2 Definitions
1. Data subject: The person to whom personal information relates;
2. POPIA: Refers to the Protection of Personal Information Act 4 of 2013;
3. GDPR: Refers to the General Data Protection Regulation (EU) 2016/679
4. Processing: any operation or activity or any set of operations, whether or not by
automatic means, concerning personal information, including:
a) the collection, receipt, recording, organisation, collation, storage, updating or
modification, retrieval, alteration, consultation or use.
b) dissemination by means of transmission, distribution or making available in any other
form; or merging, linking, as well as restriction, degradation, erasure or destruction of
information.
5. Records: any recorded information regardless of form or medium, including any of the
following;
(a) writing of material;
(b) information produced, recorded or stored digitally or Physically or any material
subsequently derived from information so produced, recorded or stored;
6. Responsible party: means a public or private body or any other person which, alone or
in conjunction with others determines the purpose of and means for processing personal
information.
7. Personal Information means information relating to an identifiable, living, natural
person, and where it is applicable, an identifiable, existing juristic person.
3 Objectives
• POPIA and GDPR requires consumer to be aware as to the manner in which their
personal information is used, protected, disclosed and destroyed.
• Saryx Engineering Group guarantees its commitment to protecting the consumer’s
privacy and ensuring that their personal information is used appropriately, transparently,
securely and in accordance with applicable laws.
• This Policy sets out the manner in which Saryx Engineering Group deals with the
consumer’s personal information and stipulating the purpose for which said information is
used.
The purpose of this policy is to enable Saryx Engineering Group to comply with;
a) Protection of Personal Information Act, 2013 (hereinafter POPIA Act)
b) General Data Protection Regulation (hereinafter GDPR)
c) Adhere to both Legislative requirements.