PROTECTION OF PERSONAL INFORMATION (POPI)
PROMOTION OF ACCESS TO INFORMATION ACT
SECTION 51 MANUAL
OFFICIAL GUIDELINES
For:PENCHANT FINE JEWELLERY (PTY) LTD
(“THE COMPANY”)
Registration # 2025 / 489392 / 07
Manual revision date: 30 June 2026
TABLE OF CONTENTS
INTRODUCTION.. 4
DEFINITIONS. 4
OVERVIEW OF THE COMPANY. 5
CONTACT DETAILS OF INFORMATION OFFICER – SECTION 51(1)(a). 6
GUIDE TO PAIA AND POPIA – SECTION 51(1)(b). 6
AUTOMATICALLY AVAILABLE RECORDS – SECTION 51(1)(c). 6
RECORDS AVAILABLE IN TERMS OF LEGISLATION – SECTION 51(1)(d). 7
CATEGORIES OF RECORDS HELD AND SUBJECT TO REQUEST. 8
PROCESSING OF PERSONAL INFORMATION IN TERMS OF POPIA.. 10
ACCESS: PROCEDURE AVAILABLE AND FEES. 13
DECISION ON REQUEST – SECTION 56. 13
AVAILABILITY. 14
FEES. 15
POLICY REVISION.. 15
INTRODUCTION
This Manual has been prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000 (PAIA), as amended, and should be read together with the Protection of Personal Information Act, 4 of 2013 (POPIA). It aims to facilitate a Request for access to a Record held by a private body where such access is required for the exercise or protection of any rights.
DEFINITIONS
Unless the context indicates otherwise, the following terms shall have the meanings assigned to them hereunder, namely –
- “Act” means the Promotion of Access to Information Act, Act 2 of 2000, as amended from time to time.
- “Company” means PENCHANT FINE JEWELLERY (PTY) LTDas more fully described in the overview hereunder.
- “Information Officer” means the person acting on behalf of the Company and discharging the duties and responsibilities assigned to the head of the Company by the Act. The Information Officer is duly authorised to act as such and such authorisation has been confirmed by the “head” of the Company in writing:
- Manual” means this manual published in compliance with Section 51 of the Act.
- “Record” means any recorded information, regardless of form or medium, which is in the Possession or under the control of the Company, irrespective of whether or not the Company created it.
- “Request” means a request for access to a Record of the Company.
- “Requestor” means any person, including a public body or an official thereof, making a Request for access to a Record of the Company and includes any person acting on behalf of that person; and
- “Regulator” means the Information Regulator established in terms of section 39 of POPIA, which is empowered to monitor and enforce compliance with PAIA and POPIA.
- “Consent” means any voluntary, specific and informed expression of will in terms of which a data subject agrees to the processing of personal information relating to him, her or it.
- “Special Personal Information” has the meaning assigned to it in POPIA and includes, where applicable, information relating to religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour.
- “Operator” means a person who processes personal information for the Company in terms of a contract or mandate, without coming under the direct authority of the Company.
- “Responsible Party” means the Company where it determines the purpose of and means for processing personal information.
- “Processing” means any operation or activity concerning personal information, including collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, distribution, merging, restriction, erasure or destruction.
- “POPIA” means the Protection of Personal Information Act, 4 of 2013, as amended from time to time.
- “Personal Information” means information relating to an identifiable natural or juristic person as defined in POPIA.
- “Data Subject” means the person to whom personal information relates.
- Unless a contrary intention appears, words signifying:
- the singular includes the plural and vice-versa.
- any one gender includes the other genders and vice versa; and
- natural persons include juristic persons.
Unless otherwise stated, terms defined in the Act shall have the same meaning in this Manual.
OVERVIEW OF THE COMPANY
PENCHANT FINE JEWELLERY (PTY) LTD is a Private Company incorporated by the company laws of South Africa and offers bespoke jewellery designs, custom-made pieces, revamping, remodelling, plating, polishing, engraving and custom designs.
CONTACT DETAILS OF INFORMATION OFFICER – SECTION 51(1)a
The Managing Member of the Company, as head of the closed corporation, has delegated his powers to the Information Officer, whose details appear hereunder, to deal with all matters in connection with Requests for Information on the Company’s behalf and to ensure compliance with the Act.
INFORMATION OFFICER: JACKIE HAHN | IDENTITY NUMBER: 860128 0037 08 3
PHYSICAL ADDRESS: 62 HUGUENOT STREET, FRANSCHHOEK, 7690,WESTERN CAPE, REPUBLIC OF SOUTH AFRICA
EMAIL: sales@penchantdesign.com
WEBSITE: https://penchantdesign.com
GUIDE TO PAIA AND POPIA (SECTION 51(1)(b) – READ WITH SECTION 10 OF PAIA)
The Information Regulator has compiled and made available a Guide on how to use PAIA and how to exercise rights under PAIA and POPIA. The Guide may be obtained from the Information Regulator and from the Information Regulator website.
The Information Regulator can be contacted directly at:
- The Information Regulator: PAIA and POPIA enquiries
- Website: https://inforegulator.org.za/
- PAIA Forms and Guide: https://inforegulator.org.za/paia-forms/ and https://inforegulator.org.za/paia-guidelines/
- Complaints and compliance services are available through the Information Regulator and its eServices portal.
AUTOMATICALLY AVAILABLE RECORDS WITHOUT HAVING TO REQUEST ACCESS – SECTION 51(1)(c)
The records below are automatically available without a person having to request access in terms of PAIA, while the web page https://penchantdesign.com/ is accessible to anyone who has access to the Internet – with the following significant categories of information:
- Brands
- Company info
- Corporate Info
- Corporate Profile
- Product and promotional brochures/pamphlets
- News and marketing information
- Corporate communications
- Other literature intended for public viewing.
RECORDS AVAILABLE IN TERMS OF LEGISLATION – SECTION 51(1)(d) [examples]
The following legislation keeps records:
- Basic Conditions of Employment Act, 1997
- Broad-Based Black Economic Empowerment Act, 2003
- Businesses Act, 1991 and Companies Act, 2008
- Consumer Protection Act, 2008
- Compensation for Occupational Injuries and Diseases Act, 1993
- Copyright Act, 1978
- Deeds Registries Act, 1937
- Electronic Communications and Transactions Act, 2002
- Employment Equity Act, 1998
- Financial Markets Act, 2012
- Foodstuffs, Cosmetics and Disinfectants Act, 1972
- Harmful Business Practices Act, 1999
- Immigration Act, 2002
- Income Tax Act, 1962
- Labour Relations Act, 1995
- Long Term Insurance Act, 1998
- Medical Schemes Act, 1956
- Occupational Health and Safety Act, 1993
- Pension Funds Act, 24 of 1956
- Prevention of Organised Crime Act, 1998
- Protected Disclosures Act, 2000
- Securities Services Act, 2004
- Short Term Insurance Act, 1998
- Skills Development Act, 1998
- Skills Development Levies Act, 1999
- Trademarks Act, 1993
- Unemployment Insurance Act, 2001
- Value Added Tax Act, 1991
- Protection of Personal Information Act, 2013
CATEGORIES OF RECORDS HELD AND SUBJECT TO REQUEST
Statutory and Legal
- Statutory registers
- Annual reports
- Statutory Records & returns, including incorporation documents, memorandum of incorporation, and share register.
- Minutes of meetings
- board
- board and statutory committees
- management committees
- Contractual and legal agreements
- Intellectual property:
- Licenses
- Copyrights & designs
- Health and safety records
Human Resources
- HR policies & procedures
- Employment equity plan and report
- Skills development plan and report
- Employee Records
- Benefits
- IR disciplinary and grievance procedures and hearings,
- Union negotiation Records
- Incentive scheme rules
Administration, Finance & Accounting:
- Accounting Records
- Auditors, or Accountant’s reports
- Tax returns
- VAT returns
- Policies & procedures
Retirement Fund
- Pension and provident fund rules
- Correspondence
- Statutory Records and Returns.
Insurance
- Policies, including coverage, limits, and insurers.
- Claim Records
Information technology
- Hardware
- Software packages
- Licenses
- IT policies and procedures
- Operating systems
Sales and Marketing
- Customer Records
- Credit application forms
- Statements of account
- Terms & conditions
- Marketing material and media releases: brochures, newsletters, and advertising materials
- Customer communication preferences and marketing campaign records
- Direct marketing consent records, opt-out records and suppression lists
Assets
- Land and building register.
- Fixed assets register
- Title deeds
- Leases
Operational information
This information is defined as information needed in the day-to-day running of the organization:
- Internal telephone record,
- address lists,
- company policies,
- company procedures
- human resource manual,
- administration manuals,
- industry-related statistical data
- customer database, historical customer histories,
- management information reports,
PROCESSING OF PERSONAL INFORMATION IN TERMS OF POPIA
This section records the Company’s processing of personal information for purposes of section 51 of PAIA, read with POPIA. Penchant Design CC processes personal information only where there is a lawful basis to do so and where such processing is connected to a legitimate business, contractual, operational, legal, security or customer-service purpose.
Purpose of Processing Personal Information
- To create, quote for, design, manufacture, remodel, repair, plate, polish, engrave, deliver and administer bespoke jewellery products and related services.
- To identify and communicate with clients, prospective clients, suppliers, service providers, employees, contractors and authorised representatives.
- To process orders, invoices, payments, deposits, refunds, statements, debtor records, supplier payments, accounting records and statutory tax records.
- To manage employment, recruitment, payroll, occupational health and safety, leave, performance, disciplinary and other human-resource obligations, where applicable.
- To manage supplier due diligence, procurement, service-level arrangements, insurance, courier arrangements, website enquiries, customer relationship management and general business administration.
- To comply with applicable laws, regulatory obligations, court orders, law-enforcement requests and lawful requests from public bodies or regulators.
- To send direct marketing, promotional, newsletter or customer relationship communications only where permitted by POPIA and applicable law.
- To secure premises, systems, website, e-mail accounts, records, devices, stock, jewellery, valuables and other business assets.
Categories of Data Subjects and Personal Information Processed
- Clients and prospective clients: names, identity or passport details where required, contact details, addresses, order histories, jewellery preferences, design specifications, measurements, photographs or images supplied for design purposes, payment records, communication records and customer-service records.
- Suppliers, service providers and contractors: names, contact details, company information, registration details, tax and VAT information, banking details, contracts, delivery records, invoices and correspondence.
- Employees, applicants and members, where applicable: identification details, contact details, employment history, payroll information, tax information, banking details, leave records, performance records, disciplinary records, training records, occupational health and safety records and next-of-kin details.
- Website users and electronic communication recipients: online identifiers, enquiry details, e-mail addresses, communication preferences, consent records, unsubscribe records, cookies or similar technical data where used, and security logs.
- Regulators, public bodies and other authorised persons: details required to comply with statutory, regulatory, legal, accounting, tax, labour, consumer-protection, safety and access-to-information obligations.
Recipients or Categories of Recipients to Whom Personal Information May Be Disclosed
- Authorised employees, members, managers, representatives and operators of the Company who require access for legitimate business purposes.
- Accountants, auditors, payroll administrators, tax practitioners, banks, insurers, legal advisers, labour consultants and other professional advisers.
- Suppliers, manufacturing partners, repairers, couriers, delivery service providers, payment processors, website hosts, e-mail providers, cloud service providers, IT support providers, CRM or marketing platforms and other contracted service providers.
- Public bodies, regulators, law-enforcement authorities, courts, tribunals or other authorised persons where disclosure is required or permitted by law.
Direct Marketing Rules
- The Company may process personal information for direct marketing only where this is lawful, fair, transparent and consistent with POPIA, including the Information Regulator’s guidance on direct marketing.
- Unsolicited electronic direct marketing will be sent only where the data subject has given consent, or where the data subject is an existing customer whose contact details were obtained in the context of a sale, the marketing relates to the Company’s own similar products or services, and the data subject is given a clear opportunity to opt out when the information is collected and in every subsequent marketing communication.
- Where consent is required, the Company should keep a record of the consent relied on, including the date, manner, scope and source of consent, and should use the prescribed consent form or an equivalent consent mechanism where appropriate.
- Each direct marketing communication should identify the sender, provide valid contact details and include a simple, effective and no-cost or low-cost opt-out mechanism.
- The Company must honour objections, withdrawals of consent and unsubscribe requests promptly and must maintain suppression or opt-out records to prevent further marketing to persons who have objected or unsubscribed.
- For non-electronic direct marketing, the Company will rely on a lawful basis under POPIA, respect objections under section 11(3), and ensure that any marketing is not excessive, misleading or contrary to the reasonable expectations of the data subject.
Planned Cross-Border or International Transfers of Personal Information
- The Company may transfer, store or provide access to personal information outside the Republic of South Africa where it uses foreign-hosted or internationally operated e-mail, website, cloud storage, accounting, payment, courier, CRM, social-media, marketing, security or IT-support platforms, or where an international supplier or service provider is involved in a transaction.
- Any cross-border transfer must comply with section 72 of POPIA. The Company will take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, or that another permitted ground applies, such as data subject consent, contractual necessity, performance of a contract in the data subject’s interest, or transfer for the benefit of the data subject where consent is not reasonably practicable.
- The Company should review material service-provider arrangements, cloud platforms and marketing platforms to confirm whether personal information may be transferred outside South Africa and whether appropriate contractual, security and confidentiality safeguards are in place.
Information Security Measures
- The Company applies reasonable technical and organisational measures appropriate to the nature of its operations and the personal information processed.
- Measures may include access control, password protection, user permissions, confidentiality undertakings, secure filing, secure disposal, backups, anti-virus and malware protection, software updates, secure e-mail practices, staff awareness, supplier confidentiality obligations and incident-response procedures.
- Where an operator processes personal information on behalf of the Company, the Company should require the operator to process the information only with the Company’s knowledge or authorisation and to maintain appropriate confidentiality and security safeguards.
Data Subject Rights
- A data subject may request access to personal information held by the Company, request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained personal information, object to processing where POPIA allows such objection, withdraw consent where processing is based on consent, and lodge a complaint with the Information Regulator.
- Requests relating to personal information should be directed to the Information Officer at the contact details set out in this Manual.
ACCESS: PROCEDURE AVAILABLE AND FEES
How to Request a Record (Section 53)
- Requests for access to Records must be made to the Information Officer in writing at the physical address or electronic mail address referred to in this Manual. A requester should use the prescribed Form 2: Request for Access to Record, available from the Information Regulator. Failure to provide sufficient information or to use the prescribed form may result in the Request being delayed or refused.
- A Request for access to a Record may be subject to the prescribed request fee and access fees determined under PAIA and the applicable Regulations. The prescribed fee structure published by the Information Regulator applies and may be amended from time to time.
- The Requestor must provide sufficient detail on the Request form to enable the Information Officer to identify the Record as well as the Requestor’s identification, which is to be accompanied by positive proof of identification.
- The Requestor must indicate which form of access is required and if he/she wishes to be informed of the decision on the Request in any other manner, to state the necessary particulars to be so informed.
- Access is not automatic. The Requestor must therefore identify the right he/she is seeking to exercise or protect and provide an explanation as to why the requested Record is required for the exercise or protection of that right.
- If a Request is made on behalf of a person, the Requestor must then submit proof, to the satisfaction of the Information Officer, of his/her authority to make the Request. Failure to do so will result in the Request being rejected.
DECISION ON REQUEST – SECTION 56
- The Requestor will be notified, within 30 days, in the manner indicated by him/her of the outcome of his/her Request, alternatively whether an extension not exceeding 30 days is required to deal with the Request.
- If the access request is granted a further access fee must be paid for the reproduction as well as the search and preparation of the Records and for any time that has exceeded the prescribed hours to search and prepare the Record for disclosure. Access will be withheld until the Requestor has made payment of the applicable fee(s).
- If the access request is refused, reasons for the refusal will be provided and the Requestor will be advised that he/she/they may lodge a complaint with the Information Regulator or apply to a court against the refusal of the Request, as well as the procedure for doing so.
- The Requestor may lodge a complaint with the Information Regulator or an application to court against a decision, deemed refusal, fee, or other PAIA-related matter where PAIA permits such remedy.
AVAILABILITY
This Manual is available at the Company’s offices: 62 HUGUENOT STREET, FRANSCHHOEK, 7690,WESTERN CAPE, REPUBLIC OF SOUTH AFRICA during office hours; 09H00 till 16H00, Monday to Friday, excluding Public Holidays.
Access to the office is dependent on government pandemic (or similar) lockdown measures (COVID, Natural Disasters, Strikes and demonstrations, Civil unrest, and other eventful considerations.
- If the access request is granted, a further access fee must be paid for the reproduction as well as the search and preparation of the Records and for any time that has exceeded the prescribed hours to search and prepare the Record for disclosure. Access will be withheld until the Requestor has made payment of the applicable fee(s).
- If the access request is refused, reasons for the refusal will be provided and the Requestor will be advised that he/she/they may lodge a complaint with the Information Regulator or apply to a court against the refusal of the Request, as well as the procedure for doing so.
- The Requestor may lodge a complaint with the Information Regulator or an application to court against a decision, deemed refusal, fee, or other PAIA-related matter where PAIA permits such remedy.
FEES
The fees payable in respect of access to Records are the prescribed PAIA fees applicable to private bodies, as published and amended from time to time by the Information Regulator. As at the current revision, the prescribed private-body request fee is R140.00, and reproduction, search, preparation, deposit, postage, e-mail or electronic-transfer fees may be charged where permitted by PAIA and the Regulations.
- a prescribed Request Fee, currently R140.00 for private bodies, where payable;
- prescribed reproduction, search and preparation fees, where applicable;
- a deposit may be required where the search and preparation time exceeds the prescribed threshold; and
- postage, courier, e-mail, cloud storage or other electronic-transfer costs may be charged at actual expense, where applicable.
POLICY INCEPTION
Date: 01 July 2020
POLICY REVISION
Date: 30 June 2026