POPIA Policy

Last updated: 15 April 2026

1. Introduction

The Protection of Personal Information Act, 2013 (Act 4 of 2013) ("POPIA") governs how personal information is collected, used, stored, and shared in South Africa. StaffGrid SA is committed to full compliance with POPIA and has implemented this policy to ensure that the personal information of all data subjects — including candidates, temporary workers, agency staff, and client contacts — is processed lawfully and responsibly.

2. Definitions

3. Information Officer

StaffGrid SA has designated an Information Officer responsible for ensuring compliance with POPIA. Enquiries related to data protection can be directed to:

4. Conditions for Lawful Processing

StaffGrid processes personal information in accordance with the eight conditions for lawful processing set out in POPIA:

4.1 Accountability

StaffGrid takes responsibility for complying with POPIA and ensures that all processing of personal information is carried out in accordance with this policy and the Act.

4.2 Processing Limitation

We only collect personal information that is necessary for the purposes of providing our services. Information is collected directly from data subjects or from the agency that manages their records, with appropriate consent.

4.3 Purpose Specification

Personal information is collected for specific, defined purposes:

Personal information will not be processed for purposes incompatible with those listed above without obtaining further consent.

4.4 Further Processing Limitation

Personal information will not be processed for a secondary purpose unless that purpose is compatible with the original purpose of collection, or where further consent has been obtained.

4.5 Information Quality

We take reasonable steps to ensure that personal information is complete, accurate, and up to date. Data subjects and agencies can update information through the Platform at any time.

4.6 Openness

This policy, together with our Privacy Policy, provides clear and accessible information about how we process personal information. Data subjects can request details about what information we hold.

4.7 Security Safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, or unlawful processing. These include:

4.8 Data Subject Participation

Data subjects have the right to access, correct, and request deletion of their personal information, subject to legal retention requirements.

5. Consent Management

StaffGrid includes built-in POPIA consent tracking for candidates. Agencies are responsible for obtaining and recording consent from data subjects before entering their personal information into the Platform. The Platform tracks:

6. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data Type Retention Period
Financial records (payslips, invoices, tax data) 5 years (Tax Administration Act, Companies Act)
Audit logs 2 years
Inactive candidate data Reviewed after 12 months of inactivity
Active candidate and worker data For the duration of the agency's account

7. Inactive Candidate Review

StaffGrid automatically flags candidates who have had no placement activity for 12 months. Agencies are notified and can choose to:

8. Special Personal Information

POPIA defines certain categories as "special personal information" (e.g., race, health, biometric data). StaffGrid does not require the collection of special personal information. If agencies choose to store such information, they do so at their own responsibility and must ensure they have a lawful basis under Section 26 or 27 of POPIA.

9. Cross-Border Transfers

StaffGrid is designed for use within South Africa. If personal information is transferred outside South Africa (for example, through hosting infrastructure), we ensure that the recipient country provides an adequate level of protection, or that appropriate safeguards are in place as required by Section 72 of POPIA.

10. Data Breach Notification

In the event of a data breach that compromises personal information, StaffGrid will:

11. Rights of Data Subjects

Under POPIA, data subjects have the following rights:

12. Information Regulator

The Information Regulator is the independent body established under POPIA to oversee data protection compliance in South Africa. Complaints can be lodged at:

13. Changes to This Policy

This POPIA Policy may be updated from time to time to reflect changes in legislation or our practices. Material changes will be communicated via email or a notice on the Platform.

14. Contact Us

For any enquiries relating to this POPIA Policy or to exercise your data subject rights, contact us at: