Isango Enterprises ← Back to Isango Enterprises

Data Processing Agreement

Table of Contents

  1. Introduction
  2. Definitions
  3. Scope and Parties
  4. Purpose and Processing Instructions
  5. Scope of Processing
  6. Confidentiality Obligations
  7. Security of Personal Information
  8. Sub-Processors and Subcontractors
  9. Cross-Border Data Transfers
  10. Data Subject Rights
  11. Security Breach Notification
  12. Return or Deletion of Data
  13. Audit Rights and Compliance
  14. Liability and Indemnification
  15. Term and Termination
  16. Governing Law and Jurisdiction
  17. Signature Blocks
  18. Annexures

1. INTRODUCTION

1.1 Purpose

This Data Processing Agreement (the "Agreement") is entered into between Isango Enterprises (Pty) Ltd, a private company incorporated under South African law (Registration Number 2026/472055/07) (the "Controller" or "Isango"), and the undersigned organization (the "Processor" or "Service Provider").

This Agreement establishes the terms and conditions under which the Processor will process personal information on behalf of the Controller, in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable data protection legislation.

This Agreement is required under POPIA Section 20, which establishes mandatory requirements for contracts between responsible parties (controllers) and operators (processors) who handle personal information.

1.3 Scope of Agreement

This Agreement applies to all processing of personal information that the Processor conducts on behalf of the Controller, whether such processing occurs on the Processor's premises, the Controller's premises, or any other location.

1.4 Incorporation of Policies

The following documents are incorporated into this Agreement by reference and form part of this Agreement:

(a) The Controller's Privacy Policy;

(b) The Controller's POPIA Compliance Notice;

(c) The Controller's Data Protection and Information Governance Policies;

(d) Any amendments or supplementary instructions issued by the Controller.

2. DEFINITIONS

In this Agreement, unless the context otherwise requires:

"Breach" means any unauthorized or unlawful processing of personal information, including unauthorized access, modification, destruction, loss, or disclosure.

"Confidential Information" means any personal information and any other information relating to the Controller's business that the Processor receives or accesses in the course of performing services under this Agreement.

"Controller" means Isango Enterprises (Pty) Ltd, the entity that determines the purposes and means of processing personal information.

"Data Subject" means any natural person to whom personal information relates and who can be identified from that information.

"Processing" means any operation performed on personal information, including collection, receipt, recording, organization, storage, updating, alteration, use, analysis, transmission, dissemination, making available, blocking, or deletion.

"Personal Information" means information relating to an identified or identifiable natural person, including information that is capable of identifying that person directly or indirectly.

"Processor" or "Service Provider" means the entity executing this Agreement with the Controller to process personal information on the Controller's behalf.

"POPIA" means the Protection of Personal Information Act 4 of 2013 and any regulations made thereunder.

"Sub-Processor" or "Subcontractor" means any third party engaged by the Processor to process personal information on behalf of the Controller.

"Security Breach" means any incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information.

"Services" means the services to be provided by the Processor to the Controller as described in Annexure A to this Agreement.

3. SCOPE AND PARTIES

3.1 Parties to the Agreement

Controller: - Legal Name: Isango Enterprises (Pty) Ltd - CIPC Registration: 2026/472055/07 - Address: 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201 - Contact Person: Mr Kwakhanya Magutywa, Information Officer - Email: POPIA@isangoenterprises.co.za - Telephone: +27 (0)87 801 2919

Processor: - Legal Name: _____ - Registration Number: _____ - Business Address: _____ - Contact Person: _____ - Email: _____ - Telephone: _____

3.2 Role of Processor

The Processor is appointed as an operator under POPIA. The Processor:

(a) Will process personal information only on written instructions from the Controller;

(b) Will not determine the purposes or means of processing (except as instructed);

(c) Is bound by confidentiality obligations;

(d) Must implement appropriate security measures;

(e) Must comply with all applicable data protection laws;

(f) Is liable for breaches caused by its actions or those of its employees.

3.3 Services to be Provided

The Processor will provide the following services to the Controller:



(Detailed description of services is set out in Annexure A)

4. PURPOSE AND PROCESSING INSTRUCTIONS

4.1 Purpose of Processing

The Processor will process personal information for the following purposes only:

(a) Service Delivery: To provide the services described in Annexure A;

(b) Client Communication: To communicate with clients on behalf of the Controller;

(c) Service Records: To maintain records of services provided;

(d) Billing and Invoicing: To process payments and issue invoices;

(e) Compliance and Audit: To comply with legal obligations and enable audits;

(f) Such other purposes as may be specifically authorized in writing by the Controller.

The Processor will not use personal information for any purpose outside those listed above without the prior written consent of the Controller.

4.2 Processing Instructions

The Processor will process personal information only in accordance with:

(a) Written instructions from the Controller;

(b) This Agreement and its terms;

(c) The Controller's policies and procedures;

(d) POPIA and applicable data protection legislation;

(e) Any amendments or supplementary instructions issued by the Controller in writing.

4.3 Processing Limitations

Unless specifically authorized in writing by the Controller, the Processor:

(a) Will not transfer personal information to third parties;

(b) Will not use personal information for marketing or direct marketing purposes;

(c) Will not process personal information for automated decision-making or profiling;

(d) Will not combine personal information with data from other sources;

(e) Will not use personal information beyond what is necessary for service delivery.

4.4 Changes to Processing

If the Processor becomes aware that processing instructions are unlawful or violate POPIA, the Processor must:

(a) Notify the Controller immediately;

(b) Refuse to carry out the unlawful processing;

(c) Provide written explanation of the legal concern;

(d) Suggest lawful alternatives (if available);

(e) Maintain records of the notification and response.

5. SCOPE OF PROCESSING

5.1 Categories of Personal Information

The Processor may process the following categories of personal information:

(a) Identification Information: Names, identification numbers, dates of birth;

(b) Contact Information: Email addresses, telephone numbers, physical addresses;

(c) Professional Information: Job titles, company names, business details;

(d) Service-Related Information: Quotation details, project information, service requirements;

(e) Payment Information: Bank account details, payment history, invoices;

(f) Technical Information: IP addresses, device information, browsing data;

(g) Communication Records: Emails, messages, enquiries, requests.

5.2 Categories of Data Subjects

The Processor may process personal information relating to:

(a) Website visitors and users;

(b) Prospective clients and enquirers;

(c) Existing clients and customers;

(d) Employees of client organizations;

(e) Delivery recipients and site contacts;

(f) Such other individuals as the Controller may specify.

5.3 Geographic Scope

Processing may occur:

(a) In South Africa (primary location);

(b) On the Processor's premises or equipment;

(c) On the Controller's premises or equipment;

(d) On secure cloud platforms (if authorized);

(e) In other locations as specified by the Controller.

5.4 Duration of Processing

The Processor will process personal information:

(a) During the term of this Agreement;

(b) For the duration of service provision;

(c) Until the Controller instructs deletion or return;

(d) For retention periods specified by the Controller;

(e) In accordance with POPIA retention requirements.

6. CONFIDENTIALITY OBLIGATIONS

6.1 General Confidentiality

The Processor acknowledges that personal information is confidential and sensitive. The Processor agrees to:

(a) Treat all personal information as confidential;

(b) Not disclose personal information to unauthorized parties;

(c) Limit access to personal information on a need-to-know basis;

(d) Ensure that employees understand confidentiality obligations;

(e) Maintain confidentiality both during and after the term of this Agreement.

6.2 Staff Confidentiality

The Processor will ensure that:

(a) All employees with access to personal information sign written confidentiality agreements;

(b) Employees are trained on confidentiality obligations;

(c) Employees understand the sensitivity of personal information;

(d) Employees are aware of POPIA obligations;

(e) Confidentiality obligations survive employment termination;

(f) Departing employees return or delete personal information.

6.3 Permitted Disclosures

The Processor may disclose personal information only:

(a) As instructed by the Controller;

(b) To authorized employees and contractors (on a need-to-know basis);

(c) To sub-processors authorized by the Controller;

(d) As required by law (with prior notice to the Controller if legally permissible);

(e) To legal advisers and auditors (under confidentiality obligations);

(f) To law enforcement (as required by legal process).

6.4 No Use for Own Purposes

The Processor will not use personal information for:

(a) Its own business purposes;

(b) Marketing or sales activities;

(c) Profiling or analytics (except for service delivery);

(d) Creating or training machine learning models;

(e) Any purpose outside service delivery to the Controller.

6.5 Confidentiality Duration

Confidentiality obligations continue:

(a) During the entire term of this Agreement;

(b) After termination or expiration;

(c) Indefinitely for information that remains confidential in nature;

(d) Even after the Processor deletes personal information (confidentiality obligation survives).

7. SECURITY OF PERSONAL INFORMATION

7.1 Security Obligation

The Processor will implement and maintain appropriate technical and organizational security measures to protect personal information against:

(a) Unauthorized access;

(b) Unauthorized modification or alteration;

(c) Unauthorized destruction or loss;

(d) Accidental destruction or loss;

(e) Unlawful processing;

(f) Disclosure to unauthorized parties;

(g) Interference with availability or integrity.

7.2 Security Standards

Security measures must be appropriate to:

(a) The sensitivity and nature of the personal information;

(b) The likelihood and severity of potential harms;

(c) Current technological development and industry best practices;

(d) The cost of implementing security measures;

(e) POPIA requirements and guidance from the Information Regulator.

7.3 Specific Security Controls

The Processor will implement at minimum:

(a) Access Controls: - Role-based access controls limiting access to authorized personnel only - Strong password authentication for all systems - Multi-factor authentication where technically feasible - Audit logs recording who accessed what information and when

(b) Encryption: - Encryption of personal information in transit (HTTPS or TLS) - Encryption of sensitive personal information at rest - Secure encryption algorithms and key management

(c) Physical Security: - Secure facilities with restricted access - Security cameras and monitoring - Locked storage for physical documents - Secure disposal of documents containing personal information

(d) Network Security: - Firewalls protecting systems and networks - Intrusion detection and prevention systems - Regular security scanning and vulnerability assessments - Regular security updates and patches

(e) Backup and Recovery: - Regular automated backups of personal information - Secure backup storage in a different location - Tested recovery procedures for disaster scenarios - Documentation of backup schedules and retention

(f) Staff Training: - Data protection and security training for all staff - Regular refresher training on security practices - Awareness of threats such as phishing and social engineering - Training on confidentiality and proper handling of information

(g) Vendor Management: - Due diligence on third-party vendors and suppliers - Security requirements in contracts with vendors - Regular assessment of vendor security practices - Procedures for terminating vendor relationships

7.4 Security Incidents

The Processor will:

(a) Implement procedures to detect security incidents;

(b) Investigate incidents promptly and thoroughly;

(c) Assess the scope and impact of incidents;

(d) Take corrective action to remediate incidents;

(e) Implement preventive measures to avoid recurrence;

(f) Document incidents and remediation steps;

(g) Notify the Controller immediately (see Section 11).

7.5 Security Certification

The Processor will, upon request, provide:

(a) Documentation of security measures implemented;

(b) Security certifications or audit reports (ISO 27001, SOC 2, etc.);

(c) Evidence of staff training;

(d) Incident response procedures and plans;

(e) Business continuity and disaster recovery plans.

8. SUB-PROCESSORS AND SUBCONTRACTORS

The Processor will not engage sub-processors or subcontractors to process personal information without the prior written consent of the Controller.

Any attempt to engage sub-processors without authorization will be a material breach of this Agreement.

8.2 Authorization Process

If the Processor wishes to engage a sub-processor:

(a) The Processor must provide the Controller with written notice including: - Name and contact details of the proposed sub-processor - Location where processing will occur - Description of processing activities - Security measures to be implemented - Any risk assessment or due diligence findings

(b) The Controller will review the notice and may: - Approve the engagement - Require modifications or conditions - Reject the engagement - Request additional information

(c) The Processor may only engage the sub-processor after receiving written approval;

(d) The Controller may withdraw approval at any time.

8.3 Sub-Processor Agreements

Any sub-processor must be bound by a written agreement that:

(a) Imposes the same data protection obligations as this Agreement;

(b) Restricts the sub-processor's use of personal information to the purposes specified;

(c) Requires equivalent security measures;

(d) Requires confidentiality of personal information;

(e) Prohibits further sub-processing without Controller approval;

(f) Includes provisions for return or deletion of personal information;

(g) Allows the Controller to audit the sub-processor;

(h) Includes termination provisions.

8.4 Processor Liability for Sub-Processors

The Processor remains fully liable to the Controller for:

(a) Any breach by sub-processors;

(b) Any unauthorized processing by sub-processors;

(c) Any security failures by sub-processors;

(d) Any failure of sub-processors to comply with data protection laws;

(e) Any losses caused by sub-processor actions.

The Processor's use of sub-processors does not relieve it of any obligations under this Agreement.

8.5 List of Current Sub-Processors

The Processor will maintain and provide to the Controller an updated list of all current sub-processors, including:

(a) Sub-processor names and locations;

(b) Description of processing activities;

(c) Date of engagement;

(d) Status of data protection agreements.

9. CROSS-BORDER DATA TRANSFERS

9.1 Transfer Authorization

Personal information collected in South Africa may only be transferred outside South Africa if:

(a) The destination country has been declared by the Information Regulator to have data protection laws equivalent to POPIA; OR

(b) The Controller has provided explicit written consent to the transfer; OR

(c) The transfer is necessary to perform a contract with the Data Subject; OR

(d) Appropriate safeguards (such as Standard Contractual Clauses) are implemented.

9.2 Processor Transfers

If the Processor processes personal information outside South Africa, the Processor must:

(a) Obtain prior written authorization from the Controller;

(b) Ensure that the destination country provides adequate protection;

(c) Implement Standard Contractual Clauses or equivalent safeguards;

(d) Comply with any conditions imposed by the Controller;

(e) Notify the Controller of any changes to transfer locations.

9.3 Prohibited Transfers

The Processor will not transfer personal information to:

(a) Countries or territories that do not provide adequate data protection;

(b) Destinations not authorized by the Controller;

(c) Jurisdictions that may require disclosure to government authorities without proper legal process.

9.4 Cooperation with Authorities

If the Processor receives a request for personal information from foreign government authorities:

(a) The Processor will notify the Controller immediately;

(b) The Processor will not comply with the request without Controller authorization;

(c) The Processor will challenge the request if legally permissible;

(d) The Processor will provide the Controller with copies of all communications;

(e) The Processor will cooperate with the Controller in responding to the request.

10. DATA SUBJECT RIGHTS

10.1 Cooperation with Data Subjects

The Processor will cooperate with the Controller to enable Data Subjects to exercise their rights under POPIA, including:

(a) Right of access;

(b) Right to correction;

(c) Right to deletion;

(d) Right to restrict processing;

(e) Right to object to processing;

(f) Right to data portability.

10.2 Access Requests

If the Processor receives an access request directly from a Data Subject, the Processor will:

(a) Notify the Controller immediately;

(b) Not respond directly to the Data Subject (unless instructed);

(c) Provide the Controller with all personal information held;

(d) Assist the Controller in responding within the required timeframe;

(e) Not disclose information without Controller authorization.

10.3 Correction and Deletion Requests

If the Processor receives a request to correct or delete personal information, the Processor will:

(a) Notify the Controller immediately;

(b) Not comply with the request without Controller authorization;

(c) Provide the Controller with necessary information to assess the request;

(d) Execute the Controller's instructions (correct or delete) promptly;

(e) Confirm completion to the Controller.

10.4 Direct Requests from Data Subjects

The Processor will refer all requests from Data Subjects to the Controller:

Mr Kwakhanya Magutywa Information Officer Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919

10.5 Assistance with Documentation

The Processor will assist the Controller by:

(a) Providing personal information in a structured format;

(b) Documenting access, correction, or deletion dates;

(c) Maintaining records of Data Subject requests;

(d) Cooperating with Data Subject rights exercises;

(e) Not obstructing Data Subject rights.

11. SECURITY BREACH NOTIFICATION

11.1 Breach Definition

A security breach is any incident involving:

(a) Unauthorized access to personal information;

(b) Unauthorized disclosure of personal information;

(c) Loss or corruption of personal information;

(d) Unauthorized deletion of personal information;

(e) Unavailability of systems processing personal information;

(f) Any other event compromising personal information security.

11.2 Immediate Notification

If a security breach occurs, the Processor must notify the Controller immediately (without unreasonable delay) by:

(a) Email: POPIA@isangoenterprises.co.za;

(b) Telephone: +27 (0)87 801 2919;

(c) Certified Mail: If email unavailable.

Notification must occur no later than 24 hours after discovery of the breach.

11.3 Contents of Breach Notice

The breach notification must include:

(a) Nature of the Breach: What happened and how the breach occurred;

(b) Scope of the Breach: What personal information was involved;

(c) Categories of Data Subjects: Who was affected (employees, clients, website visitors, etc.);

(d) Number of Individuals Affected: Estimated number of affected Data Subjects;

(e) Likely Consequences: What are the potential impacts on Data Subjects;

(f) Detection Date: When was the breach discovered;

(g) Time of Occurrence: When did the breach occur (if known);

(h) Processor Actions: What steps has the Processor already taken;

(i) Mitigating Factors: Any factors that reduce the severity or impact;

(j) Contact Person: Name and contact details of the person managing the breach response;

(k) Documentation: Copies of any evidence, system logs, or incident reports.

11.4 Ongoing Communication

Following the initial notification, the Processor will:

(a) Provide regular updates on the investigation (daily or as significant developments occur);

(b) Notify the Controller of any changes to the scope or nature of the breach;

(c) Provide a full written breach report within 5 business days;

(d) Continue investigation and remediation to completion;

(e) Provide evidence of remediation steps;

(f) Document lessons learned and preventive measures;

(g) Remain available for questioning by the Controller or authorities.

11.5 Cooperation with Authorities

The Processor agrees to:

(a) Cooperate with the Information Regulator's investigation;

(b) Provide all requested documentation and evidence;

(c) Preserve evidence and maintain confidentiality where requested;

(d) Respond to all notices and inquiries promptly;

(e) Not make public statements about the breach without Controller authorization.

11.6 Costs of Breach Response

The Processor will bear:

(a) All costs of investigating the breach;

(b) All costs of remediating the breach;

(c) All costs of notifying affected Data Subjects;

(d) All costs of legal defense in proceedings related to the breach;

(e) All fines or penalties imposed by the Information Regulator;

(f) Compensation to Data Subjects for losses caused by the breach;

(g) Any other costs arising from the breach.

The Controller will not bear any costs or liability for breaches caused by the Processor.

12. RETURN OR DELETION OF DATA

12.1 Obligation to Return or Delete

Upon termination or expiration of this Agreement, the Processor will, at the Controller's election:

(a) Return all personal information to the Controller in a secure manner within 10 business days; OR

(b) Delete all personal information securely and permanently within 10 business days.

12.2 Deletion Process

If personal information is deleted, the Processor will:

(a) Use secure deletion methods that prevent recovery;

(b) Delete data from all storage locations (servers, backups, archives, etc.);

(c) Delete data from all devices and systems;

(d) Provide written certification of deletion;

(e) Maintain records of deletion (dates, methods, systems);

(f) Not retain copies except as legally required;

(g) Verify deletion through technical testing.

12.3 Return Process

If personal information is returned to the Controller, the Processor will:

(a) Provide the data in a structured, machine-readable format;

(b) Ensure completeness and accuracy of returned data;

(c) Transfer data securely using encryption;

(d) Verify successful receipt by the Controller;

(e) Delete the Processor's copies after confirmed receipt;

(f) Provide written confirmation of return and deletion.

12.4 Exceptions to Deletion

The Processor may retain personal information beyond termination only:

(a) As required by law (tax law, legal obligation);

(b) As necessary to defend legal claims;

(c) As specified in this Agreement;

(d) For the minimum period legally required;

(e) With Controller consent.

Retained information must remain subject to confidentiality and security obligations.

12.5 Timing

The 10-business-day deadline is mandatory and cannot be extended except:

(a) By written agreement of both parties;

(b) Where deletion is legally prevented;

(c) Where the Controller requests extended retention.

13. AUDIT RIGHTS AND COMPLIANCE

13.1 Audit Right

The Controller has the right to:

(a) Audit the Processor's compliance with this Agreement;

(b) Inspect the Processor's facilities where personal information is processed;

(c) Review security measures and controls;

(d) Request documentation of processing activities;

(e) Interview staff regarding data protection practices;

(f) Conduct unannounced audits if necessary.

13.2 Audit Frequency

The Controller may conduct audits:

(a) At least annually (scheduled);

(b) Upon reasonable notice (minimum 10 business days);

(c) Without notice if a breach or violation is suspected;

(d) Following any security incident;

(e) In response to a Data Subject complaint.

13.3 Audit Process

Audits will:

(a) Be conducted during normal business hours;

(b) Be conducted by the Controller or authorized representatives;

(c) Require the Processor to provide cooperation and access;

(d) Allow review of systems, facilities, and documentation;

(e) Allow interviews with relevant staff;

(f) Be documented in writing;

(g) Result in an audit report.

13.4 Audit Costs

Costs are allocated as follows:

(a) Scheduled Audits: Controller bears audit costs;

(b) Breach-Related Audits: Processor bears all costs;

(c) Remediation: Processor bears all costs of remediation;

(d) Legal Fees: Processor bears legal costs related to compliance issues.

13.5 Audit Reports

Following an audit, the Controller will:

(a) Provide a written report of findings;

(b) Identify any non-compliance or risks;

(c) Recommend corrective actions;

(d) Set deadlines for remediation;

(e) Follow up to verify remediation.

13.6 Compliance Certifications

The Processor will provide upon request:

(a) ISO 27001 certification (Information Security Management);

(b) SOC 2 Type II audit reports (System and Organization Controls);

(c) Security assessments by independent auditors;

(d) Documentation of security controls and measures;

(e) Staff training certificates and records;

(f) Data retention and deletion policies;

(g) Incident response plans and procedures.

13.7 Remediation of Non-Compliance

If an audit identifies non-compliance, the Processor will:

(a) Acknowledge the non-compliance in writing;

(b) Develop a remediation plan with timelines;

(c) Implement remediation measures;

(d) Provide evidence of remediation;

(e) Submit to follow-up audits to verify remediation;

(f) Bear all costs of remediation.

14. LIABILITY AND INDEMNIFICATION

14.1 Processor Liability

The Processor is fully liable to the Controller for:

(a) Any breach of this Agreement;

(b) Any unauthorized or unlawful processing of personal information;

(c) Any security breach or data loss;

(d) Any violation of POPIA or other data protection laws;

(e) Any failure to return or delete personal information;

(f) Any breach by its employees or sub-processors;

(g) Any losses, damages, or costs arising from the above.

14.2 No Limitation of Liability

The Controller's right to claim damages is not limited by any provision of this Agreement, except as required by law.

The Processor cannot exclude or limit liability for:

(a) Breaches caused by the Processor's negligence or willful misconduct;

(b) Breaches of confidentiality obligations;

(c) Security breaches;

(d) Unauthorized processing of personal information;

(e) Failure to return or delete personal information;

(f) Violations of POPIA.

14.3 Damages Recoverable

The Controller may recover:

(a) Direct damages (costs of remediation, notification, etc.);

(b) Consequential damages (business losses, reputational harm, etc.);

(c) Compensation to Data Subjects;

(d) Administrative fines imposed by the Information Regulator;

(e) Legal costs and attorney fees;

(f) Any other damages authorized by law.

14.4 Indemnification by Processor

The Processor agrees to indemnify and hold harmless the Controller from:

(a) Any claims by Data Subjects or third parties;

(b) Any liability for breach or unauthorized processing;

(c) Administrative fines or penalties;

(d) All legal costs and expenses;

(e) Reputational or business harm;

(f) Any other damages arising from the Processor's breach.

14.5 Insurance

The Processor will maintain:

(a) Errors and omissions insurance (minimum R5 million);

(b) Cyber liability and data breach insurance (minimum R5 million);

(c) Professional indemnity insurance;

(d) General commercial liability insurance.

Insurance will:

(a) Be maintained throughout the term of this Agreement;

(b) List the Controller as a named insured;

(c) Provide that insurance is primary to any other coverage;

(d) Not exclude liability for data breaches;

(e) Be evidenced annually to the Controller.

15. TERM AND TERMINATION

15.1 Term

This Agreement commences on the date of signature and continues for the duration of the Processor's engagement to provide services to the Controller, including:

(a) Any initial service period;

(b) Any renewal periods;

(c) Until terminated by either party as provided below.

15.2 Termination for Convenience

The Controller may terminate this Agreement at any time by providing written notice to the Processor:

(a) Notice Period: 30 days' written notice;

(b) Effective Date: Termination is effective on the date specified in the notice;

(c) Obligations Survive: Confidentiality and data handling obligations survive termination.

15.3 Termination for Cause

The Controller may terminate this Agreement immediately (without notice) if the Processor:

(a) Commits a material breach of this Agreement and fails to cure within 10 days of notice;

(b) Breaches POPIA or other data protection laws;

(c) Experiences a security breach affecting the Controller's data;

(d) Engages unauthorized sub-processors;

(e) Becomes insolvent or bankrupt;

(f) Refuses to comply with the Controller's lawful instructions;

(g) Fails to return or delete personal information as required.

15.4 Effect of Termination

Upon termination:

(a) The Processor will immediately cease processing personal information;

(b) The Processor will cease accessing personal information;

(c) The Processor will return or delete all personal information within 10 business days;

(d) Confidentiality obligations continue indefinitely;

(e) Audit rights continue for 12 months;

(f) Any outstanding payment obligations become immediately due.

15.5 Survival of Obligations

The following obligations survive termination:

(a) Confidentiality (indefinitely);

(b) Security of retained data (until deletion);

(c) Return or deletion of data;

(d) Breach notification;

(e) Data Subject rights cooperation;

(f) Indemnification;

(g) Audit rights (12 months post-termination);

(h) Governing law and dispute resolution;

(i) Any other obligations by their nature survive.

16. GOVERNING LAW AND JURISDICTION

16.1 Governing Law

This Agreement is governed by and construed in accordance with the laws of the Republic of South Africa, without regard to its conflict of law principles.

Applicable law includes:

(a) Protection of Personal Information Act 4 of 2013 (POPIA);

(b) Electronic Communications and Transactions Act 25 of 2002;

(c) Consumer Protection Act 68 of 2008;

(d) South African common law;

(e) Constitutional law of South Africa.

16.2 Jurisdiction

Both parties submit to the exclusive jurisdiction of the courts of South Africa, specifically:

(a) The courts in the jurisdiction where Isango Enterprises has its head office (East London, Eastern Cape); or

(b) Such other court as may be determined by South African law.

Both parties waive any objection based on inconvenient forum or lack of personal jurisdiction.

16.3 Dispute Resolution

Before commencing legal proceedings, the parties will attempt to resolve disputes through:

(a) Good Faith Negotiation: Direct discussion between parties (minimum 10 business days);

(b) Escalation to Management: If negotiation fails, escalation to senior management;

(c) Mediation: If escalation fails, the parties may agree to mediation;

(d) Legal Proceedings: If alternative dispute resolution fails, either party may commence legal proceedings.

16.4 Costs

In any dispute or legal proceeding:

(a) The unsuccessful party bears the winner's legal costs;

(b) The Processor bears all costs related to breach allegations;

(c) Each party bears its own costs during negotiation and mediation;

(d) Legal costs include reasonable attorney fees and court costs.

17. SIGNATURE BLOCKS

This Agreement is entered into on the date of the last signature below.

17.1 Controller Signature

ISANGO ENTERPRISES (PTY) LTD

By: _____ Name: Mr Kwakhanya Magutywa Title: Information Officer and Executive Director Date: _____ Signature: _____

17.2 Processor Signature

[PROCESSOR NAME]

By: _____ Name: _____ Title: _____ Date: _____ Signature: _____

18. ANNEXURES

ANNEXURE A: DESCRIPTION OF PROCESSING ACTIVITIES

Service Provider Name: _____

Services to be Provided:




Personal Information Categories to be Processed:

(a) _____

(b) _____

(c) _____

Data Subject Categories:

(a) _____

(b) _____

Processing Location(s):


Retention Period(s):


Security Measures:

(a) _____

(b) _____

(c) _____

Sub-Processors (if authorized):



ANNEXURE B: SECURITY REQUIREMENTS

The Processor will implement the following minimum security measures:

Technical Safeguards:

  1. HTTPS encryption for data in transit
  2. AES-256 encryption for sensitive data at rest
  3. Firewall protection for network systems
  4. Intrusion detection and prevention systems
  5. Regular security scanning and vulnerability assessments
  6. Automated security updates and patching
  7. Multi-factor authentication for system access
  8. Role-based access controls
  9. Audit logging of all access to personal information
  10. Secure backup and disaster recovery systems

Organizational Safeguards:

  1. Written data protection and security policies
  2. Information security awareness training for all staff
  3. Confidentiality agreements with all employees
  4. Restricted access to personal information on need-to-know basis
  5. Secure procedures for handling personal information
  6. Incident response procedures and plans
  7. Regular testing of incident response procedures
  8. Business continuity and disaster recovery plans
  9. Third-party vendor assessment and management
  10. Regular compliance audits and assessments

Physical Safeguards:

  1. Secure facilities with restricted access
  2. Security cameras and monitoring systems
  3. Locked storage for physical documents
  4. Secured destruction of documents containing personal information
  5. Limited visitor access to areas containing personal information

ANNEXURE C: DATA SUBJECT CONTACT INFORMATION

For data subject rights requests and complaints:

Information Officer:

Mr Kwakhanya Magutywa Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201

ANNEXURE D: BREACH NOTIFICATION PROCEDURE

Breach Reporting Contacts:

Immediate Notification (within 24 hours):

Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal: 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201

Information to Include:

  1. Nature and description of the breach
  2. When the breach occurred and when discovered
  3. What personal information was involved
  4. How many data subjects were affected
  5. Potential impacts on data subjects
  6. What steps the processor has already taken
  7. Contact person managing the breach response
  8. Any supporting documentation

Follow-Up Reporting:

Within 5 business days: Full written breach report Ongoing: Regular updates on investigation and remediation Completion: Final report with lessons learned and preventive measures

19. INTERPRETATION AND SEVERABILITY

19.1 Interpretation

In this Agreement:

(a) Headings are for convenience only and do not affect interpretation;

(b) References to "days" mean calendar days unless otherwise specified;

(c) References to "business days" mean Monday to Friday excluding public holidays;

(d) Words defined in POPIA have the same meaning in this Agreement;

(e) The context determines whether singular or plural forms apply;

(f) "Including" means "including without limitation."

19.2 Severability

If any provision of this Agreement is found to be invalid or unenforceable:

(a) That provision will be modified to the extent necessary to make it enforceable;

(b) If it cannot be modified, it will be severed;

(c) The remaining provisions continue in full force;

(d) The severing of one provision does not affect others;

(e) The intent and effect of the Agreement are preserved.

19.3 Entire Agreement

This Agreement, together with:

(a) The Controller's Privacy Policy;

(b) The Controller's POPIA Compliance Notice;

(c) The Controller's Website Terms & Conditions;

(d) Any written amendments or supplements;

...constitutes the entire agreement between the parties regarding data processing and supersedes all prior agreements, understandings, and representations.

20. AMENDMENTS AND UPDATES

20.1 Right to Amend

The Controller may amend this Agreement:

(a) To comply with changes in POPIA or data protection law;

(b) To respond to Information Regulator guidance or decisions;

(c) To address security risks or emerging threats;

(d) To improve data protection practices;

(e) For operational reasons.

20.2 Notice of Amendment

The Controller will provide written notice of amendments:

(a) At least 30 days before amendment takes effect;

(b) Clearly identifying the changes being made;

(c) Explaining the reasons for amendments;

(d) Specifying the effective date.

20.3 Processor Acceptance

By continuing to process personal information for the Controller after the effective date of an amendment, the Processor accepts the amended terms.

If the Processor does not accept an amendment, the Processor must terminate this Agreement within 30 days.