Pricing Features Resources
Login Register
Pricing Features Resources
Login Register
Back to Legal Hub
POPIA S21 OPERATOR • S72 ADEQUACY SAFEGUARDS

Data Processing Agreement (DPA)

Doccu Statutory Policy • Last Updated: September 2026 • Jurisdiction: Republic of South Africa

Table of Contents

1. Roles of Parties & Statutory Basis 2. Section 21 Operator Obligations 3. Technical & Organisational Measures (TOMs) 4. 36-Hour Security Compromise Notification 5. Sub-processor Governance & Directory 6. Audits & SETA Verification Assistance 7. 30-Day Grace, Data Return & Purge

1. Roles of the Parties & Statutory Basis

This Data Processing Agreement ("DPA") governs the processing of personal information by Doccu on behalf of the Customer in connection with the Doccu service.

Under the Protection of Personal Information Act No. 4 of 2013 ("POPIA"):

  • The Customer is the Responsible Party (determining the purpose and means of processing student, trainer, and sponsor personal data).
  • Doccu acts strictly as an Operator (processing personal information on behalf of and under the mandate of the Responsible Party).

2. Section 21 Operator Obligations

In accordance with Section 21 of POPIA, Doccu covenants and warrants that:

  • It shall process Customer personal information solely on documented instructions from the Customer, including regarding transfers outside of South Africa.
  • All personnel authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • It shall establish and maintain the security measures required in terms of Section 19 of POPIA to prevent loss, damage, or unauthorized destruction or access.

3. Technical & Organisational Measures (TOMs)

Doccu maintains industry-leading Technical and Organisational Measures ("TOMs") to ensure a level of security appropriate to the risk of processing learnership records:

Cryptographic Data Protection

AES-256 encryption at rest for all stored PDFs and attachments; TLS 1.3 transit encryption; SHA-256 cryptographic chaining on all submission audit events.

Access Control & Authentication

Mandatory administrator Two-Factor Authentication (2FA), role-based privilege tiers (Admin, Editor, Viewer), and automated session invalidation.

Vulnerability & Application Security

Automated DAST/SAST vulnerability scans (Aikido Security), real-time crash diagnostics (Sentry), and hardened perimeter firewalls.

4. 36-Hour Security Compromise Notification

Doccu will notify the Customer's designated administrative contact without undue delay and in any event within 36 hours after becoming aware of any confirmed security compromise involving Customer Personal Information in terms of Section 22 of POPIA.

5. Sub-processor Governance & Directory

Customer grants general written authorization to Doccu to engage third-party sub-processors. Doccu maintains an up-to-date catalog of approved sub-processors in our public Sub-processors Directory. Doccu imposes data protection obligations on every sub-processor no less protective than those in this DPA.

6. Audits & SETA Verification Assistance

Doccu provides comprehensive in-app tooling, including cryptographic Master Audit Trails, exportable ZIP packages, and SOC 2 / POPIA security reports to assist Customers during statutory audits conducted by SETA quality assurance verifiers.

7. 30-Day Grace Period, Data Return & Purge

Upon service termination, Customer enters a 30-day read-only grace period to export all completed agreements and audit certificates. After 30 days, Doccu irrevocably purges Customer data from production systems, providing written confirmation of destruction upon request.

Legal Hub Terms of Service Privacy Policy Data Processing Agreement Sub-processors
© 2026 Doccu • Republic of South Africa