Terms & Conditions.
INCLUDING PROTECTION OF PERSONAL INFORMATION ACT (POPIA) COMPLIANCE
Sharon’s Shortbread (Pty) Ltd
2020/224130/07
- INTRODUCTION
This manual is prepared in accordance with Section 51 of the Promotion of Access to Information Act, 2 of 2000 (“PAIA”) and incorporates the requirements of the Protection of Personal Information Act, 4 of 2013 (“POPIA”).
The purpose of this manual is to:
- Facilitate requests for access to information held by the organisation
- Outline how personal information is processed in compliance with POPIA
- Provide transparency regarding records held and processing activities
- ORGANISATION DETAILS
Registered Name: Sharon’s Shortbread (Pty) Ltd
Registration Number: 2020/224130/07
Physical and Postal Address: 30 Valerie Road Kibler Park Johannesburg 2196
Telephone number: 082 464 1411
Email: sharon@shortbread.co.za
- INFORMATION OFFICER
Information Officer: Sharon Oosthuizen
Email: sharon@shortbread.co.za Telephone: 082 464 1411
The Information Officer is responsible for:
- Ensuring compliance with PAIA and POPIA
- Handling access to information requests
- Managing personal information processing practices
- GUIDE ON HOW TO USE PAIA
A guide is available from the Information Regulator:
Website: https://www.justice.gov.za/inforeg/ Email: inforeg@justice.gov.za
- APPLICABLE LEGISLATION
The organisation complies with the following legislation:
- Promotion of Access to Information Act 2 of 2000
- Protection of Personal Information Act 4 of 2013
- Companies Act 71 of 2008
- Basic Conditions of Employment Act
- Labour Relations Act
- Income Tax Act
- VAT Act
- RECORDS HELD BY THE ORGANISATION
6.1 Personnel Records
- Employment contracts
- Payroll records
- Disciplinary records
6.2 Financial Records
- Financial statements
- Tax records
- Banking details
6.3 Operational Records
- Client agreements
- Supplier contracts
- Policies and procedures
6.4 IT and Communication Records
- Emails
- System logs
- PROCESSING OF PERSONAL INFORMATION (POPIA)
7.1 Purpose of Processing
Personal information is processed for:
- Providing services
- Managing employees
- Compliance with legal obligations
- Marketing (where consent is obtained)
7.2 Categories of Data Subjects
- Employees
- Clients
- Suppliers
- Website users
7.3 Categories of Personal Information
- Identity information
- Contact details
- Financial information
- Employment information
7.4 Lawful Basis for Processing
- Consent
- Contractual necessity
- Legal obligation
- Legitimate interests
- RECIPIENTS OF PERSONAL INFORMATION
Personal information may be shared with:
- Regulatory authorities
- Service providers
- Auditors
- Legal advisors
- TRANSBORDER INFORMATION FLOWS
Personal information may be transferred outside South Africa where:
- Adequate protection is in place
- Consent has been obtained
- Required for contractual obligations
- INFORMATION SECURITY MEASURES
The organisation implements:
- Access control
- Data encryption
- Secure storage
- Staff training
- DATA SUBJECT RIGHTS
Data subjects have the right to:
- Access their personal information
- Request correction or deletion
- Object to processing
- Lodge complaints with the Information Regulator
- REQUEST PROCEDURE UNDER PAIA
12.1 Request Submission
Requests must be made in writing using the prescribed form and submitted to the Information Officer.
12.2 Fees
Applicable request fees may apply as prescribed by regulation.
12.3 Response Time
Requests will be processed within 30 days.
- AVAILABILITY OF THE MANUAL AND UPDATES TO THIS MANUAL
- This manual is available on request from the Information Officer
- This manual will be updated annually to ensure compliance with legislative requirements.
Last Updated: 23.04.2026