Legal & Compliance Policy

zukisa360asset.co.za
Version 1.0
Effective: 15 July 2026 Owner: Legal/Compliance Officer Applies to: Employees, contractors, third‑party providers

1. Purpose and Scope

This Policy establishes the legal and regulatory framework for the operation of the website zukisa360asset.co.za. It is designed to ensure compliance with South African law, protect the rights of users ("Data Subjects" or "Consumers"), and mitigate legal risk for the business ("Responsible Party" / "Supplier").

This policy applies to all personal and non‑personal data processing activities, commercial transactions, and content management conducted via the website.

2. Data Protection and Privacy (POPIA)

2.1. Legal Basis

The website and its associated services are subject to the Protection of Personal Information Act 4 of 2013 (POPIA). As a Responsible Party, we are mandated to process personal information lawfully and transparently.

2.2. Conditions for Lawful Processing

All processing of personal information must adhere to the eight conditions for lawful processing, including accountability, processing limitation, purpose specification, and information quality.

2.3. Consent and Direct Marketing

2.4. Privacy and Cookie Policy

2.5. Cross‑Border Data Transfers

Personal information will not be transferred to a third party in a foreign country unless:

2.6. Information Officer

The business must appoint an Information Officer and Deputy Information Officer. This role is responsible for compliance with POPIA, handling Data Subject Access Requests (DSARs), and maintaining the PAIA manual.

2.7. Security Breach Notification

In the event of a security compromise, we will:

3. Consumer Protection (CPA)

3.1. Legal Basis

The operation of zukisa360asset.co.za is governed by the Consumer Protection Act 68 of 2008 (CPA). This Act grants consumers extensive rights regarding returns, refunds, and the quality of goods and services.

3.2. Return, Refund, and Warranty Policy

3.3. Plain Language and Transparency

All terms and conditions, descriptions, and prices on the website must be drafted in plain and understandable language. Complex legal jargon is prohibited and may render clauses unenforceable.

3.4. Direct Marketing Conduct

Telemarketing or promotional communications must comply with the times and mechanisms prescribed by the CPA and POPIA. Consumers must have the right to opt‑out.

4. Electronic Communications and Cybercrimes (ECT Act & Cybercrimes Act)

4.1. Supplier Information (ECT Act)

In compliance with the Electronic Communications and Transactions Act 25 of 2002 (ECT Act), the website must clearly display the following:

4.2. Prohibited Content (Harmful Data Messages)

The website and its user‑generated content areas (if any) must not host content that:

Such content is criminalised under the Cybercrimes Act 19 of 2020.

5. Compliance Roles and Responsibilities

Role Responsibility
Information Officer Liaise with the Information Regulator; manage data subject requests; oversee POPIA compliance.
Marketing Team Ensure all marketing campaigns have valid consent; maintain call records if telemarketing is used.
Customer Service Manage complaints and returns in line with the CPA; maintain records of resolutions.
IT / Security Ensure encryption of payment data; manage breach detection and reporting protocols.

6. Enforcement and Penalties

Non‑compliance with these policies can result in severe penalties, including:

POPIAFines up to R10 million and/or imprisonment of up to 10 years.
Cybercrimes ActFines and imprisonment of up to 15 years for offences.
Enforcement ActionThe Information Regulator has demonstrated a willingness to issue administrative fines (e.g., R500,000 fines) for unlawful disclosures.

7. Review and Updates

This policy will be reviewed annually or as necessary upon changes to legislation (e.g., PAIA amendments expected by the Regulator in 2026).