Pricing Features Resources
Login Register
Pricing Features Resources
Login Register
Back to Legal Hub
POPIA 8 CONDITIONS • JURISTIC PERSON SCOPE

Privacy Policy

Doccu Statutory Policy • Last Updated: September 2026 • Jurisdiction: Republic of South Africa

Table of Contents

1. POPIA Framework & Statutory Scope 2. Protection of Natural & Juristic Persons 3. The Eight Conditions for Lawful Processing 4. Statutory Information Officer Mandate 5. PAIA Form 2 Subject Access Requests 6. Cross-Border Transfers & Section 72 7. Section 22 Incident & Breach Notification

1. POPIA Statutory Framework & Scope

Doccu is committed to upholding the privacy and constitutional rights of all individuals and corporate entities interacting with our platform in accordance with the Protection of Personal Information Act No. 4 of 2013 ("POPIA") and the Promotion of Access to Information Act No. 2 of 2000 ("PAIA") of South Africa.

2. Protection of Natural and Juristic Persons

In South African law, POPIA extends data privacy protections to both living natural persons and identifiable juristic persons (including registered private companies, close corporations, educational trusts, and non-profit SDPs). Doccu applies strict confidentiality and encryption controls across all personal information, whether belonging to individual learners, corporate employer sponsors, or training academies.

3. Adherence to the Eight Conditions for Lawful Processing

Doccu strictly implements and enforces the 8 Conditions for Lawful Processing set forth in Chapter 3 of POPIA:

Condition 1: Accountability

We take proactive statutory responsibility for compliance with all conditions across all platform subsystems.

Condition 2: Processing Limitation

Information is processed lawfully with verifiable consent, strictly limited to what is adequate, relevant, and not excessive.

Condition 3: Purpose Specification

Personal data is collected for explicit, defined educational, learnership administration, and signing verification purposes.

Condition 4: Further Processing Limitation

Secondary processing is restricted to activities strictly compatible with the original learnership signing intent.

Condition 5: Information Quality

We provide self-service tooling for customers and signatories to maintain accurate, up-to-date, and complete records.

Condition 6: Openness & Transparency

We maintain registered Information Officer documentation and clear privacy notifications prior to capturing signatures.

Condition 7: Security Safeguards

Technical and Organisational Measures (TOMs), AES-256 encryption at rest, TLS 1.3 in transit, and immutable Merkle audit logging.

Condition 8: Data Subject Participation

Full statutory rights to confirm processing, access copies of personal records, and request correction or deletion.

4. Statutory Information Officer Mandate

Doccu has designated and registered an official Information Officer with the Information Regulator of South Africa in terms of Section 55 of POPIA. For inquiries, regulatory filings, or complaints:

Information Officer: Legal & Compliance Office

Email: legal@doccu.co.za

Physical Address: Gauteng, Republic of South Africa

Standard Response SLA: Under 24 Business Hours

5. PAIA Form 2 Subject Access Requests

Data subjects may exercise their right to request access to their personal records held by Doccu using Form 2 (Request for Access to Record) under the Promotion of Access to Information Act (PAIA). Requests should be submitted directly to legal@doccu.co.za with certified proof of identity.

6. Cross-Border Data Transfers & Section 72 Adequacy

All primary application databases, user credentials, and submission metadata are hosted 100% in-country within South African data centres (xneelo). Encrypted document binaries and PDF artifacts are stored on Cloudflare R2 located within the European Union under Section 72(1)(a) adequacy safeguards and binding contractual commitments ensuring GDPR-level data protection.

7. Section 22 Incident & Breach Notification Protocols

In the unlikely event of reasonable suspicion or confirmation that personal information has been accessed or acquired by an unauthorized person, Doccu will notify the Information Regulator and affected customers within 36 hours of confirmation, in compliance with Section 22 of POPIA.

Legal Hub Terms of Service Privacy Policy Data Processing Agreement Sub-processors
© 2026 Doccu • Republic of South Africa