CONDITIONS OF LAWFUL PROCESSING
In accordance with the POPIA , Kastelo is committed to ensure that the processing of personal information is lawful, and thereby comply with the following eight conditions:
- Accountability - Kastelo must ensure that the conditions set out in Chapter 3 of the POPIA, and all measures that give effect to such conditions are complied with at the time of determining the purpose and the means of the processing.
- Processing limitation - Personal information may only be processed in a lawful and reasonable manner that does not infringe on the privacy of the data subject, and may only be processed if:
- the Client consents to the processing;
- processing is necessary to carry out actions for the conclusion or performance of a contract or undertaking to which the Client is party;
- processing complies with an obligation imposed by law on Kastelo for it to obtain information from Clients about their financial needs and capabilities in order to provide them with applicable and beneficial products;
- processing protects a legitimate interest on the Client; it is in the best interest of the Client to have a proper needs analysis performed so as to provide him/her with an appropriate and beneficial product, and which would require the obtaining of personal information;
- processing is necessary for the proper performance of a public law duty by a public body; in order for Kastelo to provide Clients with products or services, both ourselves and certain third parties require certain personal information to make a decision as to whether he/she would qualify for certain products and/or services; or
- processing is necessary for pursuing the legitimate interests of the responsible party or of a third party to whom the information is supplied;
- Purpose specific - Kastelo will process personal information only for specific reasons. Kastelo will inform Clients of such reasons, which are contained herein, prior to the collecting and processing of personal information. It remains the responsibility of the data subject / client to read and satisfactorily interpret this policy and reasons for collection and processing.
- Further processing - personal information will not be processed for a secondary purpose unless that processing is compatible with the original purpose; if Kastelo wishes to process existing personal information for a purpose other than the purpose for which it was originally collected, Kastelo shall first obtain additional consent from the Client.
- Information quality - Kastelo shall take reasonable steps to ensure that all personal information collected is complete, accurate and not misleading. Where personal information is collected or received from third parties, Kastelo will take reasonable steps to confirm that the information is correct by verifying the accuracy of the information directly with Kastelo or by way of independent sources.
- Openness - Kastelo will take reasonable steps to inform all data subjects whose information is being collected of:
- the information being collected and, where information is not being collected from the data subject, the source from which it is collected;
- the name and address of the responsible party, which shall be Kastelo;
- the purpose for which the information is being collected;
- whether or not the supply of the information by Client is voluntary or mandatory;
- the consequence of failure to provide the information;
- Any particular law authorising or requiring the collection of information;
- Security Safeguards - Kastelo must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent loss of damage to or unauthorised destruction of personal information, and unlawful access to or processing of personal information, and thereby take the following reasonable measures:
- identify all reasonably foreseeable internal and external risks to personal information in its possession or under its control;
- establish and maintain appropriate safeguards against the risk identified;
- regularly verify that the safeguards are effectively implemented; and
- ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards
- Client Participation - A Client may request whether his/her personal information is held, as well as the correction or deletion of his /her personal information held by Kastelo, the latter taking all reasonable steps to confirm the applicable Client’s identity before providing details of such personal information requested.