LEGAL
POPIA operator terms
Draft South African POPIA operator terms for specialist legal review.
Last updated: 30 July 2026
Draft — legal review required. This page is not an approved customer agreement or legal notice.
Responsible party and operator
The customer is intended to determine the purpose and means of processing and Beetl to process personal information as operator on documented instructions. Counsel must confirm this allocation for each service arrangement.
Security safeguards
Beetl must establish and maintain appropriate technical and organisational measures, identify reasonably foreseeable risks, maintain safeguards, verify effectiveness and update controls as risks change.
Confidentiality
People authorised to process personal information must do so only as necessary for their role and under enforceable confidentiality obligations.
Security compromises
The operator must notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, and provide available facts and ongoing cooperation.
Sub-operators and transfers
Sub-operator appointment, cross-border processing, contractual protections and the approved processing locations must be documented in the signed agreement.
Return, deletion and assistance
The final terms must cover access/correction/deletion assistance, evidence, return or destruction at termination, backup propagation and legally required retention.