Visible South Africa
POPIA Policy
Visible South Africa NPC (“Visible SA”, “we”, “our”, “us”) is committed to safeguarding personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains how we collect, use, disclose, store, and protect personal information relating to natural and juristic persons in South Africa.
1. Who We Are
Visible SA is a charitable organisation based in South Africa. Through the Naked Truth Project, our mission is ‘opening eyes and freeing lives from the damaging impact of pornography’. We act as the Responsible Party as defined under POPIA and determine the purpose and means of processing personal information.
2. Information Officer
Visible SA NPC on acceptance of this policy will appoint a designated Information Officer (IO), as required under POPIA Sections 55–56. The IO is responsible for encouraging and ensuring compliance with the Act, managing internal awareness, handling data subject requests, conducting assessments, and liaising with the Information Regulator.
The Information Officer will be registered with the Information Regulator, as legally required, and Visible SA will ensure that any appointed Deputy Information Officers in the future, are also registered before assuming their duties.
Contact details of the Information Officer are published in accordance with POPIA’s “Openness” condition and the POPIA Regulations.
3. What Data We Collect
We collect and process various types of personal data, including:
- Identity Information: Name, title, date of birth
- Contact Information: Email, telephone number, postal address
- Financial Information: Donation history, bank details (if applicable)
- Technical Information: IP address, browser type, operating system, device identifiers
- Usage Information: Website navigation, event attendance, communication preferences
- Special Category Data: Religious affiliation, where voluntarily provided for charity purposes
- POPIA also protects juristic persons.
4. How We Collect Data
We collect personal data through:
- Donation forms and payment processing platforms
- Website forms and newsletter sign-ups
- Volunteering or employment applications
- Events, workshops, and ministry activities
- Cookies and online tracking technologies
- Direct communication (e.g., phone calls, emails)
- Social media platforms
5. Conditions for Lawful Processing (POPIA’s 8 Principles)
We comply with accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.
6. Lawful Basis for Processing under POPIA
We process personal information in accordance with Section 11 of POPIA, using one or more of the following lawful justifications:
Consent Management - Where processing is based on consent, Visible SA ensures that consent is voluntary, specific, and informed, and obtained through a clear, affirmative action.
Pre-ticked boxes, silence, or inactivity will never constitute valid consent.
Data subjects may withdraw consent at any time through a simple written request to the Information Officer, and Visible SA will cease processing unless another lawful basis under POPIA applies.
All consent records are securely stored and auditable.
- Consent – When you have voluntarily, specifically, and knowingly agreed to our processing (e.g., marketing communications).
- Contractual Necessity – Where processing is required to enter into or perform a contract or respond to your request.
- Legal Obligation – Where processing is required to comply with South African law.
- Legitimate Interests – Where processing is necessary to pursue our legitimate interests or those of a third party, provided this does not infringe your rights or interests.
- Vital Interests – To protect your or another person’s life or physical safety.
- Public Law Duty / Public Interest – Where processing is necessary to perform a public law duty or is in the public interest, where applicable.
7. How We Use Your Data
We use your personal data to:
- Process donations and issue receipts
- Communicate charity updates, appeals, and events
- Manage volunteer involvement
- Respond to enquiries and requests
- Improve our website and online experiences
- Comply with applicable legal and regulatory obligations
8. Data Sharing and Transfers
We may share your data with trusted third parties for the following purposes:
Visible SA may transfer or store personal information outside South Africa where necessary to provide services or operate our systems, including the use of secure cloud-based platforms and service providers.
Where personal information is transferred outside South Africa, Visible SA will take reasonable steps to ensure that such transfers comply with POPIA. This includes ensuring that the recipient is subject to appropriate data protection obligations or that adequate safeguards are in place to protect personal information.
- IT support and infrastructure, including cloud services
- Email marketing and Email communication platforms (e.g., Mailchimp)
- Payment processing (e.g., Stripe, PayPal)
- Legal and regulatory compliance
- Website hosting and analytics
- Event Systems
9. Operator (Third-Party Processor) Compliance
Visible SA engages third-party service providers (“operators”) only under written Operator Processing Agreements (OPAs), as required by POPIA.
These agreements specify:
- the operator may only process personal information with Visible SA’s knowledge and authorisation;
- confidentiality obligations;
- required technical and organisational safeguards;
- breach-reporting duties (operators must notify Visible SA immediately upon becoming aware of a security compromise);
- restrictions on subcontracting without prior written approval.
Visible SA conducts periodic reviews to ensure operators comply with this policy.
10. Data Retention and Secure Disposal
Visible SA retains personal information only for as long as necessary to fulfil the specific purposes for which it was collected, or as required by applicable South African law. Typical retention periods include:
- Donation and financial data: 7 years (to comply with companies act)
- Data related to VAT: 5 years
- Mailing list subscriptions: Until you unsubscribe
- Employment files: 3-5 years
Upon expiry of the relevant retention period, personal information is securely deleted, anonymised, or destroyed using industry-approved disposal methods consistent with Section 14 of POPIA (Purpose Limitation and Retention). Data subjects will be informed of applicable retention periods upon request, and retention practices are reviewed annually as part of Visible SA’s compliance audit processes. We periodically review and securely delete or anonymise data that is no longer needed.
11. Your Rights
Under POPIA, you have the following rights:
Data subjects may exercise their rights above, by contacting the IO. Visible SA will acknowledge requests within a reasonable time and respond within 20 working days, unless an extension is permitted due to the nature or volume of the request.
Requests must be submitted via email or post using the contact details in Section 14, and Visible SA may request verification of identity before actioning any request, in accordance with the POPIA Regulations.
All actions taken regarding data subject requests will be documented in compliance with POPIA’s accountability obligations.
- Right to Access – Request a copy of your data
- Right to Rectification – Request correction of inaccurate data
- Right to Erasure – Request deletion of your data
- Right to Restrict Processing – Temporarily halt use of your data
- Right to Object – Opt out of certain uses (e.g., direct marketing)
- Right to Data Portability – Request transfer of your data to another service
- Right to Withdraw Consent – At any time for processing based on consent
- Right to Disclosure Information
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or loss. These include secure servers, encryption, password protection, and staff training.
13. Use of Artificial Intelligence (AI) and Safeguards
Visible South Africa is committed to ensuring that the use of Artificial Intelligence (AI) systems aligns with the highest standards of data protection and ethical responsibility. Where AI systems are used to collect, analyse, or manage personal information, Visible SA will ensure full compliance with the POPIA act and related regulatory guidance. We will do this by implementing the following safeguards:
Purpose and Lawful Use
AI tools will only be used for lawful, specific, and explicitly defined purposes. Personal information processed by AI systems will be adequate, relevant, and not excessive for the purposes for which it is collected.
Transparency
Individuals will be clearly informed whenever their personal information is processed using AI or automated tools. This includes the purpose of the processing, the type of data involved, and the potential impact on the individual.
Data Minimisation
Only the minimum personal information necessary for the functioning of the AI system will be collected and processed. AI systems will be designed and configured to avoid unnecessary or excessive data use.
Human Oversight and Section 71 Compliance
Visible SA will not make decisions that produce legal or similarly significant effects solely through automated processing unless permitted under Section 71 of POPIA and accompanied by appropriate safeguards. Where automated decision-making is used: individuals will be notified that a decision has been made using automated processing; individuals will have the right to request human intervention, express their views, and contest such decisions; and a suitably authorised staff member will review such decisions to ensure fairness, accuracy, and accountability.
Right to Object and Right to Explanation
Individuals may object at any time to the processing of their personal information by AI systems, in accordance with POPIA. They may also request meaningful information about the logic involved in automated processing and the consequences of such processing.
Bias, Fairness, and Non-Discrimination
Visible SA will regularly assess AI systems to identify, prevent, and mitigate risks of unfair bias or discriminatory outcomes. This includes periodic testing, validation, and review of algorithms and datasets.
Security Safeguards
Personal information processed by AI systems will be protected through appropriate technical and organisational measures, including but not limited to: encryption, access controls, audit trails, and secure data storage and transmission. These safeguards will be reviewed and updated regularly to address emerging risks.
Ongoing Monitoring and Accountability
All AI systems used by Visible SA will be subject to ongoing monitoring, evaluation, and audit to ensure compliance with POPIA, internal policies, and ethical standards. Any third-party AI service providers will be required to meet equivalent data protection obligations.
Continuous Improvement
Visible SA is committed to responsible innovation. This clause will be reviewed and updated as technology, regulatory expectations, and best-practice standards evolve. For any questions regarding the use of AI or automated decision-making, individuals may contact the Information Officer.
14. Cookies and Website Usage
Our website uses cookies to enhance your browsing experience and help us understand site usage. You can control or disable cookies in your browser settings.
15. Children’s Privacy
We do not knowingly collect personal data from individuals under the age of 18 without parental consent. If you believe a child has provided us with data without permission, please contact us.
16. POPIA Compliance and Accountability
Visible SA is committed to ensuring ongoing compliance with POPIA. The Information Officer is responsible for overseeing implementation of this policy, promoting staff awareness, and monitoring compliance within the organisation.
Visible SA will take reasonable steps to ensure that all staff, volunteers, and contractors who process personal information understand their responsibilities under POPIA. Periodic internal reviews may be conducted to ensure that personal information is handled appropriately and securely.
16. Changes to This Policy
We may update this policy periodically to reflect changes in legal requirements or our data practices. The latest version will always be available on our website.
17. Contact Us
If you have questions, concerns, or wish to exercise your data rights, please contact us in the first instance:
Information Officer (IO) Visible SA Address: Email: Info@visibleSA.com Phone: Website:
18. Data Breach Procedure
18.1 Identification and Containment
Any staff member who becomes aware of a potential data breach must immediately report it to the Information Officer (IO). The IO will investigate and classify the breach. Immediate actions will be taken to contain and mitigate further risk (e.g., suspending systems, changing access rights, informing IT support).
18.2 Assessment
The IO will assess the scope and impact of the data breach, including the type and volume of personal data affected, the number of data subjects impacted, and risks to individuals (including identity theft, distress, and financial harm).
18.3 Data Breach Notification
In accordance with Section 22 of POPIA, Visible SA will, as soon as reasonably possible after becoming aware of a security compromise involving personal information, notify the Information Regulator and affected data subjects (unless their identities cannot be established). Notifications will include a description of the nature and scope of the breach; types of data involved; steps Visible SA is taking or has taken to address the breach; recommended measures for affected individuals; and the identity of the unauthorised party, if known.
18.4 Record-Keeping
All breaches—whether notifiable or not—are logged in Visible SA’s Security Compromise Register, in accordance with accountability obligations. This log includes details of the incident, actions taken, outcomes, and whether notifications were made.
18.5 Review and Remediation
Following each incident, a formal review will be conducted to determine root causes, effectiveness of the response, and required improvements in policies, training, or systems. The IO will ensure appropriate updates are made to minimise future risk.
19. Adoption of this policy
Policy adopted and approved on by the Directors on: 7 April 2026
Next Review date: March 2028
Signed: (Ian Henderson, Chair)