PERSONAL DATA PROTECTION POLICY

1. Introduction

Reviva Technology Proprietary Limited ("Reviva") forms part of the Bounty Brands group of companies ("Bounty", "the Group") . For the purposes of carrying out its business and related objectives, Bounty will from time to time, process personal data of individuals and legal entities including public and private entities, such as personal data pertaining to employees and staff, prospective employees and job applicants, students and graduates, service providers and contractors, vendors, clients, customers, and other third parties ("Data").

This Policy seeks to ensure that Bounty:

  • 1.1 Complies with the South African and international legal standards and best practice for the processing of personal data which includes the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, disseminating and destruction of personal data;
  • 1.2 Protects the rights of its employees and staff, prospective employees and job applicants, students and graduates, service providers and contractors, vendors, clients, customers, and other third parties ("data subjects") in respect of personal data processed;
  • 1.3 Transparently renders how it processes personal data of individuals; and
  • 1.4 Mitigates the risks of data breaches.

2. Purpose and Objectives

  • 2.1 Bounty processes personal data belonging to data subjects on an ongoing basis to carry out and pursue its business and related operational interests. This may include:
    • 2.1.1 Recruitment and employment purposes;
    • 2.1.2 Concluding contracts and business transactions;
    • 2.1.3 For risk assessments, insurance and underwriting purposes;
    • 2.1.4 Assessing and processing queries, enquiries, complaints, and / or claims;
    • 2.1.5 Conducting criminal reference checks and / or conducting credit reference searches orverification;
    • 2.1.6 Confirming, verifying and updating persons details;
    • 2.1.7 For purposes of personnel and other claims history;
    • 2.1.8 For the detection and prevention of fraud, crime, money laundering or other malpractice;
    • 2.1.9 Conducting market or customer satisfaction research;
    • 2.1.10 Promotional, marketing and direct marketing purposes;
    • 2.1.11 Financial, audit and record keeping purposes;
    • 2.1.12 In connection with legal proceedings;
    • 2.1.13 Providing services to clients to carry out the services requested and to maintain and constantly improve the relationship;
    • 2.1.14 Communicating with employees, third parties, customers, suppliers and / or governmental officials and regulatory agencies; and
    • 2.1.15 In connection with and to comply with legal and regulatory requirements or when it is otherwise required or allowed by law.
    • 2.2 The objective and purpose of this policy is therefore to set out Bounty’s policy on the processing of personal data and to provide guidelines on how personal data is to be processed and safeguarded.

3. Scope

  • 3.1 This policy will apply to the processing by Bounty of all and any data subjects’ personal data.
  • 3.2 This policy without exception will apply to:
    • 3.2.1 Bounty and its subsidiary companies, including all employees thereof, including permanent, fixed term, and temporary staff, directors and executives, secondees;
    • 3.2.2 Any entity or person who processes personal data on behalf of Bounty, whether residing or operating in South Africa, or overseas, who will hereinafter be referred to as an "operator", provided they have been made aware of this Policy.

4. Data Protection Principles and Conditions

  • 4.1 Personal Data shall always be:
    • 4.1.1 Obtained and processed fairly and lawfully;
    • 4.1.2 Obtained only for specific lawful purposes;
    • 4.1.3 Adequate, relevant and not excessive;
    • 4.1.4 Accurate, and kept up to date;
    • 4.1.5 Held for no longer than necessary for the purpose it was obtained for;
    • 4.1.6 Processed in accordance with the rights of data subjects;
    • 4.1.7 Be protected in appropriate ways, methodologies and procedures and according to suitable methods, both organisationally and technologically;
    • 4.1.8 Not be disclosed, transferred or exported illegally, or in breach of any agreement with a data subject.
  • 4.2 All employees and where applicable, operators and persons acting on behalf of Bounty, shall continually be responsible for ensuring the safeguarding, protection and avoidance of any unauthorised disclosure or breach of personal data in the execution of employment duties and services to Bounty, or otherwise in the course of rendering services or being associated with Bounty.
  • 4.3 Where it is necessary to store personal data on portable devices such as laptops, USB flash drives, portable hard drives, CDs, DVDs, employees and where applicable, operators and persons acting on behalf of Bounty without exception must before storing said personal data ensure that the data is encrypted and is kept secure, and that appropriate measures and safeguards are in place to prevent unauthorised access, disclosure and loss of such personal data.
  • 4.4 Where paper or hard copies of personal data are removed from Bounty premises, employees, operators and/or persons acting on behalf of Bounty must ensure that only relevant data is taken. In addition, such data must be kept safe and secure and appropriate measures and safeguards are taken to prevent any unauthorised access, disclosure and loss of such personal data.
  • 4.5 Paper or hard copies of personal data and portable electronic devices housing personal data should be stored in locked units, which should not be left on desks overnight or in view of other employees or third parties.
  • 4.6 Personal information which is no longer required should be destroyed or securely archived and retained.
  • 4.7 Personal data shall be deemed confidential information and shall not be disclosed unlawfully to any third party.
  • 4.8 Personal data loss must be reported to the relevant manager of the department from where the information emanates and to the Chief Financial, Risk or Compliance Officer.
  • 4.9 Negligent loss or unauthorised disclosure of personal data, or failure to report such events, may be treated as a disciplinary matter.
  • 4.10 Bounty will continuously review the security controls and processes to ensure that all personal data is secure.

5. Policy Compliance

5.1 Compliance measurement

Group IT will verify compliance to this policy through various methods, including periodic walk-throughs, business tool reports, internal and external audits, and feedback to the policy owner.


5.2 Exceptions

Any exception to the policy must be approved by the Head of Group IT in advance.