Privacy Policy

  

Contents

· Section 1: Introduction & Scope

· Section 2: Applicable Legislation

· Section 3: Data We Collect and Why

· Section 4: Lawful Basis for Processing

· Section 5: Data Subject Rights

· Section 6: Data Retention Policy

· Section 7: Data Security Measures

· Section 8: Third-Party Data Sharing

· Section 9: International Data Transfers

· Section 10: Breach Notification Procedure

· Section 11: POPIA Specific Obligations (SA Clients)

· Section 12: GDPR Specific Obligations (UK/EU Clients)

· Section 13: Employee & Contractor Data

· Section 14: Roles & Responsibilities

· Section 15: Compliance Review & Audit


  

SECTION 1: INTRODUCTION & SCOPE

BERMS Engineering & Risk Management (Pty) Ltd ("BERMS", "the Company", "we") is committed to protecting the privacy, confidentiality, and integrity of all personal and business data entrusted to us by clients, employees, contractors, and third parties.

This Data Protection, GDPR & POPIA Compliance Framework ("the Framework") sets out the policies, procedures, and controls adopted by BERMS to ensure compliance with applicable data protection legislation — including the Protection of Personal Information Act 4 of 2013 (POPIA) in South Africa and the General Data Protection Regulation (GDPR) where applicable to UK or EU-based clients or data subjects.

1.1 Scope

This Framework applies to:

· All personal data processed by BERMS in the course of its business operations.

· All employees, directors, contractors, and sub-consultants of BERMS.

· All client engagements, proposals, and communications.

· All digital and physical data storage systems used by BERMS.

· All third-party service providers who process data on behalf of BERMS.

1.2 Policy Statement

BERMS will collect only the personal data that is necessary for legitimate business purposes, store it securely, retain it only for as long as required, and never sell, rent, or misuse personal data. We will be transparent with data subjects about how their data is used and will honour all rights afforded to them under applicable law.


SECTION 2: APPLICABLE LEGISLATION

BERMS operates primarily under UK law but may engage with clients, data subjects, or service providers in the South Africa and European Union. The following legislation applies:

 

POPIA (South Africa)


Protection of Personal Information Act 4 of 2013 — primary legislation governing personal data processing in South Africa. Fully   effective from 1 July 2021.

 

GDPR (EU)


General Data   Protection Regulation (EU) 2016/679 — applies where BERMS processes personal   data of EU data subjects or provides services to EU-based clients.

 

UK GDPR


UK General Data Protection Regulation — applies where BERMS processes personal data of UK data subjects or provides services   to UK-based clients post-Brexit.

 

OHSA (South Africa)


Occupational   Health and Safety Act 85 of 1993 — governs health and safety data collected   during site-based engagements.

 

ECTA (South Africa)


Electronic Communications and Transactions Act 25   of 2002 — governs electronic data storage, transmission, and security.

 

Companies Act 71 of 2008


Governs   retention of company records, financial data, and statutory documents.


SECTION 3: DATA WE COLLECT AND WHY

BERMS collects and processes the following categories of personal and business data:

 

Client Contact Data


Names, job titles, email addresses, telephone   numbers, company details.


Delivering consulting services; issuing proposals   and invoices; maintaining client relationships.

 

Client Operational Data


Site data, asset   records, maintenance histories, production data, CMMS outputs.


Conducting failure risk assessments, engineering reviews, and compliance audits.

 

Financial Data


Invoice details, payment records, banking   references (company-level).


Billing, VAT compliance, financial record-keeping.

 

Employee / Contractor Data


Names, ID   numbers, tax numbers, banking details, employment contracts.


Payroll, SARS   compliance, PAYE, UIF obligations.

 

Health & Safety Data


Site induction records, PPE compliance, incident   reports.


OHSA compliance; site safety management.

 

Website / Communication Data


Email   correspondence, LinkedIn messages, enquiry forms.


Business   development, client communication, proposal management.

 

Sensitive Data


Medical information (only if relevant to site   safety or incapacity).


Collected only with explicit consent and only where   strictly necessary.


SECTION 4: LAWFUL BASIS FOR PROCESSING

BERMS will only process personal data where a lawful basis exists. The following bases apply under both POPIA and GDPR:

 

Contractual Necessity


Processing required to fulfil a consulting   agreement or employment contract.

 

Legal Obligation


Processing   required to comply with SARS, CIPC, OHSA, or other statutory obligations.

 

Legitimate Interests


Processing necessary for BERMS's legitimate   business interests (e.g. business development, client relationship   management), where not overridden by the data subject's rights.

 

Consent


Where no other   lawful basis applies, explicit consent will be obtained from the data subject   before processing. Consent may be withdrawn at any time.

 

Vital Interests


Processing necessary to protect the life or safety   of a person (e.g. medical emergency on site).


SECTION 5: DATA SUBJECT RIGHTS

BERMS recognises and will honour the following rights of data subjects under POPIA and GDPR:

 

Right to Access


Data subjects may request a copy of the personal   data BERMS holds about them. Requests will be responded to within 30 days.

 

Right to Rectification


Data subjects   may request correction of inaccurate or incomplete personal data.

 

Right to Erasure


Data subjects may request deletion of their   personal data where it is no longer necessary, consent is withdrawn, or   processing is unlawful — subject to legal retention obligations.

 

Right to Restrict Processing


Data subjects   may request that BERMS restricts processing of their data in certain   circumstances.

 

Right to Data Portability


Where processing is based on consent or contract,   data subjects may request their data in a structured, machine-readable   format.

 

Right to Object


Data subjects   may object to processing based on legitimate interests or for direct   marketing purposes.

 

Right to Complain


Data subjects may lodge a complaint with the   Information Regulator (South Africa) or the ICO (UK) if they believe their   rights have been violated.

To exercise any of the above rights, data subjects should contact: Allen Steenkamp, Principal Consultant — [allen.steenkamp@bermsltd.co.uk]


SECTION 6: DATA RETENTION POLICY

BERMS will retain personal and business data only for as long as necessary for the purpose for which it was collected, or as required by law. The following retention periods apply:

 

Client Engagement Records   (contracts, reports, correspondence)


7 years from end of engagement (SARS / Companies   Act requirement)

 

Financial Records (invoices, payments, VAT records)


5 years from   date of transaction (SARS requirement)

 

Employee / Contractor Records


5 years from end of employment / contract

 

Health & Safety Records (site   inductions, incident reports)


5 years from   date of record (OHSA requirement)

 

Marketing / Business Development   Data


3 years from last contact, or until opt-out   received

 

Proposal / Tender Documents   (unsuccessful)


2 years from   date of submission

 

CIPC / Statutory Company Records


Indefinitely (as required by Companies Act 71 of   2008)

 

Sensitive Data (medical, etc.)


Deleted   immediately upon cessation of the purpose for which it was collected

Upon expiry of the retention period, data will be securely deleted (digital) or shredded (physical). A retention log will be maintained and reviewed annually.


SECTION 7: DATA SECURITY MEASURES

BERMS implements the following technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or disclosure:

7.1 Technical Measures

· All digital data stored on password-protected devices with full-disk encryption.

· Cloud storage (e.g. Google Drive, OneDrive) used only with two-factor authentication enabled.

· Client data shared only via encrypted email or secure file transfer — no unprotected public links.

· Antivirus and malware protection maintained and updated on all devices.

· Regular data backups performed and stored securely.

· Remote wipe capability enabled on mobile devices used for business purposes.

7.2 Organisational Measures

· Access to personal data restricted to those with a legitimate need to know.

· All sub-contractors and third-party service providers required to sign a Data Processing Agreement (DPA) before receiving any personal data.

· Physical documents containing personal data stored in locked filing or destroyed by cross-cut shredding.

· No personal data to be discussed in public spaces or on unsecured communication channels.

· Annual data protection awareness review conducted by the Principal Consultant.

· This Framework reviewed annually and updated following any material change in operations or legislation.


SECTION 8: THIRD-PARTY DATA SHARING

BERMS will not sell, rent, or trade personal data. Data may be shared with third parties only in the following circumstances:

 

Accountant / Tax Practitioner


Financial and employee data shared for SARS   compliance, VAT returns, and payroll processing. DPA in place.

 

Legal Advisors


Data shared only   where necessary for legal advice or dispute resolution. Bound by professional   confidentiality.

 

Sub-Contractors / Associate   Consultants


Only the minimum data necessary for delivery of a   specific engagement. DPA required before sharing.

 

SARS / CIPC / Regulatory Bodies


Data disclosed   only where legally required by statute or court order.

 

Insurance Providers


Data shared for professional indemnity, public   liability, or other insurance purposes.

 

IT / Cloud Service Providers


Data processed   by providers (e.g. Microsoft, Google) under their own GDPR/POPIA-compliant   terms.


SECTION 9: INTERNATIONAL DATA TRANSFERS

Where BERMS transfers personal data outside of South Africa (e.g. to UK-based clients or cloud service providers), the following safeguards will apply:

· Transfers to the UK will be conducted in compliance with POPIA Section 72, which permits transfers to countries with adequate data protection laws. The UK maintains an adequate level of protection post-Brexit.

· Transfers to EU countries will comply with GDPR Chapter V requirements, including Standard Contractual Clauses (SCCs) where required.

· Cloud service providers (e.g. Microsoft Azure, Google Workspace) used by BERMS maintain GDPR and POPIA-compliant data processing agreements.

· No personal data will be transferred to a country without adequate data protection unless explicit consent is obtained from the data subject or a lawful transfer mechanism is in place.


SECTION 10: BREACH NOTIFICATION PROCEDURE

In the event of a personal data breach, BERMS will follow the procedure below:

 

Step 1 — Identify & Contain


Upon discovery of a suspected breach, the Principal Consultant must be notified immediately. All access to the affected data or   system must be suspended pending investigation.

 

Step 2 — Assess


The nature, scope, and likely impact of the breach must be assessed within 24 hours.   Determine: what data was affected, how many data subjects are impacted, and what the likely consequences are.

 

Step 3 — Notify the Regulator


Under POPIA: notify the Information Regulator as soon as reasonably possible if the breach is likely to result in harm to data subjects. Under GDPR: notify the relevant supervisory authority within 72   hours of becoming aware of the breach.

 

Step 4 — Notify Data Subjects


Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, affected individuals must be notified without undue delay, in plain language, describing the nature of the breach and steps taken.

 

Step 5 — Document


All breaches (regardless of severity) must be recorded in the Breach Register, including: date, nature of breach, data affected, actions taken, and outcome.

 

Step 6 — Review


Following   resolution, a root cause analysis must be conducted and corrective measures   implemented to prevent recurrence.


SECTION 11: POPIA SPECIFIC OBLIGATIONS

As a entity, BERMS is subject to the Protection of Personal Information Act 4 of 2013 (POPIA). The following specific obligations apply:

11.1 Information Officer

Allen Steenkamp is designated as the Information Officer of BERMS Engineering & Risk Management (Pty) Ltd, responsible for ensuring compliance with POPIA and liaising with the Information Regulator. The Information Officer must be registered with the Information Regulator upon CIPC registration of the Company.

11.2 PAIA Manual

BERMS will prepare and maintain a PAIA (Promotion of Access to Information Act) Manual as required by law. This manual will be made available to data subjects upon request and submitted to the South African Human Rights Commission (SAHRC) as required.

11.3 Eight Conditions for Lawful Processing (POPIA)

  

Condition


BERMS Commitment

 

1. Accountability


BERMS takes responsibility for ensuring POPIA compliance across all processing activities.

 

2. Processing Limitation


Data collected   only for a specific, explicitly defined, and lawful purpose.

 

3. Purpose Specification


Data subjects informed of the purpose of collection   at the time of collection.

 

4. Further Processing Limitation


Data not   processed in a manner incompatible with the original purpose.

 

5. Information Quality


Reasonable steps taken to ensure data is complete, accurate, and up to date.

 

6. Openness


BERMS maintains a PAIA Manual and notifies data subjects of processing activities.

 

7. Security Safeguards


Technical and organisational measures in place to protect data integrity and confidentiality.

 

8. Data Subject Participation


Data subjects may access, correct, or request deletion of their personal data.


SECTION 12: GDPR SPECIFIC OBLIGATIONS (UK/EU CLIENTS)

Where BERMS provides services to UK or EU-based clients, or processes personal data of UK or EU data subjects, the following GDPR-specific obligations apply:

· BERMS will maintain a Record of Processing Activities (ROPA) documenting all processing operations involving UK/EU personal data.

· Privacy notices will be provided to UK/EU data subjects at the point of data collection, in plain language, covering: identity of the controller, purpose and lawful basis, retention periods, and data subject rights.

· Data Processing Agreements (DPAs) will be in place with all processors handling UK/EU personal data on behalf of BERMS.

· Where BERMS acts as a data processor for a UK/EU client, it will process data only on documented instructions from the client (data controller).

· Data Protection Impact Assessments (DPIAs) will be conducted for any high-risk processing activities involving UK/EU personal data.

· BERMS will not engage in automated decision-making or profiling of UK/EU data subjects without explicit consent.

· Where required, BERMS will appoint a UK or EU representative to act as a point of contact for supervisory authorities and data subjects.


SECTION 13: EMPLOYEE & CONTRACTOR DATA

BERMS collects and processes personal data relating to employees and contractors for the following purposes:

 

Payroll & Tax


Name, ID number, NI, tax number, banking details, salary — processed for PAYE, UIF, HMRC, and SARS compliance.

 

Employment Records


Employment contracts, performance records, leave records — retained for duration of   employment plus 5 years.

 

Health & Safety


Medical fitness certificates, site induction records — retained for 5 years per OHSA.

 

Emergency Contacts


Next of kin details — retained for duration of employment only.

 

Background Checks


Qualifications, professional registrations — verified at onboarding; retained for duration of employment.

All employees and contractors will be provided with a Privacy Notice at the commencement of their engagement, informing them of how their personal data will be used, stored, and retained.


SECTION 14: ROLES & RESPONSIBILITIES

 

Information Officer / Data   Controller


Allen Steenkamp — Principal Consultant &   Director


Overall accountability for POPIA and GDPR compliance. Registers with Information Regulator. Maintains PAIA Manual.   Handles data subject requests and breach notifications.

 

Data Processor (Sub-Contractors)


Associate Consultants / Sub-Contractors


Process data only on documented instructions from BERMS. Must sign a Data Processing   Agreement before receiving any personal data.

 

Third-Party Processors


Accountant, IT Providers, Legal Advisors


Process data under their own GDPR/POPIA-compliant terms or under a DPA with BERMS.


SECTION 15: COMPLIANCE REVIEW & AUDIT

BERMS will conduct an annual compliance review of this Framework to ensure it remains current, effective, and aligned with applicable legislation. The review will include:

· Assessment of any changes in applicable legislation (POPIA, GDPR, UK GDPR, ECTA).

· Review of data processing activities and retention schedules.

· Review of third-party Data Processing Agreements.

· Assessment of any data breaches or near-misses in the preceding year.

· Update of the Breach Register and ROPA.

· Review of technical and organisational security measures.

· Update of the PAIA Manual if required.

Confirmation of Information Officer registration with the Information Regulator. 

  • Privacy Policy

Copyright © 2025 BERMS LTD - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept