Global Fleet Solutions (“This company”) PROTECTION OF PERSONAL INFORMATION (POPI) MANUAL

This Privacy of Personal Information (POPI) Manual (“Manual”) outlines the policies and procedures adopted by Global Fleet Solutions (“GFS,” “we,” “us,” or “our”) to ensure compliance with the Protection of Personal Information Act (POPIA) and to protect the privacy of personal information in our possession or under our control.

Purpose
The purpose of this Manual is to:

  1. Outline the measures taken by GFS to comply with the principles and requirements of POPIA.
  2. Provide guidance to employees, contractors, and third parties on the collection, use, and protection of personal information.

Scope
This Manual applies to all personal information processed by GFS, including information collected from customers, employees, contractors, and other individuals.

Responsible Party
GFS is the responsible party for the processing of personal information and is responsible for ensuring compliance with POPIA and this Manual.

Principles of POPIA Compliance
GFS is committed to upholding the principles of POPIA, including:

  1. Accountability: We are responsible for ensuring compliance with POPIA and for implementing measures to protect personal information.
  2. Processing Limitation: We only collect and process personal information for lawful and specific purposes, and we do not process personal information in a manner that is incompatible with those purposes.
  3. Data Minimization: We only collect personal information that is adequate, relevant, and not excessive for the purposes for which it is collected.
  4. Information Quality: We take reasonable steps to ensure that personal information is accurate, complete, and up-to-date.
  5. Security Safeguards: We implement appropriate technical and organizational measures to protect personal information against loss, theft, unauthorized access, disclosure, alteration, or destruction.
  6. Openness: We are transparent about our data processing practices and provide individuals with information about how their personal information is processed.
  7. Individual Participation: We provide individuals with the right to access and correct their personal information and to object to its processing.
  8. Purpose Specification: We only process personal information for specified, explicit, and legitimate purposes and do not further process personal information in a manner incompatible with those purposes.
  9. Lawful Processing: We only process personal information lawfully and with the consent of the data subject or in accordance with other legal bases provided by POPIA.

Collection and Use of Personal Information
We collect and use personal information for the following purposes:

  1. Providing our services to customers.
  2. Managing employee and contractor relationships.
  3. Communicating with individuals.
  4. Compliance with legal obligations.
  5. Any other lawful purposes.

Security Measures
We implement the following security measures to protect personal information:

  1. Access controls to restrict access to personal information to authorized individuals.
  2. Encryption and pseudonymization of personal information where appropriate.
  3. Regular monitoring and testing of security controls.
  4. Employee training on data protection and security practices.
  5. Incident response procedures to address data breaches or security incidents.

Data Subject Rights
Individuals have the following rights regarding their personal information:

  1. Right to access: Individuals have the right to request access to their personal information and to receive a copy of the information we hold about them.
  2. Right to rectification: Individuals have the right to request the correction of inaccurate or incomplete personal information.
  3. Right to erasure: Individuals have the right to request the deletion of their personal information under certain circumstances.
  4. Right to object: Individuals have the right to object to the processing of their personal information for direct marketing purposes or on grounds relating to their particular situation.
  5. Right to data portability: Individuals have the right to receive their personal information in a structured, commonly used, and machine-readable format and to transmit that information to another controller.
  6. Right to restriction of processing: Individuals have the right to request the restriction of processing of their personal information under certain circumstances.

Data Breach Notification
In the event of a data breach involving personal information, GFS will promptly investigate the breach and take appropriate measures to mitigate the risk to affected individuals. We will also notify the relevant regulatory authorities and affected individuals in accordance with legal requirements.

Review and Revision
This Manual will be reviewed and updated as necessary to ensure compliance with POPIA and changes in our business practices. Employees and other relevant stakeholders will be notified of any changes to this Manual.

Contact Information
If you have any questions or concerns about our privacy practices or this Manual, please contact us at sales@globalfleetsolutions.co.za