LEGAL

POPIA operator terms

Draft South African POPIA operator terms for specialist legal review.

Last updated: 30 July 2026

Draft — legal review required. This page is not an approved customer agreement or legal notice.

Responsible party and operator

The customer is intended to determine the purpose and means of processing and Beetl to process personal information as operator on documented instructions. Counsel must confirm this allocation for each service arrangement.

Security safeguards

Beetl must establish and maintain appropriate technical and organisational measures, identify reasonably foreseeable risks, maintain safeguards, verify effectiveness and update controls as risks change.

Confidentiality

People authorised to process personal information must do so only as necessary for their role and under enforceable confidentiality obligations.

Security compromises

The operator must notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, and provide available facts and ongoing cooperation.

Sub-operators and transfers

Sub-operator appointment, cross-border processing, contractual protections and the approved processing locations must be documented in the signed agreement.

Return, deletion and assistance

The final terms must cover access/correction/deletion assistance, evidence, return or destruction at termination, backup propagation and legally required retention.