Protection of Personal Information Act 4 of 2013

Privacy Policy & POPIA Notice

How K Gcolotela & Peter Incorporated collects, uses, protects, shares and retains personal information, and the rights you have as a data subject.

Last updated: 16 September 2026 Version 2.0 Next review: September 2027

1. Introduction

K Gcolotela & Peter Incorporated ("KG&P", "the Firm", "we", "us" or "our") is a firm of attorneys, conveyancers and notaries. In the course of providing legal services we necessarily collect and process personal information about our clients, their employees and customers, counterparties, witnesses, suppliers, job applicants, website visitors and other persons.

We are committed to processing personal information lawfully, securely and responsibly, in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), the Legal Practice Act 28 of 2014, the rules of the Legal Practice Council, and our contractual obligations to our clients.

This Privacy Policy explains what personal information we collect, why we collect it, how we protect it, who we share it with, how long we keep it, and what rights you have. It should be read together with our Information Security Policy, which describes the technical and organisational measures we apply to safeguard personal information.

2. Who we are (Responsible Party)

For the purposes of POPIA, the responsible party is:

Legal name
K Gcolotela & Peter Incorporated
Nature of business
Attorneys, Conveyancers and Notaries Public (private body)
Head office
99 Adelaide Tambo Drive, Durban North, KwaZulu-Natal, South Africa
Other offices
Sunninghill (Gauteng), Cape Town (Western Cape), East London and Gqeberha (Eastern Cape)
Telephone
031 312 0036 (KZN)  |  010 023 1875 (GP)
Email
reception@gcolotela.co.za
Website
www.gcolotela.co.za

3. Information Officer

In terms of section 55 of POPIA and section 17 of PAIA, the Firm has designated an Information Officer who is responsible for encouraging and ensuring compliance with POPIA, dealing with requests made under POPIA and PAIA, working with the Information Regulator, and ensuring that this Policy and our internal measures are implemented, maintained and reviewed.

Information Officer

Khanyiswa Gcolotela

Managing Director

officemanager@gcolotela.co.za

Deputy Information Officer

Yolanda Sineke

Office Manager

officemanager@gcolotela.co.za

Our Information Officer is registered with the Information Regulator (South Africa) as required by Regulation 4 of the POPIA Regulations.

4. Definitions

Terms used in this Policy carry the meaning given to them in POPIA. In particular:

  • Personal information means information relating to an identifiable, living natural person and, where applicable, an identifiable existing juristic person, including (but not limited to) names, identity numbers, contact details, financial and employment history, biometric information, opinions, correspondence and any identifying number or symbol.
  • Special personal information means information about a person's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour.
  • Processing means any operation concerning personal information, including collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, distribution, merging, linking, restriction, erasure or destruction.
  • Data subject means the person to whom personal information relates.
  • Responsible party means the person who determines the purpose of and means for processing personal information — in this Policy, the Firm.
  • Operator means a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party (for example, our IT, cloud hosting and document-management service providers).
  • Information Regulator means the Information Regulator (South Africa) established under section 39 of POPIA.

5. What personal information we collect

Depending on your relationship with us, we may collect and process the following categories of personal information:

CategoryExamples
Identity informationFull names, identity or passport number, date of birth, gender, nationality, marital status, company registration numbers, signatures and FICA verification documents.
Contact informationPhysical, postal and email addresses, telephone and mobile numbers.
Financial informationBank account details, income and asset information, credit and payment history, property and bond details, and information required for trust account transactions.
Employment informationEmployer, occupation, employment history, CVs, qualifications and references (clients, witnesses and job applicants).
Matter informationInstructions, correspondence, pleadings, contracts, deeds, evidence, and any personal information contained in documents relating to a legal matter, including information about third parties such as counterparties, witnesses and family members.
Client-provided dataPersonal information of our clients' customers, employees, debtors or account holders that a client shares with us for the purposes of a mandate (for example, debt recovery, litigation, conveyancing or investigations conducted on behalf of a financial institution).
Special personal informationHealth, criminal, biometric or similar information, only where necessary for a legal matter (for example personal injury, labour or forensic matters) and processed under an applicable POPIA exemption.
Website and technical dataIP address, browser type, device information, pages visited and cookie data collected when you use our website or submit an online form.

6. How we collect personal information

Wherever reasonably practicable we collect personal information directly from you. We may also collect personal information:

  • from our clients, when they instruct us on a matter in which you are involved;
  • from public sources and registers, such as the Deeds Office, CIPC, the courts, credit bureaus and public records, where this is necessary for a matter and permitted by law;
  • from third parties such as counterparties, other attorneys, sheriffs, tracing agents, experts, government departments and regulators;
  • from your employer or recruitment agency (job applicants);
  • through our website, contact forms, event registrations, cost calculator and email correspondence; and
  • through CCTV and visitor registers at our offices, for security purposes.

7. Why we process personal information

We process personal information only for authorised, specific and lawful business purposes and in accordance with our contractual obligations. These purposes include:

  • providing legal advice and services, and carrying out client mandates (litigation, conveyancing, debt recovery, commercial, labour, estate, procurement and forensic matters);
  • verifying identity and complying with the Financial Intelligence Centre Act 38 of 2001 ("FICA") and other anti-money-laundering and anti-corruption obligations;
  • administering client files, trust account transactions, billing and collections;
  • communicating with clients, courts, counterparties and other parties to a matter;
  • complying with our obligations to the Legal Practice Council, the courts, regulators and law enforcement;
  • managing our relationships with suppliers, service providers and business partners;
  • recruiting and employing staff;
  • maintaining the security of our premises, systems and information; and
  • operating and improving our website, and responding to enquiries submitted through it.

We do not process personal information for purposes that are incompatible with those for which it was collected, unless you consent or the further processing is otherwise permitted by POPIA.

8. Our commitment to lawful processing

We give effect to the eight conditions for lawful processing set out in Chapter 3 of POPIA as follows:

1
Accountability

The Firm remains responsible for compliance with POPIA, including where processing is outsourced to an operator.

2
Processing limitation

We process personal information lawfully, in a reasonable manner that does not infringe your privacy, and only with a lawful justification (consent, contract, legal obligation, legitimate interest or protection of your interests).

3
Purpose specification

We collect personal information for specific, explicitly defined and lawful purposes and retain it no longer than necessary.

4
Further processing limitation

Further processing must be compatible with the original purpose of collection.

5
Information quality

We take reasonable steps to ensure that personal information is complete, accurate, not misleading and up to date.

6
Openness

We maintain the documentation required by section 51 of PAIA and inform data subjects of the purpose of collection through this Policy.

7
Security safeguards

We secure the integrity and confidentiality of personal information through appropriate technical and organisational measures (see section 11).

8
Data subject participation

You may access, correct and, where appropriate, request deletion of your personal information (see section 14).

Data minimisation

We collect, use and share only the minimum personal information necessary for the specific purpose at hand. Staff are instructed to request and disclose only what a matter requires, and to redact personal information that is not relevant before documents are shared.

9. Sharing personal information and operators

We do not sell personal information. We share personal information only where necessary for the purposes described above and only with:

  • Courts, tribunals, sheriffs, the Deeds Office, CIPC, SARS, the Master of the High Court and other authorities, as required for a matter;
  • Counsel, correspondent attorneys, experts, tracing agents and other professional advisers engaged on a matter;
  • Our clients, where we act on their instructions in relation to you;
  • Operators and service providers that process information on our behalf — including IT support, cloud hosting, email, practice-management and document-management providers, and secure archiving and destruction services;
  • Banks and financial institutions, for trust account and conveyancing transactions;
  • Regulators and law enforcement, where required by law; and
  • Insurers, auditors and professional bodies, where required for the Firm's regulatory and risk-management obligations.

All operators are bound by written agreements that require them to process personal information only on our instructions, to treat it as confidential, to implement appropriate security measures, and to notify us immediately of any actual or suspected security compromise. Employees, contractors and subcontractors who handle personal information on our behalf are bound by confidentiality undertakings and receive privacy and security awareness training.

10. Cross-border transfers

Personal information is stored and processed primarily in South Africa. Where a service provider stores information outside South Africa (for example, cloud email or backup services), we transfer personal information only where permitted by section 72 of POPIA — that is, where the recipient is subject to a law, binding corporate rules or a binding agreement that provides substantially similar protection to POPIA, where you have consented, or where the transfer is necessary for the performance of a contract with you or in your interest.

11. Security safeguards

In terms of section 19 of POPIA we secure the integrity and confidentiality of personal information in our possession or under our control by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of it. These measures are set out in detail in our Information Security Policy and include:

Password-protected transmission

All documents containing personal information are password-protected or encrypted before being transmitted by email, with the password communicated through a separate channel.

Access control

Access to files and systems is restricted on a need-to-know basis, protected by unique user accounts, strong passwords and multi-factor authentication.

Secure systems

Encrypted devices, endpoint protection, patched systems, firewalled networks and secure, regularly tested backups.

Trained people

Mandatory privacy and security awareness training for all employees, contractors and subcontractors who handle personal information, at induction and annually thereafter.

Confidentiality

Attorney-client privilege, professional confidentiality obligations and written confidentiality undertakings from all staff and operators.

Regular review

Our processes, policies and controls are reviewed at least annually and after any incident to ensure ongoing adherence to data protection laws and contractual obligations.

12. Data breaches and security compromises

We maintain a documented incident response procedure. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will:

  • contain the incident and preserve evidence immediately;
  • promptly report the actual or suspected breach, privacy incident or unauthorised disclosure to any client whose information is involved, in accordance with our contractual obligations and without undue delay;
  • notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery, as required by section 22 of POPIA, including a description of the possible consequences and the measures we have taken or intend to take;
  • record the incident in our incident register; and
  • conduct a post-incident review and implement corrective measures.

Anyone who becomes aware of an actual or suspected security compromise involving information held by the Firm should report it immediately to officemanager@gcolotela.co.za or to 031 312 0036.

13. Retention of personal information

We retain personal information only for as long as is necessary to achieve the purpose for which it was collected, unless a longer period is required or permitted by law, is reasonably required for lawful purposes related to our functions, is required by a contract, or you have consented. Indicative retention periods are:

Record typeRetention period
Client files and matter recordsMinimum of 7 years after the matter is closed (Legal Practice Act and Legal Practice Council rules), or longer where a matter or claim remains open
Trust and business accounting recordsMinimum of 7 years (Legal Practice Act, Companies Act and Tax Administration Act)
FICA identification and verification records5 years from the end of the business relationship or transaction
Conveyancing and deeds recordsRetained in accordance with Deeds Registries Act requirements
Employee recordsDuration of employment plus the periods required by labour and tax legislation
Unsuccessful job applications12 months after the recruitment process, unless you consent to longer retention
Website enquiries and event registrationsUntil the enquiry or event has been dealt with and for a reasonable period thereafter, not exceeding 24 months
CCTV footage and visitor registersUp to 90 days unless required for an investigation

When personal information is no longer required, it is securely destroyed, deleted or de-identified so that it cannot be reconstructed.

14. Your rights as a data subject

Subject to the exceptions in POPIA and to legal professional privilege, you have the right to:

  • be notified that we are collecting your personal information, or that it has been accessed by an unauthorised person;
  • request access to the personal information we hold about you, and to know the identity of third parties who have had access to it (section 23);
  • request correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, obtained unlawfully or no longer authorised to be retained (section 24);
  • object to the processing of your personal information on reasonable grounds relating to your particular situation, or for purposes of direct marketing (section 11(3));
  • withdraw consent at any time, where processing is based on consent;
  • not be subject to a decision based solely on automated processing of your personal information; and
  • lodge a complaint with the Information Regulator.
How to exercise your rights

Send your request to the Information Officer at officemanager@gcolotela.co.za with the subject line "POPIA Data Subject Request", or use the prescribed Form 2 (objection) or Form 1 (access request under PAIA) available from the Information Regulator. We will need to verify your identity before responding.

We will respond within a reasonable time and in any event within 30 days, unless a longer period is permitted by law. A prescribed fee may be payable for access requests under PAIA.

15. Direct marketing

We will only send you electronic marketing communications (such as newsletters, event invitations and legal updates) where you are an existing client, or where you have given your consent in accordance with section 69 of POPIA. Every marketing communication will include a simple means to opt out, and we will honour your request promptly.

16. Cookies and website usage

Our website uses a small number of cookies and similar technologies. Strictly necessary cookies enable core functionality and remember your cookie preference. Analytics cookies (Google Analytics) help us understand how visitors use the site so that we can improve it; these are only used if you accept them via our cookie notice, and you may withdraw your choice at any time by clearing your browser storage. You can also configure your browser to refuse cookies, although some features may then not work.

When you submit an online form we collect the information you enter together with the date, time and IP address of the submission for security and anti-abuse purposes. Online forms require you to confirm that you have read this Policy before submitting.

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites.

17. Children's personal information

We process the personal information of children (persons under 18) only where necessary for a legal matter and with the consent of a competent person, or where otherwise permitted by section 35 of POPIA.

18. PAIA manual

Our manual in terms of section 51 of the Promotion of Access to Information Act describes the records we hold and the procedure for requesting access to them. A copy is available on request from the Information Officer and for inspection at our head office.

19. Complaints

If you believe that we have processed your personal information unlawfully, please raise the matter with our Information Officer first so that we can attempt to resolve it. You also have the right to lodge a complaint with the Information Regulator:

The Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

P.O. Box 31533, Braamfontein, Johannesburg, 2017

Complaints: POPIAComplaints@inforegulator.org.za

General enquiries: enquiries@inforegulator.org.za

Website: inforegulator.org.za

20. Changes to this Policy

We review this Policy at least annually and whenever there is a material change in the law, our business or our processing activities. The current version will always be published on this page with its effective date. Material changes affecting existing clients will be communicated directly.

21. Contact us

Questions about this Policy, requests to exercise your rights, and reports of privacy incidents may be directed to:

Information Officer — K Gcolotela & Peter Incorporated

99 Adelaide Tambo Drive, Durban North, 4051

Tel: 031 312 0036

Email: officemanager@gcolotela.co.za