Privacy Policy
1. Purpose and Introduction
This Privacy Policy explains how NIL Data Africa (Pty) Ltd collects, processes, stores, shares, and protects personal data. NIL Data Africa serves a diverse, internationally engaged audience and is committed to safeguarding personal information in accordance with internationally recognized privacy principles and applicable legal requirements.
This policy is designed to be clear, practical, and transparent. It reflects how personal data is handled throughout an individual’s or organization’s engagement with NIL Data Africa, whether through our programs, services, digital platforms, or commercial relationships. It sets accurate expectations for clients, delegates, partners, and other stakeholders.
2. Scope
This policy applies to all personal data collected and processed within the NIL Data Africa ecosystem. It covers, without limitation:
- Prospective and enrolled delegates across all programs and short courses
- Partner organizations, resellers, and sponsors
- Service providers and subcontractors
- Website visitors and digital channel users
- Clients and certification bodies
This policy applies regardless of the geographic location of the data subject.
3. Regulatory Alignment
NIL Data Africa operates in alignment with applicable data protection laws, frameworks, and standards, including:
- Protection of Personal Information Act (POPIA)
- General Data Protection Regulation (GDPR)
This alignment supports consistent privacy practices while accommodating jurisdiction-specific requirements where applicable.
4. Key Terms and Acronyms
Term (Acronym) | Definition |
NIL Data Africa | NIL Data Africa (Pty) Ltd, acting as the data controller and service operator. |
Data Subject | An identifiable individual whose personal data is collected or processed. |
Data Processor | A third party that processes personal data on behalf of NIL Data Africa. |
Personal Data | Information relating to an identified or identifiable individual. |
Standard Contractual Clauses (SCCs) | Legal mechanisms used to safeguard international data transfers. |
POPIA | Protection of Personal Information Act (South Africa, Act 4 of 2013). |
GDPR | General Data Protection Regulation (European Union, 2016/679). |
5. Lawful Basis for Processing
NIL Data Africa processes personal data only where a lawful basis exists. Depending on the context, applicable bases include:
- Contractual Necessity: To deliver programs, services, assessments, and client support.
- Legal Obligation: To meet regulatory, audit, accreditation, and verification requirements.
- Legitimate Interests: To support program integrity, quality assurance, reporting, fraud prevention, and operational effectiveness, where such interests do not override the rights of data subjects.
- Consent: Where required by law, consent is obtained in accordance with applicable requirements and may be withdrawn, subject to any mandatory legal or retention obligations.
6. Data Collection and Management
NIL Data Africa collects personal data necessary to operate, administer, and continuously improve its programs and services. This includes, where applicable:
- Full name and contact details
- Demographic and eligibility information
- Assessment results and learning progress
- Certification, verification, and completion records
- Program participation and operational data
- Website interaction and digital channel analytics
- Commercial and transactional records
Personal data is processed for onboarding, service delivery, certification access, program administration, quality assurance, marketing communications (where consent applies), and compliance purposes.
6.1 Data Architecture
Personal data is processed using a secure, cloud-based architecture. Access to personal data is limited to authorized individuals based on role and necessity. NIL Data Africa applies access controls and conducts periodic reviews to ensure data is handled appropriately across its systems.
NIL Data Africa does not sell personal data and does not permit processors to use personal data for their own independent purposes.
7. Data Retention, Archival, and the Right to Erasure
NIL Data Africa applies a defined data lifecycle that balances individual privacy rights with legal and operational obligations:
- Active Period: Personal data is retained for the duration of an active engagement or program participation.
- Mandatory Audit Retention: Upon completion or termination of engagement, relevant personal data is retained for a minimum of five (5) years to support qualification verification, audits, and partner obligations.
- Right to Be Forgotten: Data subjects may request deletion of their personal data. Where mandatory retention obligations apply, immediate erasure may not be possible, and this will be communicated to the data subject.
- Anonymization Protocol: Where lawful and appropriate, personal data will be anonymized by permanently removing identifiable elements, preserving operational traceability without retaining personal identifiers.
8. Data Subject Rights
Subject to applicable law and mandatory retention requirements, data subjects may exercise the following rights:
- Right of access to personal data held by NIL Data Africa
- Right to rectification of inaccurate or incomplete data
- Right to restriction of processing in certain circumstances
- Right to data portability where applicable
- Right to object to processing based on legitimate interests
- Right to lodge a complaint with a relevant supervisory authority
Requests may require reasonable identity verification and are handled within applicable legal timeframes. NIL Data Africa aims to respond to all data subject requests promptly and in a manner consistent with regulatory requirements.
9. Privacy Governance
NIL Data Africa maintains internal accountability for data protection and privacy compliance. Responsibility for privacy oversight is assigned within the organization and supported by documented policies, contractual controls with service providers, and management oversight.
Access to personal data is restricted to individuals who require it for legitimate business or program purposes and who are subject to confidentiality obligations. NIL Data Africa conducts periodic reviews of its privacy practices to ensure continued alignment with regulatory requirements.
10. Supervisory Authorities
NIL Data Africa engages with the relevant supervisory authority based on the location of the data subject and the nature of the processing activity. In South Africa, the primary regulatory authority is the Information Regulator, established under POPIA.
Where required under applicable law, NIL Data Africa cooperates with lead or local supervisory authorities in accordance with established regulatory mechanisms.
11. Automated Decision-Making
NIL Data Africa does not engage in fully automated decision-making that produces legal or similarly significant effects on individuals without meaningful human involvement. Where automated tools are used to support assessments or recommendations, final decisions involving individuals are subject to human review.
12. Security and International Data Transfers
NIL Data Africa implements reasonable technical and organizational security measures appropriate to the nature of the personal data processed. These measures include access controls, data minimization practices, and encryption where appropriate.
As an international organization, we may transfer personal data across borders. Where international transfers occur, NIL Data Africa relies on appropriate safeguards, including Standard Contractual Clauses (SCCs) or equivalent mechanisms, to ensure consistent and lawful protection of personal data.
13. Personal Data Breaches
In the event of a personal data breach, NIL Data Africa will assess the incident and, where legally required, notify relevant supervisory authorities and affected individuals without undue delay, in accordance with applicable laws.
NIL Data Africa maintains procedures to support timely identification, assessment, and response to data security incidents, including an internal escalation process and documented remediation steps.
14. Website and Digital Channels
When visitors interact with NIL Data Africa’s website and digital channels, certain technical data may be collected automatically, including device type, browser information, IP address, and interaction data. This data is used for operational analytics, security, and service improvement.
Where cookies or similar tracking technologies are used, NIL Data Africa provides appropriate notice and, where required by law, obtains consent before placing non-essential cookies on a visitor’s device.
15. Marketing Communications
NIL Data Africa may send marketing communications to individuals who have engaged with our services or who have provided consent to receive such communications. Recipients may opt out of marketing communications at any time by following the unsubscribe instructions in any communication or by contacting us directly.
16. Data Processing Agreement
Acceptance of this Privacy Policy through enrolment, engagement, or use of NIL Data Africa services constitutes acknowledgment of the embedded Data Processing Agreement (DPA). This agreement requires NIL Data Africa and its sub-processors to process personal data only on documented instructions, maintain confidentiality, implement appropriate safeguards, and notify NIL Data Africa of data security incidents in a timely manner.
17. Policy Updates
This Privacy Policy may be updated periodically to reflect changes in legal requirements, operational practices, or service delivery. Where required by applicable law or where changes are material, affected individuals will be notified through appropriate channels.
The current version of this policy is always available on the NIL Data Africa website and outward-facing channels.
18. Contact Information
For privacy-related inquiries, to exercise data protection rights, or to raise a concern, please contact:
Organization: | NIL Data Africa |
Email: | rgoudie@nil.co.za |
Subject line: | Privacy Inquiry |
Website: | www.nil.co.za |
NIL Data Africa is committed to responsible data stewardship, transparency, and continuous improvement as privacy expectations and regulatory requirements evolve.