Purpose of Processing and Categories of Information
Insofar as POPIA is concerned, we set out below the information required in terms of section 51(1)(c) of PAIA:
| Category of Personal Information | Category of Data Subject | Purpose of Processing | Category of Recipients |
| Financial Records | Firm | Financial reporting and tax compliance | Firm’s directors, shareholders, employees, accountants, auditors and applicable regulatory authorities (including without limitation, South African Revenue Services (SARS) and Legal Practice Council (LPC)) |
| Firm, clients and legal correspondents | Provision of services | Clients’ nominated recipients, Firm’s employees, accountants, correspondents, auditors, financial institutions and applicable regulatory authorities (including without limitation, SARS and LPC) | |
| Firm and creditors | Receipt of business services | Firm’s employees, accountants, auditors and applicable regulatory authorities (including without limitation, SARS) | |
| Company Secretarial | Firm, shareholders, employees, auditors | Maintenance of company records and financial reporting | Firm’s employees, suppliers, shareholders, directors, accountants, auditors and applicable regulatory authorities (including without limitation, SARS, LPC, Companies and Intellectual Property Commission) |
| FICA Records | Clients, prospective clients and connected persons (including ultimate beneficial owner(s)) | Compliance with FICA as an ‘Accountable Institution’ | Firm’s employees and applicable regulatory authorities (including without limitation, Financial Intelligence Centre) |
| Client Data | Clients and other relevant third parties | Provision of legal services | Clients’ nominated recipients, Firm’s employees, accountants, correspondents, auditors, applicable counsel, and regulatory authorities (including without limitation, LPC) |
| Human Resources | Firm and employees | Business operations and compliance with labour laws | Firm’s employees, suppliers, directors, shareholders, accountants, auditors and applicable regulatory authorities (including without limitation, SARS and Director-General of Labour Department) |
| Marketing | Firm, employees and clients | Marketing | Firm’s employees and all information contained on website is publicly available |
| Administration | Firm, employees, clients and suppliers | Business operations | Firm’s employees, suppliers, directors, shareholders, accountants, auditors and applicable regulatory authorities (including without limitation, LPC and Department of Health) |
Planned Transborder Flows of Information
As required in terms of section 51(1)(c)(iv) of PAIA, the planned transborder flows of information entail:
- The transfer of the Firm’s data stored on the Microsoft Office 365 exchange and backed-up into the cloud located in the European Union protected by the Microsoft Office 365 Trust Centre, and data stored on a system using Microsoft Power Apps, part of the Microsoft Office 365 services located in the UK Microsoft Office 365 Trust Centre;
- The possible transfer of client information to correspondents (such as foreign law firms) as part of rendering legal professional services to the client; and
- The transfer of Firm and employee-related information for the purposes of marketing, which transfers shall all be in accordance with section 72 of POPIA.
Information Security Measures
As required in terms of section 51(1)(c)(v) of PAIA, the Firm has implemented a number of information security measures (including encrypted back-ups, secure hosted services, anti-malware and firewalls) to ensure the confidentiality, integrity and availability of any information which may be processed by the Firm