject means the person to whom personal information relates.
- Responsible party means the person who determines the purpose of and means for processing personal information — in this Policy, the Firm.
- Operator means a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party (for example, our IT, cloud hosting and document-management service providers).
- Information Regulator means the Information Regulator (South Africa) established under section 39 of POPIA.
5. What personal information we collect
Depending on your relationship with us, we may collect and process the following categories of personal information:
| Category | Examples |
|---|---|
| Identity information | Full names, identity or passport number, date of birth, gender, nationality, marital status, company registration numbers, signatures and FICA verification documents. |
| Contact information | Physical, postal and email addresses, telephone and mobile numbers. |
| Financial information | Bank account details, income and asset information, credit and payment history, property and bond details, and information required for trust account transactions. |
| Employment information | Employer, occupation, employment history, CVs, qualifications and references (clients, witnesses and job applicants). |
| Matter information | Instructions, correspondence, pleadings, contracts, deeds, evidence, and any personal information contained in documents relating to a legal matter, including information about third parties such as counterparties, witnesses and family members. |
| Client-provided data | Personal information of our clients' customers, employees, debtors or account holders that a client shares with us for the purposes of a mandate (for example, debt recovery, litigation, conveyancing or investigations conducted on behalf of a financial institution). |
| Special personal information | Health, criminal, biometric or similar information, only where necessary for a legal matter (for example personal injury, labour or forensic matters) and processed under an applicable POPIA exemption. |
| Website and technical data | IP address, browser type, device information, pages visited and cookie data collected when you use our website or submit an online form. |
6. How we collect personal information
Wherever reasonably practicable we collect personal information directly from you. We may also collect personal information:
- from our clients, when they instruct us on a matter in which you are involved;
- from public sources and registers, such as the Deeds Office, CIPC, the courts, credit bureaus and public records, where this is necessary for a matter and permitted by law;
- from third parties such as counterparties, other attorneys, sheriffs, tracing agents, experts, government departments and regulators;
- from your employer or recruitment agency (job applicants);
- through our website, contact forms, event registrations, cost calculator and email correspondence; and
- through CCTV and visitor registers at our offices, for security purposes.
7. Why we process personal information
We process personal information only for authorised, specific and lawful business purposes and in accordance with our contractual obligations. These purposes include:
- providing legal advice and services, and carrying out client mandates (litigation, conveyancing, debt recovery, commercial, labour, estate, procurement and forensic matters);
- verifying identity and complying with the Financial Intelligence Centre Act 38 of 2001 ("FICA") and other anti-money-laundering and anti-corruption obligations;
- administering client files, trust account transactions, billing and collections;
- communicating with clients, courts, counterparties and other parties to a matter;
- complying with our obligations to the Legal Practice Council, the courts, regulators and law enforcement;
- managing our relationships with suppliers, service providers and business partners;
- recruiting and employing staff;
- maintaining the security of our premises, systems and information; and
- operating and improving our website, and responding to enquiries submitted through it.
We do not process personal information for purposes that are incompatible with those for which it was collected, unless you consent or the further processing is otherwise permitted by POPIA.
8. Our commitment to lawful processing
We give effect to the eight conditions for lawful processing set out in Chapter 3 of POPIA as follows:
Accountability
The Firm remains responsible for compliance with POPIA, including where processing is outsourced to an operator.
Processing limitation
We process personal information lawfully, in a reasonable manner that does not infringe your privacy, and only with a lawful justification (consent, contract, legal obligation, legitimate interest or protection of your interests).
Purpose specification
We collect personal information for specific, explicitly defined and lawful purposes and retain it no longer than necessary.
Further processing limitation
Further processing must be compatible with the original purpose of collection.
Information quality
We take reasonable steps to ensure that personal information is complete, accurate, not misleading and up to date.
Openness
We maintain the documentation required by section 51 of PAIA and inform data subjects of the purpose of collection through this Policy.
Security safeguards
We secure the integrity and confidentiality of personal information through appropriate technical and organisational measures (see section 11).
Data subject participation
You may access, correct and, where appropriate, request deletion of your personal information (see section 14).
Data minimisation
We collect, use and share only the minimum personal information necessary for the specific purpose at hand. Staff are instructed to request and disclose only what a matter requires, and to redact personal information that is not relevant before documents are shared.
10. Cross-border transfers
Personal information is stored and processed primarily in South Africa. Where a service provider stores information outside South Africa (for example, cloud email or backup services), we transfer personal information only where permitted by section 72 of POPIA — that is, where the recipient is subject to a law, binding corporate rules or a binding agreement that provides substantially similar protection to POPIA, where you have consented, or where the transfer is necessary for the performance of a contract with you or in your interest.
11. Security safeguards
In terms of section 19 of POPIA we secure the integrity and confidentiality of personal information in our possession or under our control by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of it. These measures are set out in detail in our Information Security Policy and include:
Password-protected transmission
All documents containing personal information are password-protected or encrypted before being transmitted by email, with the password communicated through a separate channel.
Access control
Access to files and systems is restricted on a need-to-know basis, protected by unique user accounts, strong passwords and multi-factor authentication.
Secure systems
Encrypted devices, endpoint protection, patched systems, firewalled networks and secure, regularly tested backups.
Trained people
Mandatory privacy and security awareness training for all employees, contractors and subcontractors who handle personal information, at induction and annually thereafter.
Confidentiality
Attorney-client privilege, professional confidentiality obligations and written confidentiality undertakings from all staff and operators.
Regular review
Our processes, policies and controls are reviewed at least annually and after any incident to ensure ongoing adherence to data protection laws and contractual obligations.
12. Data breaches and security compromises
We maintain a documented incident response procedure. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will:
- contain the incident and preserve evidence immediately;
- promptly report the actual or suspected breach, privacy incident or unauthorised disclosure to any client whose information is involved, in accordance with our contractual obligations and without undue delay;
- notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery, as required by section 22 of POPIA, including a description of the possible consequences and the measures we have taken or intend to take;
- record the incident in our incident register; and
- conduct a post-incident review and implement corrective measures.
Anyone who becomes aware of an actual or suspected security compromise involving information held by the Firm should report it immediately to officemanager@gcolotela.co.za or to 031 312 0036.
13. Retention of personal information
We retain personal information only for as long as is necessary to achieve the purpose for which it was collected, unless a longer period is required or permitted by law, is reasonably required for lawful purposes related to our functions, is required by a contract, or you have consented. Indicative retention periods are:
| Record type | Retention period |
|---|---|
| Client files and matter records | Minimum of 7 years after the matter is closed (Legal Practice Act and Legal Practice Council rules), or longer where a matter or claim remains open |
| Trust and business accounting records | Minimum of 7 years (Legal Practice Act, Companies Act and Tax Administration Act) |
| FICA identification and verification records | 5 years from the end of the business relationship or transaction |
| Conveyancing and deeds records | Retained in accordance with Deeds Registries Act requirements |
| Employee records | Duration of employment plus the periods required by labour and tax legislation |
| Unsuccessful job applications | 12 months after the recruitment process, unless you consent to longer retention |
| Website enquiries and event registrations | Until the enquiry or event has been dealt with and for a reasonable period thereafter, not exceeding 24 months |
| CCTV footage and visitor registers | Up to 90 days unless required for an investigation |
When personal information is no longer required, it is securely destroyed, deleted or de-identified so that it cannot be reconstructed.
14. Your rights as a data subject
Subject to the exceptions in POPIA and to legal professional privilege, you have the right to:
- be notified that we are collecting your personal information, or that it has been accessed by an unauthorised person;
- request access to the personal information we hold about you, and to know the identity of third parties who have had access to it (section 23);
- request correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, obtained unlawfully or no longer authorised to be retained (section 24);
- object to the processing of your personal information on reasonable grounds relating to your particular situation, or for purposes of direct marketing (section 11(3));
- withdraw consent at any time, where processing is based on consent;
- not be subject to a decision based solely on automated processing of your personal information; and
- lodge a complaint with the Information Regulator.
How to exercise your rights
Send your request to the Information Officer at officemanager@gcolotela.co.za with the subject line "POPIA Data Subject Request", or use the prescribed Form 2 (objection) or Form 1 (access request under PAIA) available from the Information Regulator. We will need to verify your identity before responding.
We will respond within a reasonable time and in any event within 30 days, unless a longer period is permitted by law. A prescribed fee may be payable for access requests under PAIA.
15. Direct marketing
We will only send you electronic marketing communications (such as newsletters, event invitations and legal updates) where you are an existing client, or where you have given your consent in accordance with section 69 of POPIA. Every marketing communication will include a simple means to opt out, and we will honour your request promptly.
17. Children's personal information
We process the personal information of children (persons under 18) only where necessary for a legal matter and with the consent of a competent person, or where otherwise permitted by section 35 of POPIA.
18. PAIA manual
Our manual in terms of section 51 of the Promotion of Access to Information Act describes the records we hold and the procedure for requesting access to them. A copy is available on request from the Information Officer and for inspection at our head office.
19. Complaints
If you believe that we have processed your personal information unlawfully, please raise the matter with our Information Officer first so that we can attempt to resolve it. You also have the right to lodge a complaint with the Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za
20. Changes to this Policy
We review this Policy at least annually and whenever there is a material change in the law, our business or our processing activities. The current version will always be published on this page with its effective date. Material changes affecting existing clients will be communicated directly.
21. Contact us
Questions about this Policy, requests to exercise your rights, and reports of privacy incidents may be directed to:
Information Officer — K Gcolotela & Peter Incorporated
99 Adelaide Tambo Drive, Durban North, 4051
Tel: 031 312 0036