Privacy & POPIA
POPIA Privacy Notice
How DIH MEITS processes and protects personal information in line with the Protection of Personal Information Act, 2013.
Our privacy commitment
DIH MEITS is committed to responsible, transparent and lawful processing of personal information. This notice explains how we collect, use, safeguard and manage information in accordance with POPIA and other applicable legal requirements.
Lawful processing
Information we process
We process only information that is relevant and proportionate to our business relationship, services and legal obligations.
Purpose and basis
Why we use information
Information may be used to respond to enquiries, deliver services, manage customer and supplier relationships, improve our website, meet legal duties and protect our systems.
Safeguards
Protection and accountability
We apply appropriate technical, organisational and contractual measures to protect information against unauthorised access, loss, misuse, alteration or disclosure.
Your rights
Managing your information
You may request access to, correction of or objection to the processing of your personal information. Where applicable, you may request deletion or withdraw consent. We will assess and handle requests in accordance with applicable legal requirements and timelines.
Access and correction requests
Objection and consent withdrawal
Deletion where applicable
Complaint and escalation support
Privacy notice details
Key information about how DIH MEITS manages personal information and privacy requests.
Who is responsible for privacy?
DIH MEITS is responsible for the processing activities described in this notice. Our Information Officer oversees privacy governance, supports compliance and manages relevant requests and complaints.
How do we manage consent?
Where consent is the appropriate lawful basis, we seek it clearly and manage it responsibly. You may withdraw consent at any time, subject to legal and operational requirements.
Do we use third-party operators?
We may use trusted operators or processors to support services, technology platforms and business operations. They are required to process information only on our instructions and with appropriate safeguards.
Can information be processed abroad?
Some service providers or technology platforms may process information outside South Africa. Where this occurs, DIH MEITS applies appropriate safeguards and considers applicable cross-border processing requirements.
How long is information retained?
We retain information only for as long as necessary for the purpose collected, contractual needs, legal obligations, dispute resolution or legitimate business requirements, after which it is securely deleted or de-identified where appropriate.
What happens if there is a breach?
If a security compromise occurs, DIH MEITS will assess the incident, take appropriate containment and remediation steps, and notify affected parties and the Information Regulator where required by applicable law.
