Privacy Disclosure Agreement Template for South Africa

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Privacy Disclosure Agreement?

The Privacy Disclosure Agreement is a crucial document required under South African data protection law, particularly the Protection of Personal Information Act (POPIA). This agreement should be implemented whenever an organization collects, processes, or shares personal information of data subjects. It serves as both a compliance tool and a transparency mechanism, demonstrating adherence to POPIA's requirements while informing data subjects about how their information will be handled. The document typically includes detailed information about data collection methods, processing purposes, security measures, data subject rights, and breach notification procedures. It's particularly important for organizations operating in South Africa or handling South African residents' personal information, as it helps ensure compliance with local privacy laws while building trust with data subjects.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

South Africa

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Privacy Disclosure Agreement

A Privacy Disclosure Agreement is a fundamental legal document that ensures your organization complies with South Africa's data protection laws while maintaining transparency with individuals whose personal information you handle. Under the Protection of Personal Information Act (POPIA), you are required to inform data subjects about how their personal information will be collected, processed, stored, and shared.

When do you need this document?

You need a Privacy Disclosure Agreement whenever your organization collects personal information from South African residents or processes such information within South Africa. This includes situations where you operate websites that collect user data, process employee information, engage third-party service providers who handle personal data, or share customer information with business partners. The agreement is particularly crucial when establishing relationships with data processors or operators who will handle personal information on your behalf. Financial institutions, healthcare providers, educational institutions, and e-commerce businesses frequently require these agreements to ensure POPIA compliance and maintain regulatory approval.

Key legal considerations

Your Privacy Disclosure Agreement must clearly define the roles and responsibilities of all parties involved in processing personal information. The document should specify whether you are acting as a responsible party (data controller) or operator (data processor), and outline the specific purposes for which personal information will be processed. You must include detailed descriptions of the types of personal information being collected, the lawful basis for processing under POPIA's eight conditions, and the security measures implemented to protect the data. The agreement should address data subject rights, including access, correction, and deletion rights, as well as procedures for handling data breaches and regulatory inquiries. Cross-border data transfer provisions are essential if information will be shared internationally, ensuring adequate protection levels are maintained.

Legal requirements in South Africa

Under POPIA, your Privacy Disclosure Agreement must comply with specific statutory requirements that came into effect in July 2021. The document must align with the eight conditions for lawful processing, including accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. You are required to register with the Information Regulator if you process personal information, and your agreement must reflect your registration details and compliance status. The agreement must specify retention periods for different categories of personal information and include procedures for secure disposal when retention periods expire. Additionally, you must ensure that any data sharing arrangements with third parties, whether domestic or international, maintain equivalent protection standards and include appropriate contractual safeguards as required by POPIA's transborder information flow provisions.

GOVERNING LAW

Applicable law

This Privacy Disclosure Agreement is drafted to comply with South Africa law. Key legislation includes:

Protection of Personal Information Act (POPIA) No. 4 of 2013: South Africa's primary data protection legislation that sets out the framework for how personal information must be collected, processed, stored, and shared. It establishes eight conditions for lawful processing of personal information and requires specific disclosures to data subjects.
Constitution of South Africa, Section 14: Establishes the fundamental right to privacy in South Africa's legal framework, including informational privacy rights. This forms the constitutional basis for privacy protection.
Consumer Protection Act No. 68 of 2008: Contains provisions relating to fair business practices and disclosure requirements, particularly regarding transparency in consumer agreements and the right to disclosure of information in plain and understandable language.
Electronic Communications and Transactions Act No. 25 of 2002: Governs electronic communications and transactions, including requirements for the collection, storage, and use of personal information obtained through electronic transactions.
National Health Act No. 61 of 2003: Contains specific provisions regarding the confidentiality of health information and the circumstances under which health-related personal information may be disclosed.
Promotion of Access to Information Act (PAIA) No. 2 of 2000: Gives effect to the constitutional right of access to information and intersects with privacy law by governing how information, including personal information, can be accessed and disclosed.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it