The Protection of Personal Information Act (POPIA) – The Colandi Group.

Because marketing Business Process Outsourcing (BPO) operations handle personal data dual-functionally—acting both as a Responsible Party (for internal staff, direct clients, and own lead pipelines) and an Operator (processing target data on behalf of corporate clients)—this framework embeds strict risk boundaries, operational protocols, and statutory alignment under the 8 Conditions for Lawful Processing.

1. Executive summary & governance structure

1.1 Legal context & application

Under Act 4 of 2013 (POPIA), The Colandi Group must ensure full compliance across all business processes that involve collecting, storing, transmitting, or destroying personal information (PI).

  • Responsible Party Roles: Internal HR/payroll, client account management, direct B2B/B2C marketing campaigns owned by The Colandi Group.
  • Operator Roles: Outsourced campaign execution, lead enrichment, CRM management, and customer support rendered on behalf of third-party enterprise clients.

1.2 Statutory roles & accountability matrix

RoleDesignated DesignationKey Responsibilities
Information Officer (IO)Owner / Director (Andiswa Mchunu)Overall statutory accountability, Information Regulator liaison, policy authorization, breach sign-off.
Deputy Information Officer (DIO)Head of Operations / Enterprise RiskDay-to-day audit execution, Operator contract oversight, access control management.
Data Protection ChampionsTeam Leads (BPO / Campaign Operations)Operational adherence, lead opt-in verification, immediate incident reporting.

2. Alignment with the 8 Conditions for Lawful Processing

POPIA CORE CONDITIONS

 1. Accountability: Ownership & Compliance Structure

 2. Processing Limitation: Consent, Minimal & Direct Collection

 3. Purpose Specification: Defined Retention & Destruction Schedules

 4. Further Processing: Strict Out-of-Scope Data Restrictions

 5. Information Quality: Accuracy & Up-to-Date Verification

 6. Openness: PAIA Manual & Transparent Privacy Notices

 7. Security Safeguards: Technical, Physical & Contractual Security

 8. Data Participation: Data Subject Access & Rectification Rights

Condition 1: Accountability

  • The Colandi Group ensures all processing activities align with POPIA provisions at inception and throughout execution.
  • Mandatory compliance reviews conducted semi-annually under the Enterprise Risk framework.

Condition 2: Processing limitation

  • Data must be processed lawfully and in a reasonable manner without infringing on privacy.
  • Minimality: Only data fields strictly necessary for the outsourced marketing/BPO deliverable may be collected (e.g., stopping unnecessary collection of ID numbers when an email/phone number suffices).
  • Consent & Direct Marketing: Direct electronic marketing (SMS, Email, WhatsApp) requires explicit, voluntary prior consent (Opt-In) unless the subject is an existing client who was given an opportunity to object at collection. Pre-ticked consent boxes are strictly prohibited.

Condition 3: Purpose specification

  • Data collected for a specific campaign or enterprise client cannot be retained longer than necessary to fulfil that specific operational scope.
  • Retention Policy: Lead data for completed campaigns must be archived or securely deleted after 6 months post-campaign unless a longer statutory retention period applies (e.g., tax records).

Condition 4: Further processing limitation

  • Data collected for one BPO campaign or client must never be cross-utilized, aggregated, or re-used for another client’s campaign without fresh, explicit consent.

Condition 5: Information quality

  • Systems must maintain data integrity and accuracy.
  • Marketing lists must be validated against national “Do Not Contact” registries and internal opt-out tables prior to launching any campaign broadcast.

Condition 6: Openness

  • Section 18 notification notices must be visible on all data intake points (web forms, landing pages, call scripts) detailing:
    1. What data is being collected.
    2. Purpose of collection.
    3. Whether supply is voluntary or mandatory.
    4. Specific identity of The Colandi Group (and client, if acting as Operator).
  • A current PAIA (Promotion of Access to Information Act) Manual and Privacy Policy must remain publicly accessible.

Condition 7: Security safeguards

  • Technical Controls: Multi-Factor Authentication (MFA) on all cloud workspaces, role-based access control (RBAC), end-to-end encryption for stored files and transit channels (TLS/SSL).
  • Physical Controls: Secure access controls at physical office locations (e.g., Durban Club Chambers suite), clean desk policies for BPO agents handling sensitive data.
  • Operator (Third-Party) Controls: Written Operator Contracts (Section 21) must be in place for any sub-processors (e.g., cloud platforms, email servers, call center tools) binding them to identical security standards.

Condition 8: Data subject participation

  • Individuals hold the right to request access to, correction of, or deletion of their personal information without charge.
  • Requests must be processed via the Information Officer within 30 days using standardized Form 1 (Objection) and Form 2 (Correction/Deletion).

3. Operational BPO Protocols & Direct Marketing Standard Operating Procedures

3.1 Cold contact & electronic marketing (Section 69 Compliance)

  1. Unsolicited Direct Marketing: Standard electronic communications (email, SMS, automated voice calls) to prospects with whom no prior transaction exists require Form 4 Consent prior to sending.
  2. Opt-Out Mechanism: Every outgoing commercial communication must feature an immediate, functional, cost-free “Unsubscribe” or “STOP” link/reply mechanism.
  3. Opt-Out Suppression Master List: Once an individual unsubscribes, their details must be automatically added to a centralized, permanent suppression list across all enterprise marketing platforms within 24 hours.

3.2 BPO operator responsibilities (Processing Client Data)

When receiving contact lists from enterprise clients:

  • Indemnity & Verification Protocol: Client must warrant in writing that data supplied has been lawfully acquired in strict compliance with POPIA prior to ingestion.
  • Data Isolation: Enterprise client databases must remain logically isolated within the cloud infrastructure—no blending of client databases.
  • Data Return/Destruction: Upon contract termination, all client PI must be securely purged or transferred back to the client, followed by an official Certificate of Destruction signed by the Information Officer.

4. Data breach incident response plan

Under Section 22 of POPIA, any suspected or confirmed breach (unauthorized access, loss, or leak of PI) triggers mandatory execution of the following workflow:

DATA BREACH INCIDENT RESPONSE WORKFLOW

1. Detection & Isolation: Immediately disconnect affected systems & alert IO

2. Risk Assessment: Determine severity, data type, & scope of impact

3. Regulatory Notification: Notify Information Regulator via Section 22 Form

4. Data Subject Notice: Notify affected individuals (unless law enforcement delays)

5. Remediation & Audit: Patch vulnerabilities, update controls, refresh training

Notification timelines & contents

  • Information Regulator: Notification must take place as soon as reasonably possible after discovery.
  • Content Requirements: Must detail the nature of the breach, measures taken to mitigate, potential consequences, and recommended mitigation steps for affected data subjects.

5. Implementation roadmap & checklist

  • Phase 1: Registration — Ensure Information Officer and Deputy IO appointments are officially registered on the Information Regulator e-Services portal.
  • Phase 2: Data Mapping Audit — Document all internal and external data flows across marketing, sales, HR, and client services.
  • Phase 3: Legal & Contractual Updates
    • Update website privacy notices and intake forms with explicit consent language.
    • Insert Section 21 Operator clauses into all third-party BPO service agreements.
    • Audit and refresh the company PAIA Manual.
  • Phase 4: Staff Training & Controls — Conduct mandatory POPIA operational training for all marketing agents and enterprise risk staff; enforce MFA and clean-desk policies.
  • Phase 5: Continuous Monitoring — Execute bi-annual internal compliance audits under the Enterprise Risk menu schedule.