Contents
· Section 1: Introduction & Scope
· Section 2: Applicable Legislation
· Section 3: Data We Collect and Why
· Section 4: Lawful Basis for Processing
· Section 5: Data Subject Rights
· Section 6: Data Retention Policy
· Section 7: Data Security Measures
· Section 8: Third-Party Data Sharing
· Section 9: International Data Transfers
· Section 10: Breach Notification Procedure
· Section 11: POPIA Specific Obligations (SA Clients)
· Section 12: GDPR Specific Obligations (UK/EU Clients)
· Section 13: Employee & Contractor Data
· Section 14: Roles & Responsibilities
· Section 15: Compliance Review & Audit
SECTION 1: INTRODUCTION & SCOPE
BERMS Engineering & Risk Management (Pty) Ltd ("BERMS", "the Company", "we") is committed to protecting the privacy, confidentiality, and integrity of all personal and business data entrusted to us by clients, employees, contractors, and third parties.
This Data Protection, GDPR & POPIA Compliance Framework ("the Framework") sets out the policies, procedures, and controls adopted by BERMS to ensure compliance with applicable data protection legislation — including the Protection of Personal Information Act 4 of 2013 (POPIA) in South Africa and the General Data Protection Regulation (GDPR) where applicable to UK or EU-based clients or data subjects.
1.1 Scope
This Framework applies to:
· All personal data processed by BERMS in the course of its business operations.
· All employees, directors, contractors, and sub-consultants of BERMS.
· All client engagements, proposals, and communications.
· All digital and physical data storage systems used by BERMS.
· All third-party service providers who process data on behalf of BERMS.
1.2 Policy Statement
BERMS will collect only the personal data that is necessary for legitimate business purposes, store it securely, retain it only for as long as required, and never sell, rent, or misuse personal data. We will be transparent with data subjects about how their data is used and will honour all rights afforded to them under applicable law.
SECTION 2: APPLICABLE LEGISLATION
BERMS operates primarily under UK law but may engage with clients, data subjects, or service providers in the South Africa and European Union. The following legislation applies:
POPIA (South Africa)
Protection of Personal Information Act 4 of 2013 — primary legislation governing personal data processing in South Africa. Fully effective from 1 July 2021.
GDPR (EU)
General Data Protection Regulation (EU) 2016/679 — applies where BERMS processes personal data of EU data subjects or provides services to EU-based clients.
UK GDPR
UK General Data Protection Regulation — applies where BERMS processes personal data of UK data subjects or provides services to UK-based clients post-Brexit.
OHSA (South Africa)
Occupational Health and Safety Act 85 of 1993 — governs health and safety data collected during site-based engagements.
ECTA (South Africa)
Electronic Communications and Transactions Act 25 of 2002 — governs electronic data storage, transmission, and security.
Companies Act 71 of 2008
Governs retention of company records, financial data, and statutory documents.
SECTION 3: DATA WE COLLECT AND WHY
BERMS collects and processes the following categories of personal and business data:
Client Contact Data
Names, job titles, email addresses, telephone numbers, company details.
Delivering consulting services; issuing proposals and invoices; maintaining client relationships.
Client Operational Data
Site data, asset records, maintenance histories, production data, CMMS outputs.
Conducting failure risk assessments, engineering reviews, and compliance audits.
Financial Data
Invoice details, payment records, banking references (company-level).
Billing, VAT compliance, financial record-keeping.
Employee / Contractor Data
Names, ID numbers, tax numbers, banking details, employment contracts.
Payroll, SARS compliance, PAYE, UIF obligations.
Health & Safety Data
Site induction records, PPE compliance, incident reports.
OHSA compliance; site safety management.
Website / Communication Data
Email correspondence, LinkedIn messages, enquiry forms.
Business development, client communication, proposal management.
Sensitive Data
Medical information (only if relevant to site safety or incapacity).
Collected only with explicit consent and only where strictly necessary.
SECTION 4: LAWFUL BASIS FOR PROCESSING
BERMS will only process personal data where a lawful basis exists. The following bases apply under both POPIA and GDPR:
Contractual Necessity
Processing required to fulfil a consulting agreement or employment contract.
Legal Obligation
Processing required to comply with SARS, CIPC, OHSA, or other statutory obligations.
Legitimate Interests
Processing necessary for BERMS's legitimate business interests (e.g. business development, client relationship management), where not overridden by the data subject's rights.
Consent
Where no other lawful basis applies, explicit consent will be obtained from the data subject before processing. Consent may be withdrawn at any time.
Vital Interests
Processing necessary to protect the life or safety of a person (e.g. medical emergency on site).
SECTION 5: DATA SUBJECT RIGHTS
BERMS recognises and will honour the following rights of data subjects under POPIA and GDPR:
Right to Access
Data subjects may request a copy of the personal data BERMS holds about them. Requests will be responded to within 30 days.
Right to Rectification
Data subjects may request correction of inaccurate or incomplete personal data.
Right to Erasure
Data subjects may request deletion of their personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful — subject to legal retention obligations.
Right to Restrict Processing
Data subjects may request that BERMS restricts processing of their data in certain circumstances.
Right to Data Portability
Where processing is based on consent or contract, data subjects may request their data in a structured, machine-readable format.
Right to Object
Data subjects may object to processing based on legitimate interests or for direct marketing purposes.
Right to Complain
Data subjects may lodge a complaint with the Information Regulator (South Africa) or the ICO (UK) if they believe their rights have been violated.
To exercise any of the above rights, data subjects should contact: Allen Steenkamp, Principal Consultant — [allen.steenkamp@bermsltd.co.uk]
SECTION 6: DATA RETENTION POLICY
BERMS will retain personal and business data only for as long as necessary for the purpose for which it was collected, or as required by law. The following retention periods apply:
Client Engagement Records (contracts, reports, correspondence)
7 years from end of engagement (SARS / Companies Act requirement)
Financial Records (invoices, payments, VAT records)
5 years from date of transaction (SARS requirement)
Employee / Contractor Records
5 years from end of employment / contract
Health & Safety Records (site inductions, incident reports)
5 years from date of record (OHSA requirement)
Marketing / Business Development Data
3 years from last contact, or until opt-out received
Proposal / Tender Documents (unsuccessful)
2 years from date of submission
CIPC / Statutory Company Records
Indefinitely (as required by Companies Act 71 of 2008)
Sensitive Data (medical, etc.)
Deleted immediately upon cessation of the purpose for which it was collected
Upon expiry of the retention period, data will be securely deleted (digital) or shredded (physical). A retention log will be maintained and reviewed annually.
SECTION 7: DATA SECURITY MEASURES
BERMS implements the following technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or disclosure:
7.1 Technical Measures
· All digital data stored on password-protected devices with full-disk encryption.
· Cloud storage (e.g. Google Drive, OneDrive) used only with two-factor authentication enabled.
· Client data shared only via encrypted email or secure file transfer — no unprotected public links.
· Antivirus and malware protection maintained and updated on all devices.
· Regular data backups performed and stored securely.
· Remote wipe capability enabled on mobile devices used for business purposes.
7.2 Organisational Measures
· Access to personal data restricted to those with a legitimate need to know.
· All sub-contractors and third-party service providers required to sign a Data Processing Agreement (DPA) before receiving any personal data.
· Physical documents containing personal data stored in locked filing or destroyed by cross-cut shredding.
· No personal data to be discussed in public spaces or on unsecured communication channels.
· Annual data protection awareness review conducted by the Principal Consultant.
· This Framework reviewed annually and updated following any material change in operations or legislation.
SECTION 8: THIRD-PARTY DATA SHARING
BERMS will not sell, rent, or trade personal data. Data may be shared with third parties only in the following circumstances:
Accountant / Tax Practitioner
Financial and employee data shared for SARS compliance, VAT returns, and payroll processing. DPA in place.
Legal Advisors
Data shared only where necessary for legal advice or dispute resolution. Bound by professional confidentiality.
Sub-Contractors / Associate Consultants
Only the minimum data necessary for delivery of a specific engagement. DPA required before sharing.
SARS / CIPC / Regulatory Bodies
Data disclosed only where legally required by statute or court order.
Insurance Providers
Data shared for professional indemnity, public liability, or other insurance purposes.
IT / Cloud Service Providers
Data processed by providers (e.g. Microsoft, Google) under their own GDPR/POPIA-compliant terms.
SECTION 9: INTERNATIONAL DATA TRANSFERS
Where BERMS transfers personal data outside of South Africa (e.g. to UK-based clients or cloud service providers), the following safeguards will apply:
· Transfers to the UK will be conducted in compliance with POPIA Section 72, which permits transfers to countries with adequate data protection laws. The UK maintains an adequate level of protection post-Brexit.
· Transfers to EU countries will comply with GDPR Chapter V requirements, including Standard Contractual Clauses (SCCs) where required.
· Cloud service providers (e.g. Microsoft Azure, Google Workspace) used by BERMS maintain GDPR and POPIA-compliant data processing agreements.
· No personal data will be transferred to a country without adequate data protection unless explicit consent is obtained from the data subject or a lawful transfer mechanism is in place.
SECTION 10: BREACH NOTIFICATION PROCEDURE
In the event of a personal data breach, BERMS will follow the procedure below:
Step 1 — Identify & Contain
Upon discovery of a suspected breach, the Principal Consultant must be notified immediately. All access to the affected data or system must be suspended pending investigation.
Step 2 — Assess
The nature, scope, and likely impact of the breach must be assessed within 24 hours. Determine: what data was affected, how many data subjects are impacted, and what the likely consequences are.
Step 3 — Notify the Regulator
Under POPIA: notify the Information Regulator as soon as reasonably possible if the breach is likely to result in harm to data subjects. Under GDPR: notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
Step 4 — Notify Data Subjects
Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, affected individuals must be notified without undue delay, in plain language, describing the nature of the breach and steps taken.
Step 5 — Document
All breaches (regardless of severity) must be recorded in the Breach Register, including: date, nature of breach, data affected, actions taken, and outcome.
Step 6 — Review
Following resolution, a root cause analysis must be conducted and corrective measures implemented to prevent recurrence.
SECTION 11: POPIA SPECIFIC OBLIGATIONS
As a entity, BERMS is subject to the Protection of Personal Information Act 4 of 2013 (POPIA). The following specific obligations apply:
11.1 Information Officer
Allen Steenkamp is designated as the Information Officer of BERMS Engineering & Risk Management (Pty) Ltd, responsible for ensuring compliance with POPIA and liaising with the Information Regulator. The Information Officer must be registered with the Information Regulator upon CIPC registration of the Company.
11.2 PAIA Manual
BERMS will prepare and maintain a PAIA (Promotion of Access to Information Act) Manual as required by law. This manual will be made available to data subjects upon request and submitted to the South African Human Rights Commission (SAHRC) as required.
11.3 Eight Conditions for Lawful Processing (POPIA)
Condition
BERMS Commitment
1. Accountability
BERMS takes responsibility for ensuring POPIA compliance across all processing activities.
2. Processing Limitation
Data collected only for a specific, explicitly defined, and lawful purpose.
3. Purpose Specification
Data subjects informed of the purpose of collection at the time of collection.
4. Further Processing Limitation
Data not processed in a manner incompatible with the original purpose.
5. Information Quality
Reasonable steps taken to ensure data is complete, accurate, and up to date.
6. Openness
BERMS maintains a PAIA Manual and notifies data subjects of processing activities.
7. Security Safeguards
Technical and organisational measures in place to protect data integrity and confidentiality.
8. Data Subject Participation
Data subjects may access, correct, or request deletion of their personal data.
SECTION 12: GDPR SPECIFIC OBLIGATIONS (UK/EU CLIENTS)
Where BERMS provides services to UK or EU-based clients, or processes personal data of UK or EU data subjects, the following GDPR-specific obligations apply:
· BERMS will maintain a Record of Processing Activities (ROPA) documenting all processing operations involving UK/EU personal data.
· Privacy notices will be provided to UK/EU data subjects at the point of data collection, in plain language, covering: identity of the controller, purpose and lawful basis, retention periods, and data subject rights.
· Data Processing Agreements (DPAs) will be in place with all processors handling UK/EU personal data on behalf of BERMS.
· Where BERMS acts as a data processor for a UK/EU client, it will process data only on documented instructions from the client (data controller).
· Data Protection Impact Assessments (DPIAs) will be conducted for any high-risk processing activities involving UK/EU personal data.
· BERMS will not engage in automated decision-making or profiling of UK/EU data subjects without explicit consent.
· Where required, BERMS will appoint a UK or EU representative to act as a point of contact for supervisory authorities and data subjects.
SECTION 13: EMPLOYEE & CONTRACTOR DATA
BERMS collects and processes personal data relating to employees and contractors for the following purposes:
Payroll & Tax
Name, ID number, NI, tax number, banking details, salary — processed for PAYE, UIF, HMRC, and SARS compliance.
Employment Records
Employment contracts, performance records, leave records — retained for duration of employment plus 5 years.
Health & Safety
Medical fitness certificates, site induction records — retained for 5 years per OHSA.
Emergency Contacts
Next of kin details — retained for duration of employment only.
Background Checks
Qualifications, professional registrations — verified at onboarding; retained for duration of employment.
All employees and contractors will be provided with a Privacy Notice at the commencement of their engagement, informing them of how their personal data will be used, stored, and retained.
SECTION 14: ROLES & RESPONSIBILITIES
Information Officer / Data Controller
Allen Steenkamp — Principal Consultant & Director
Overall accountability for POPIA and GDPR compliance. Registers with Information Regulator. Maintains PAIA Manual. Handles data subject requests and breach notifications.
Data Processor (Sub-Contractors)
Associate Consultants / Sub-Contractors
Process data only on documented instructions from BERMS. Must sign a Data Processing Agreement before receiving any personal data.
Third-Party Processors
Accountant, IT Providers, Legal Advisors
Process data under their own GDPR/POPIA-compliant terms or under a DPA with BERMS.
SECTION 15: COMPLIANCE REVIEW & AUDIT
BERMS will conduct an annual compliance review of this Framework to ensure it remains current, effective, and aligned with applicable legislation. The review will include:
· Assessment of any changes in applicable legislation (POPIA, GDPR, UK GDPR, ECTA).
· Review of data processing activities and retention schedules.
· Review of third-party Data Processing Agreements.
· Assessment of any data breaches or near-misses in the preceding year.
· Update of the Breach Register and ROPA.
· Review of technical and organisational security measures.
· Update of the PAIA Manual if required.
Confirmation of Information Officer registration with the Information Regulator.