PROMOTION OF ACCESS TO INFORMATION MANUAL
Hersol Manufacturing Laboratories (Pty) Ltd
2006/020507/07
Prepared in terms of the requirements of the PROMOTION OF ACCESS TO INFORMATION ACT No. 2 of 2000
1. INTRODUCTION
The Promotion of Access to Information Act 2 of 2000 (“PAIA” or “the Act”) gives effect to the constitutional right of access to any information held by the state and any information that is held by another person and that is required for the exercise or protection of any rights. The Protection of Personal Information Act 2013 has amended the PAIA and also requires from private bodies to disclose certain information through the relevant organisation’s PAIA Manual.
Specifically, section 51(1) of the Act, read with the Protection of Personal Information Act of 2013, requires a private body to compile a manual that must contain information as specified and required by both PAIA and POPI. In addition, the PAIA manual must set out the formal procedure that a person must follow in order to request to view, update or delete personal information held by the private body.
In this context, a “private body” is defined as any natural person who carries or has carried on any trade, business or profession, but only in such capacity or any partnership which carries or has carried on any trade, business or profession or any former or existing juristic person (e.g. any company, close corporation or business trust).
This organisation falls within the definition of a “private body” and this Manual has been compiled in accordance with the said provisions and to fulfil the requirements of the Act.
In terms of the Act, where a request for information is made to a body, there is an obligation to provide the information, except where the Act expressly provides that the information may not be released. In this context, Section 9 of the Act recognises that access to information can be limited. In general the limitations relate to circumstances where such release would pose a threat to the protection of privacy, commercial confidentiality and the exercising of efficient governance.
Accordingly, this manual provides a reference to the records held and the process that needs to be adopted to access such records.
All requests for access to information (other than information that is available to the public) must be addressed to the Information Officer or Deputy Information Officers named in section 2 of this Manual.
2. BUSINESS AND CONTACT DETAILS
Name of Business: Hersol Manufacturing Laboratories (Pty) Ltd
Information Officer: Konrad de Beer
Postal Address: P O Box 85058, Emmarentia, 2029
Physical Address: 36 Madison Street, Jeppestown, Johannesburg, 2094
Phone Number: +27 11 614 6631 / 2
Email Address: az.oc.losreh@nimda
Website: www.hersol.co.za
Deputy Information Officer: Jacques de Necker
Phone Number: +27 11 614 6631 / 2
Email Address: az.oc.losreh@nseuqcaj
Deputy Information Officer: Lionel Huntley
Phone Number: +27 11 614 6631 / 2
Email Address: az.oc.losreh@lenoil
3. SECTION 51(1) OF THE PROMOTION OF ACCESS TO INFORMATION ACT (THE ACT)
3.1 The Act grants a requester access to records of a private body, if the record is required for the exercise or protection of any rights. If a public body lodges a request, the public body must be acting in the public interest.
3.2 Requests in terms of the Act must be made in accordance with the prescribed procedures, at the rates provided. The forms and tariff are dealt with in regulations 6 and 7 of the Act.
4. RECORDS THAT ARE HELD AT THE OFFICES OF THE BUSINESS
The following is a list of records that are held at the business’s office:
4.1 Administration
- Company registration
- Beneficial ownership
- VAT registration
- Relevant licenses
- Statutory returns
4.2 Human Resources
- Employment contracts
- Employee records
- Health and safety information
- Pension and provident fund records
- Personnel policies and procedures
- Statutory records
4.3 Operations
- Standard operating procedures
- Customer records
- Supplier records
- Technical agreements
- Commercial agreements
4.4 Finances
- Tax records
5. Processing of personal information
Purpose of processing
- Fulfilling statutory obligations in terms of applicable legislation
- Historical record keeping, research and recording statistics necessary for fulfilling your business objectives.
- Keeping of accounts and records
- Marketing and advertising
- Monitoring, maintaining and managing our contractual obligations to customers, clients, suppliers, service providers, employees, directors and other third parties
- Obtaining information necessary to provide contractually agreed services to a customers and clients
- Resolving and tracking complaints
- Staff administration
- Verifying information provided to us
Categories of Data Subjects
- Clients and client’s employees, representatives, agents, contractors and service providers
- Existing and former employees (including contractors, agents, temporary and casual employees)
- Suppliers and service providers and their respective authorised employees, representatives, agents, contractors and service providers of such suppliers and service providers
Categories of Personal Information processed
Natural Persons
- Name & Surname
- Physical and postal addresses
- Date of birth
- ID number
- Tax related information
- Medical, dental, mental and/or other healthcare related information
- Nationality
- Gender
- Race
- Confidential correspondence
- Email address
- Telephone number
- Next of kin
Juristic Persons
- Names of contact persons
- Name of Legal Entity
- Registration Number
- Physical and Postal address and contact details
- Financial information
- Founding documents
- Tax related information
- BBBEE information
Possible Recipients of Personal Information
- Auditors
- Debt collection and tracing agencies
- Employees of the organisation
- Employment and recruitment agencies
- Family, associates and representatives of the person whose personal information is processed
- Healthcare, social and welfare organisations
- Ombudsman and regulatory authorities
- Police / courts where necessary
- Regulatory, statutory and government bodies
- Suppliers, service providers, vendors, agents and representatives of such entities
- Third party verification agencies and credit bureau
General Description of Information Security Measures
- Up to date technology is employed to ensure the confidentiality, integrity and availability of the Personal Information under our care.
- Measures include:
- Acceptable usage of personal information
- Access control to personal information
- All third parties with whom any contract exists are required to ensure that appropriate security, privacy and confidentiality obligations are observed.
- Computer and network security including Firewalls, Virus protection software and update protocols
- Governance and regulatory compliance
- Information security and HR policies
- Investigating and reacting to security incidents.
- Access control
- Retention and disposal of information
- Secure communications
- Security in the outsourcing of any activities or functions through appropriate contracts
- Training of staff members