Compliance

Introduction

At Clear The Air NPC, we are committed to protecting the privacy and security of personal information in compliance with the Protection of Personal Information Act, 4 of 2013 (POPIA). POPIA promotes the lawful processing of personal information by public and private bodies, and establishes the right to privacy as a fundamental human right in South Africa.

This statement outlines our approach to managing personal information, ensuring transparency, accountability, and respect for individuals’ privacy rights.

Isithembiso Sethu

Clear The Air NPC is dedicated to upholding the highest standards of data protection and privacy. We have implemented robust policies, processes, and measures to ensure that personal information is collected, processed, stored, and destroyed in a lawful, ethical, and secure manner. Our compliance with POPIA is aligned with our mission to build trust and integrity in our interactions with stakeholders, beneficiaries, and the public.


How We Protect Your Personal Information

1. Information We Process

We process personal information for specific, lawful purposes related to our organisational objectives, including raising awareness about the illicit tobacco trade, facilitating community engagement, and advocating for legislative change. This information may include:

  • Names and contact details (e.g., email addresses and phone numbers).
  • Demographic details for reporting and campaign purposes.
  • Information provided when signing petitions, subscribing to updates, or participating in events.

2. Lawful Processing

In line with POPIA, Clear The Air NPC ensures that all processing activities are:

  • Justified: Processing is based on one or more lawful grounds, including consent, contractual necessity, or compliance with legal obligations.
  • Transparent: Individuals are informed about why their data is collected, how it is used, and their rights under POPIA.

3. Retention and Erasure

We adhere to the data minimisation and storage limitation principles by:

  • Retaining personal information only for as long as it is necessary to fulfil the purposes for which it was collected.
  • Securely destroying personal information when it is no longer needed or upon the request of the data subject, provided no legal or contractual obligation exists to retain it.

4. Data Subject Rights

Clear The Air NPC recognises and respects the rights of data subjects, which include:

  • The right to access personal information we hold about you.
  • The right to rectification of incorrect or incomplete data.
  • The right to object to the processing of personal information, particularly for direct marketing.
  • The right to withdraw consent where processing is based on consent.
  • The right to request erasure of personal information, subject to legal and regulatory requirements.
  • The right to lodge a complaint with the Information Regulator if you believe your personal information has been unlawfully processed.

To exercise these rights, please contact us at [email protected].

5. Security Measures

We take the security of your personal information seriously and employ technical and organisational measures to prevent unauthorised access, loss, or misuse, including:

  • Data encryption and secure storage.
  • Access controls to restrict personal information to authorised personnel only.
  • Regular security audits and vulnerability assessments.
  • Secure destruction of obsolete data.

Third-Party Processing and Transfers

Where personal information is shared with third parties to achieve our organisational goals (e.g., service providers, partners), we ensure that:

  • A processing agreement is in place to safeguard your information.
  • The third party complies with POPIA and other relevant data protection laws.
  • Personal information is only shared to the extent necessary for the intended purpose.

Direct Marketing and Consent

Clear The Air NPC respects your preferences regarding direct marketing:

  • All marketing communications include clear instructions for opting out or unsubscribing.
  • Consent is obtained before adding individuals to our mailing lists, and records of this consent are securely maintained.

Reporting Data Breaches

In the event of a data breach, we have measures in place to:

  • Identify, investigate, and contain the breach promptly.
  • Notify the affected data subjects and the Information Regulator as required by POPIA.
  • Implement corrective actions to prevent future breaches.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee compliance with POPIA and other applicable privacy laws. The DPO is responsible for promoting awareness of data protection across the organisation, responding to data subject requests, and ensuring continuous adherence to our data protection policies.

If you have any queries or concerns regarding how your personal information is processed, please contact our DPO at:
Email: [email protected]


Conclusion

Clear The Air NPC is dedicated to safeguarding your personal information and ensuring compliance with POPIA. By implementing a privacy-first approach, we aim to foster trust and transparency in all our operations. We are committed to continually enhancing our data protection measures to align with evolving legal standards and best practices.

This statement is subject to updates as necessary to reflect changes in legal or operational requirements.