Skip to main content

IMCSA

Protection of Personal Information (POPI) Policy for IMCSA​

  1. Introduction
    • IMCSA is committed to protecting the privacy of our members, stakeholders, and visitors.
    • This policy explains how we collect, use, disclose, and safeguard your personal information.
    • This policy complies with the Protection of Personal Information Act (POPIA), No. 4 of 2013 of South Africa.
  1. Information We Collect
    • We collect personal information to provide professional body services and manage memberships.
    • Member Data: Names, identity numbers, contact details, physical addresses, and employment history.
    • Qualifications: Academic records, professional certifications, and CVs.
    • Financial Data: Billing addresses, banking details, and transaction histories for fee processing.
    • Digital Data: IP addresses, cookies, and website usage patterns.
  1. Purpose of Processing
    • We process your personal information strictly for legitimate business and professional purposes.
    • To register, administer, and manage your professional IMCSA membership.
    • To verify academic and professional qualifications for grading.
    • To process payments for application fees, annual subscriptions, and training events.
    • To communicate regulatory updates, industry newsletters, and event invitations.
    • To comply with statutory obligations under South African law.
  1. Consent and Choice
    • By applying for membership or using our website, you consent to this data processing.
    • You may withdraw your consent for marketing communications at any time using the “unsubscribe” link.
    • Withdrawing operational consent may limit our ability to maintain your active professional membership.
  1. Information Security
    • We implement robust technical and organisational measures to secure your personal data.
    • Secured electronic data is protected by firewalls, encryption, and access-controlled servers.
    • Physical documents containing personal info are stored in locked facilities with restricted access.
    • We regularly review our security risks and update our data protection protocols.
  1. Third-Party Sharing
    • We do not sell, rent, or trade your personal information to third parties.
    • Information is only shared with trusted service providers who help run our business operations.
    • Operators (e.g., IT hosts, payment gateways) must sign strict POPIA-compliant data privacy agreements.
    • We may disclose data if legally required by South African law enforcement or regulatory authorities.
  1. Data Retention
    • We keep your personal information only as long as necessary for the purpose it was collected.
    • Active member data is retained for the full duration of your membership profile.
    • Inactive member records are kept in line with statutory financial and legal retention periods.
    • Once the retention period expires, your data is securely deleted, destroyed, or de-identified.
  1. Your Data Rights
    • You have the right to request a copy of the personal information we hold about you.
    • You have the right to ask us to update, correct, or delete inaccurate or outdated data.
    • You have the right to object to the processing of your data for direct marketing purposes.
    • To exercise these rights, please contact our Information Officer using the details below.
  1. Information Officer Contact Details
    • For any POPIA queries, data access requests, or complaints, please reach out to our team:
    • Email: info@imcsa.org.za
    • Phone: +2711 789 9996
    • Physical Address: 12 Shelley Avenue Willowild, Sandton
  1. Complaints to the Regulator
    • If you feel we have not processed your data lawfully, you have the right to lodge a complaint.
    • Complaints must be directed to the South African Information Regulator.
    • Website: inforegulator.org.za
    • Email: info@inforegulator.org.za / complaints.IR@inforegulator.org.za