POPIA SECTION 17 MANUAL • LAST UPDATED 10 JAN 2026 • INFO OFFICER +27 76 948 9154

POPIA Compliance Manual

How NextGrid Technologies (Pty) Ltd processes personal information as Responsible Party and Operator under Protection of Personal Information Act 4 of 2013. For SA SMEs 5-50 staff – M365 security, backup, 24/7 monitoring.

✓ PAIA Manual AvailableOn-site Pretoria, Midrand, Centurion, JHB | Remote SAR950 Check includes POPIA gap report
Information Officer & Contact – Section 17(1)
NextGrid Technologies (Pty) Ltd
Information Officer: Clem Chikanya
Physical & Postal Address
Pretoria, Gauteng, SA — On-site Pretoria, Midrand, Centurion, Johannesburg | Anywhere else - Remote, remote across SA. Postal: Same as physical. By appointment for on-site secure asset disposal, BitLocker verification, offboarding.
Reg No: [Your Reg No] • VAT: [Your VAT] • PAIA Manual available on request and at /privacy/

2. Responsible Party & Information Officer

Responsible Party: NextGrid Technologies (Pty) Ltd, Pretoria, Gauteng. We determine purpose and means for our own billing, CRM, support tickets, website leads.

Operator: When we manage your M365 tenant (emails, files, Teams, Intune), we act only on your instructions – ticket, call to +27 76 948 9154 logged, or email from authorized contact. MSA includes Sec 20 Operator clauses, confidentiality, Sec 19 security, breach notification within 24h, return/delete on termination.

Information Officer: Clem Chikanya – contact above. Deputy: Support Manager (same contact). Officer registered with Information Regulator, contact available during business hours 8am-5pm Mon-Fri, after-hours for breach.

3. Definitions (Plain English)

  • Personal Information: Anything that identifies you – name, email, phone, ID number, bank details, location, IP, device ID, etc.
  • Special Personal Info (Sec 26): Religious, health, biometric, criminal, etc – we don't collect except where required for employment (e.g., criminal check consent) – higher protection, DLP block on sharing external.
  • Data Subject: You, client contact, staff member whose info we process.
  • Processing: Collect, use, store, share, delete – everything we do with info.

4. Purpose & Lawful Basis (Sec 11)

We process personal info only for lawful purpose:

  • Contract (Sec 11(1)(b)): To deliver M365 licensing R290 / R450 Secure, hardware quote, R950 Health Check 2hr on-site, support, backup R45/user/mo.
  • Legitimate Interest (Sec 11(1)(f)): 24/7 monitoring (inbox rule creation, impossible travel), Secure Score reporting, POPIA gap report – to protect you and us from BEC, ransomware. You can object.
  • Legal Obligation (Sec 11(1)(c)): SARS eFiling 5yr retention, audit logs 1yr+ for Condition 8 Accountability, employment records.
  • Consent (Sec 11(1)(a)): Marketing – explicit opt-in checkbox not pre-ticked, or existing client opt-out for similar services. Every marketing message has who we are, +27 76 948 9154, why you got it, free opt-out.

5. Categories of Data Subjects & Information We Process

Clients (SMEs 5-50 staff): Contact name, company, phone +27 76 948 9154, email, M365 tenant ID, device serials, support tickets, invoices 7yr retention.

Website visitors: IP, browser, pages visited, form data (name, company, phone, email) for R950 Check booking, PDF download email capture (1 email/month). Stored in formsubmit.co + local backup, encrypted.

Suppliers / Operators: Microsoft (M365), Lenovo 360 Authorized 2026 hardware distributor, FortiGate, etc – only contact details, NDAs in place.

We do NOT: Sell personal info, use for automated decision-making with legal effect, or transfer to third parties for their marketing.

8. Security Measures (Sec 19) – Technical & Organisational

This is where we earn your trust – same controls from R950 Check that finds 4.2 critical issues avg, and from case studies:

  • Identity: MFA number matching for all, block legacy auth (found in 61% audits), Conditional Access SA only, impossible travel block 2-min alert, separate admin accounts, break-glass FIDO2.
  • Email: Safe Links click-time rewrite, Safe Attachments sandbox detonation, external banner [EXTERNAL] ON, DMARC p=reject + SPF + DKIM + anti-spoof + impersonation protection for CEO (stopped R87k fraud case study), inbox rule audit (18% have hidden Gmail rule).
  • Devices: BitLocker enforced, keys escrowed in Entra ID, Intune compliance (block personal devices), Defender tamper protection + ASR rules, 3yr warranty.
  • Backup: 3-2-1 immutable: production + NAS snapshots + cloud object lock 30+ days SA DC, real restore test monthly (not green tick), RPO <24h RTO <4h. OneDrive is NOT backup – delete on laptop = delete in cloud 30d later (case study law firm 2hr recovery).
  • Network: FortiGate + Mikrotik hardening, RDP 3389 blocked (found 34% audits), secure WiFi guest isolation, UPS load-shedding resilient.
  • Organisational: Staff NDAs, least privilege, quarterly POPIA training, offboarding checklist (wipe + access revoke + asset register), incident response plan with Regulator notification 72h if serious breach.

9. Your Rights – How to Request (Sec 23-25)

You have right to access, correct, delete, object, restrict, data portability. How:

  • Email info@nextgridtechnologies.co.za subject POPIA RIGHTS REQUEST or call +27 76 948 9154 – we verify ID (ID document redacted + proof of relationship), respond within 20 business days with outcome.
  • Form: Form 1 (Objection), Form 2 (Access/Correction/Deletion) available on Regulator website inforegulator.org.za and on request.
  • No fee for first request, reasonable fee for excessive (e.g., large export). We keep request log 5yrs for accountability.

13. Complaints – Internal First, Then Information Regulator

STEP 1 – INTERNAL (FREE)
  1. Email info@nextgridtechnologies.co.za subject POPIA COMPLAINT OR call +27 76 948 9154
  2. Include: name, relationship, description, dates, remedy (access, deletion, apology, process change), evidence (screenshots, no passwords).
  3. We acknowledge in 2 business days, outcome in 20 business days. Complex = interim update.
  4. We keep complaint file 5yrs.
Responsible: Clem Chikanya, Pretoria. Decision in writing with reasons.
STEP 2 – INFORMATION REGULATOR (SA)

If internal fails or you are unsatisfied, lodge complaint directly per Sec 74.

Email: complaints.IR@justice.gov.za / inforeg@justice.gov.za
Phone: 012 406 4818 / 012 406 4819
Physical: JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2017
Form: Form 5 – Complaint to Regulator
You have right to complain without retaliation. We will cooperate with Regulator and provide logs.
Need POPIA technical implementation that auditors trust?
We're not a law firm – we are technicians who make POPIA real: DLP for SA ID & bank accounts, retention labels for 5yr SARS rule, encryption, audit logs, MFA & Conditional Access. 47 SMEs in Pretoria region trust us. R950 Check includes POPIA gap report you can give your attorney.
Call +27 76 948 9154WhatsApp for POPIA PackBook R950 Check →
© Document: NextGrid Technologies (Pty) Ltd – Information Officer: Clem Chikanya, Pretoria • info@nextgridtechnologies.co.za • +27 76 948 9154 • Public and printable for your POPIA file.