- Policy Owner
- Information Officer
- Approved By
- Board / Managing Executive
- Version
- 1.0
- Effective Date
- 16 September 2025
- Review Date
- Annual, or upon material regulatory/operational change
- Classification
- Corporate Governance Policy
1. Purpose
The purpose of this Policy is to establish the principles, responsibilities, controls and procedures implemented by eKash Group (“eKash”) for the lawful and responsible processing of personal information.
The Policy is intended to ensure compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), applicable regulations and other relevant South African legislation.
eKash recognises privacy and protection of personal information as fundamental components of responsible corporate governance, digital financial services, customer trust and information security.
eKash is committed to ensuring that personal information is:
- processed lawfully and transparently.
- collected for specific and legitimate purposes.
- adequate, relevant and not excessive.
- accurate and kept up to date where reasonably practicable.
- retained only for as long as reasonably required.
- protected against loss, damage, unauthorised destruction, access or disclosure.
- processed in a manner that respects the rights of data subjects.
2. Scope
This Policy applies to all personal information processed by or on behalf of eKash, irrespective of whether the information is processed electronically, digitally, manually, through paper records or through third-party platforms.
It applies to:
- directors and officers.
- permanent and temporary employees.
- contractors and consultants.
- agents and representatives.
- customers and prospective customers.
- borrowers and finance applicants.
- merchants and SMMEs.
- suppliers and service providers.
- business partners.
- investors and shareholders.
- employees and job applicants.
- website and application users.
- beneficiaries of programmes administered by eKash.
- visitors to eKash premises.
- any other natural or juristic person whose personal information is processed by eKash.
The Policy applies to all eKash systems and platforms, including websites, mobile applications, finance platforms, eBoleka or related financial solutions, customer relationship management systems, accounting systems, payment systems, cloud services and databases.
3. Legal and Regulatory Framework
This Policy must be read together with applicable South African legislation and regulatory requirements, including, where applicable:
- Protection of Personal Information Act 4 of 2013.
- Promotion of Access to Information Act 2 of 2000 (“PAIA”).
- Electronic Communications and Transactions Act 25 of 2002.
- Financial Intelligence Centre Act 38 of 2001 (“FICA”).
- National Credit Act 34 of 2005, where applicable.
- Companies Act 71 of 2008.
- Consumer Protection Act 68 of 2008.
- Tax Administration Act 28 of 2011.
- Basic Conditions of Employment Act 75 of 1997.
- applicable Information Regulator regulations, guidance and codes of conduct.
- other laws requiring eKash to collect, maintain, disclose or retain information.
Where another applicable law requires a longer retention period or additional processing of personal information, eKash shall comply with that legal obligation.
4. Definitions
For purposes of this Policy:
- Data Subject
- means the person to whom personal information relates.
- Personal Information
- means information relating to an identifiable living natural person and, where applicable under POPIA, an identifiable existing juristic person.
- Processing
- includes collecting, receiving, recording, organising, storing, updating, retrieving, using, distributing, transmitting, merging, linking, restricting, deleting or destroying personal information.
- Responsible Party
- means the party that determines the purpose and means of processing personal information.
- Operator
- means a person or organisation that processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that responsible party.
- Information Officer
- means the person responsible for ensuring that eKash complies with POPIA and PAIA and performs the statutory responsibilities associated with that role.
- Special Personal Information
- includes categories of information afforded additional protection under POPIA.
- Security Compromise
- means unauthorised access to, acquisition, loss, destruction or disclosure of personal information, or reasonable grounds for believing that such access or acquisition has occurred.
5. POPIA Processing Principles
eKash shall manage personal information according to the conditions for lawful processing established by POPIA. These principles include:
5.1 Accountability
eKash shall take appropriate measures to ensure that the requirements of POPIA are implemented throughout the organisation.
5.2 Processing Limitation
Personal information shall be processed lawfully and in a reasonable manner that does not unjustifiably infringe the privacy of a data subject.
5.3 Purpose Specification
Personal information shall be collected for specific, explicitly defined and lawful purposes related to the activities and functions of eKash.
5.4 Further Processing Limitation
Where information is subsequently used for another purpose, eKash shall ensure that such further processing is compatible with the purpose for which the information was originally collected or is otherwise permitted by law.
5.5 Information Quality
eKash shall take reasonably practicable measures to ensure that personal information is complete, accurate, not misleading and updated where necessary.
5.6 Openness
eKash shall process information transparently and provide appropriate privacy notices explaining relevant processing activities.
5.7 Security Safeguards
Appropriate technical and organisational measures shall be maintained to protect personal information.
5.8 Data Subject Participation
Data subjects shall be provided with appropriate mechanisms to exercise their rights regarding their personal information.
6. Categories of Personal Information
Depending on the relevant product, service or relationship, eKash may process:
6.1 Identification and KYC Information
- full name.
- identity or passport number.
- date of birth.
- nationality.
- photograph.
- signatures.
- company registration information.
- director/shareholder information.
- beneficial ownership information.
- verification documentation.
6.2 Contact Information
- residential and business addresses.
- email addresses.
- mobile and telephone numbers.
- preferred communication methods.
6.3 Financial Information
- bank account information.
- bank statements.
- income information.
- financial statements.
- turnover information.
- payment records.
- transaction history.
- assets and liabilities.
- loan information.
- credit-related information.
- affordability information.
- funding requirements.
6.4 Business Information
- company registration records.
- tax information.
- B-BBEE information.
- ownership information.
- contracts.
- invoices.
- purchase orders.
- supplier information.
- business performance information.
6.5 Employment Information
- CVs.
- employment history.
- qualifications.
- employment contracts.
- payroll information.
- performance records.
- leave information.
- statutory employment records.
6.6 Digital and Technical Information
- IP addresses.
- device identifiers.
- application usage information.
- browser information.
- authentication records.
- login records.
- security logs.
- cookies and similar technologies.
- audit trails.
7. Purposes for Processing Information
eKash may process personal information for legitimate operational and legal purposes including:
- opening and managing customer accounts.
- customer onboarding.
- identity and business verification.
- KYC and due diligence.
- financial diagnostic assessments.
- processing finance applications.
- affordability and credit assessments.
- fraud detection and prevention.
- anti-money-laundering controls.
- processing payments and transactions.
- administering loans and financial products.
- managing collections and repayments.
- providing business development services.
- customer service and complaints handling.
- regulatory reporting.
- tax administration.
- supplier management.
- employment administration.
- contractual administration.
- cybersecurity and fraud monitoring.
- statistical and management reporting.
- improving eKash products and services.
- marketing where legally permitted.
- protecting eKash’s legitimate business interests.
- complying with applicable laws and lawful regulatory requirements.
8. Lawful Basis for Processing
eKash shall ensure that a lawful justification exists before processing personal information. Depending on the circumstances, processing may occur where:
- the data subject has provided consent.
- processing is necessary for the conclusion or performance of a contract.
- processing complies with an obligation imposed by law.
- processing protects a legitimate interest of the data subject.
- processing is necessary for the proper performance of a public-law duty by a public body.
- processing is necessary for pursuing the legitimate interests of eKash or a third party to whom information is supplied, subject to the rights and interests of the data subject.
Consent shall not automatically be relied upon where another appropriate lawful basis exists.
Where consent is required, it must be capable of being demonstrated.
9. Customer Onboarding, KYC and Financial Information
Because eKash provides technology and financial-services-related solutions, enhanced controls shall apply to customer financial information. eKash shall, where appropriate:
- verify customer identity.
- verify business registration and ownership.
- verify banking information.
- conduct required KYC and due-diligence processes.
- obtain supporting documents necessary for finance applications.
- verify invoices and purchase orders where relevant.
- assess financial information.
- maintain appropriate audit trails.
- restrict access to financial documents.
- disclose information only to authorised parties.
Information collected for financial applications shall not be used for unrelated purposes unless permitted by POPIA or another applicable law.
10. Credit and Financial Assessments
Where eKash conducts or facilitates a financial diagnostic, affordability assessment, credit assessment or funding-readiness assessment, the information used may include:
- bank statements.
- credit information.
- financial statements.
- management accounts.
- cash-flow information.
- turnover.
- liabilities.
- existing finance.
- repayment history.
- invoices.
- purchase orders.
- other relevant financial information.
eKash shall implement appropriate controls around access to and use of this information.
Where decisions involving automated processing materially affect a data subject, eKash shall ensure that such processing complies with applicable POPIA requirements and that appropriate human review, transparency or other safeguards are implemented where required.
11. Special Personal Information
Special personal information shall only be processed where permitted by POPIA.
Access to such information shall be restricted to employees or service providers with a legitimate and authorised need to process it.
Additional technical and organisational safeguards may be implemented depending on the sensitivity and risk associated with the information.
12. Children’s Personal Information
eKash does not intentionally process children’s personal information unless such processing is necessary, lawful and appropriately authorised.
Where children’s information must be processed, eKash shall ensure that the processing complies with the specific requirements of POPIA and any applicable authorisation requirements.
13. Data Minimisation
eKash shall endeavour to collect only the personal information that is adequate, relevant and reasonably necessary for the identified processing purpose.
Employees must not collect personal information merely because it may potentially be useful at some future date.
Forms, systems and onboarding processes should periodically be reviewed to remove unnecessary data fields.
14. Data Accuracy
Reasonable measures shall be taken to maintain accurate and current information.
Data subjects may request correction of inaccurate or incomplete information.
Employees who become aware of materially inaccurate personal information must take appropriate steps to correct or escalate the information.
15. Privacy Notices
Where required, eKash shall provide data subjects with appropriate privacy notices explaining matters including:
- the information being collected.
- the purpose of collection.
- whether providing the information is mandatory or voluntary.
- consequences of failing to provide required information.
- relevant legal authority.
- potential recipients of the information.
- cross-border processing where relevant.
- data-subject rights.
- contact information for privacy-related queries.
Privacy notices should be presented in clear and reasonably understandable language.
16. Data Subject Rights
Subject to applicable legislation, data subjects may:
- request confirmation of whether eKash holds their personal information.
- request access to personal information held about them.
- request correction of inaccurate information.
- request deletion or destruction where legally permissible.
- object to certain processing.
- withdraw consent where processing is based on consent.
- object to certain direct marketing.
- submit complaints concerning the processing of personal information.
- lodge complaints with the Information Regulator.
Requests shall be directed to the Information Officer or designated privacy contact.
eKash shall maintain a procedure for verifying the identity of persons submitting requests before disclosing personal information.
17. Direct Marketing
eKash shall conduct electronic direct marketing in accordance with POPIA and other applicable legislation.
Where consent is required, appropriate consent shall be obtained before marketing communications are sent.
Marketing communications must provide an appropriate mechanism for recipients to opt out of future marketing.
Opt-out requests shall be implemented within a reasonable period and recorded to prevent inappropriate re-enrolment.
18. Information Sharing
Personal information may only be disclosed where there is an appropriate lawful basis. Potential recipients may include:
- authorised eKash employees.
- banks and payment service providers.
- lenders and funding partners.
- credit bureaux where legally permissible.
- identity-verification providers.
- KYC and compliance service providers.
- accountants and auditors.
- legal advisers.
- cloud and technology service providers.
- debt collection service providers.
- insurers.
- government departments.
- SARS.
- regulatory authorities.
- law-enforcement agencies where legally authorised.
- other contracted service providers.
Disclosure must be limited to information reasonably required for the intended purpose.
19. Third-Party Operators and Service Providers
Where a third party processes personal information on behalf of eKash, eKash shall conduct appropriate risk-based due diligence and establish contractual safeguards. Agreements should, where applicable, require operators to:
- process information only under eKash’s authority.
- maintain confidentiality.
- implement appropriate security safeguards.
- notify eKash promptly of suspected or confirmed security compromises.
- restrict unauthorised subcontracting.
- return or securely destroy information when required.
- assist eKash with applicable POPIA obligations.
20. Cross-Border Transfers
Personal information shall not be transferred outside South Africa unless the requirements governing transborder information flows under POPIA are satisfied.
Before implementing material cross-border processing arrangements, eKash shall consider:
- the country where information will be processed.
- applicable privacy protections.
- contractual protections.
- security measures.
- nature and sensitivity of the information.
- whether any regulatory approval or prior authorisation is required.
Cloud-service arrangements shall be assessed for the geographic location and legal jurisdiction of data hosting and processing.
21. Information Security
eKash shall implement appropriate and reasonable technical and organisational security safeguards having regard to the nature of the information and foreseeable risks. Controls may include:
- encryption.
- multi-factor authentication.
- role-based access controls.
- password controls.
- network security.
- endpoint protection.
- secure backups.
- vulnerability management.
- patch management.
- logging and monitoring.
- secure software development practices.
- data-loss prevention measures.
- physical security.
- employee confidentiality obligations.
- secure document disposal.
- periodic security assessments.
- incident-response procedures.
Access to personal information shall be based on the principle of least privilege.
22. Access Control
Employees shall only have access to information reasonably required to perform their duties. eKash shall establish processes for:
- authorising user access.
- modifying access when responsibilities change.
- terminating access when employment or contracts end.
- periodically reviewing privileged access.
- maintaining audit trails for critical systems.
Sharing user accounts or passwords is prohibited.
23. Information Security Incidents and Data Breaches
All employees, contractors and service providers must immediately report suspected loss, unauthorised disclosure, cybersecurity incidents or compromise of personal information. Examples include:
- lost or stolen devices.
- phishing incidents.
- compromised passwords.
- ransomware.
- emails sent to incorrect recipients.
- unauthorised database access.
- lost documents.
- disclosure of customer information.
- malicious insider activity.
- unauthorised access by service providers.
Upon becoming aware of a suspected compromise, eKash shall:
- contain the incident.
- preserve relevant evidence.
- determine the nature and extent of the compromise.
- identify affected systems and information.
- assess risks to affected data subjects.
- implement remediation measures.
- determine notification obligations.
- notify relevant parties as required by law.
- document the incident and response.
- implement corrective and preventative measures.
24. Security Compromise Notification
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, eKash shall follow the notification requirements prescribed by POPIA.
The Information Officer shall coordinate any required notification to the Information Regulator and affected data subjects.
Notifications shall be made in accordance with applicable statutory and regulatory requirements and shall provide sufficient information to enable affected persons to take appropriate protective measures.
25. Record Retention
Personal information shall not be retained longer than permitted or necessary for the purpose for which it was collected, unless:
- retention is required or authorised by law.
- eKash reasonably requires the record for lawful purposes.
- retention is required by a contract.
- the data subject has consented to retention where legally appropriate.
eKash shall maintain a Records Retention Schedule covering major categories of business information.
26. Secure Destruction
When personal information is no longer required, it shall be destroyed, deleted or de-identified in a manner that prevents reconstruction in an intelligible form. Appropriate methods may include:
- secure shredding.
- certified document destruction.
- secure electronic deletion.
- cryptographic erasure.
- media destruction.
- irreversible anonymisation.
27. Employee Responsibilities
All employees and contractors are responsible for protecting personal information. They must:
- comply with this Policy.
- maintain confidentiality.
- use personal information only for authorised purposes.
- protect passwords and authentication credentials.
- follow information-security requirements.
- avoid unauthorised downloads or transfers.
- immediately report security incidents.
- complete required privacy training.
- cooperate with investigations and audits.
Unauthorised access, disclosure, copying, alteration or destruction of personal information may constitute misconduct and may result in disciplinary action.
28. Information Officer
The eKash Information Officer shall oversee the organisation’s POPIA compliance programme. Responsibilities include:
- promoting organisational compliance.
- overseeing implementation of privacy policies.
- managing data-subject requests.
- monitoring privacy risks.
- maintaining required regulatory registrations.
- overseeing privacy impact assessments.
- coordinating breach-response activities.
- engaging with the Information Regulator.
- overseeing privacy awareness and training.
- monitoring third-party privacy risks.
- reporting significant privacy matters to management.
Deputy Information Officers may be appointed where necessary.
29. Privacy Impact Assessments
eKash shall conduct appropriate privacy assessments when introducing new products, systems or processing activities that may create significant privacy risks. This should particularly apply to projects involving:
- large volumes of financial information.
- credit scoring.
- automated decision-making.
- biometric information.
- artificial intelligence.
- behavioural profiling.
- new mobile applications.
- integration with external databases.
- cloud migration.
- new lending platforms.
- material cross-border processing.
Privacy should be incorporated into system and product design from the earliest reasonable stage.
30. Privacy by Design and Default
eKash shall seek to integrate privacy controls into the design of its digital platforms. Systems should, where appropriate:
- collect only necessary information.
- use secure authentication.
- encrypt sensitive information.
- restrict access by role.
- maintain audit trails.
- provide appropriate consent mechanisms.
- provide privacy notices.
- facilitate data-subject requests.
- support secure deletion and retention management.
31. Automated Decision-Making and Artificial Intelligence
Where eKash uses algorithms, artificial intelligence, credit-scoring models or automated systems in assessing customers, finance applications or risks, eKash shall ensure compliance with applicable POPIA requirements. Controls may include:
- documenting the purpose of the model.
- controlling the data used.
- testing data quality.
- monitoring model outputs.
- implementing human oversight where appropriate.
- maintaining audit trails.
- providing appropriate transparency.
- ensuring that automated processing does not unlawfully prejudice data subjects.
33. Employee Training and Awareness
Employees with access to personal information shall receive appropriate POPIA and information-security awareness training. Training should address:
- POPIA principles.
- confidentiality.
- phishing.
- password security.
- customer information.
- handling financial documents.
- data-subject requests.
- breach reporting.
- direct marketing.
- secure disposal.
Training shall be refreshed periodically.
34. Third-Party Risk Management
eKash shall consider privacy and information-security risks when appointing service providers. Higher-risk providers may be subject to enhanced due diligence, particularly providers that:
- host customer databases.
- process financial information.
- conduct KYC.
- process payments.
- perform credit assessments.
- provide cloud infrastructure.
- have privileged access to eKash systems.
35. Record of Processing Activities
eKash should maintain an appropriate information inventory or processing register identifying material processing activities. The register should record, where appropriate:
- information categories.
- data subjects.
- processing purposes.
- lawful justification.
- information sources.
- recipients.
- systems used.
- operators.
- storage locations.
- cross-border transfers.
- retention periods.
- applicable security measures.
36. Regulatory Cooperation
eKash shall cooperate with lawful requests, investigations, assessments and enforcement processes conducted by the Information Regulator and other authorised regulators.
All regulatory communications concerning POPIA shall be escalated to the Information Officer and executive management.
37. Complaint Management
Privacy complaints shall be:
- acknowledged.
- recorded.
- investigated.
- appropriately escalated.
- responded to within reasonable or legally required periods.
- retained for audit purposes.
Where appropriate, root-cause analysis shall be conducted and corrective measures implemented.
38. Monitoring and Auditing
eKash shall periodically assess its compliance with this Policy. Reviews may include:
- access-control reviews.
- information-security assessments.
- privacy audits.
- data-retention reviews.
- operator assessments.
- breach-register reviews.
- consent-management reviews.
- direct-marketing reviews.
- employee-training reviews.
- assessments of new systems and products.
Material findings shall be reported to management and corrective actions tracked.
39. Non-Compliance
Failure by employees, contractors or representatives to comply with this Policy may result in:
- suspension or restriction of system access.
- disciplinary action.
- termination of contractual arrangements.
- internal investigation.
- civil or regulatory consequences.
- referral to appropriate authorities where legally required.
40. Supporting Policies and Procedures
This Policy should be supported by appropriate operational documents, including:
- Privacy Notice.
- PAIA Manual.
- Information Security Policy.
- Data Retention and Destruction Policy.
- Data Breach Response Procedure.
- Data Subject Access Request Procedure.
- Operator/Data Processing Agreement template.
- Employee Confidentiality Undertaking.
- Direct Marketing and Consent Procedure.
- Cookie Policy.
- Access Control Policy.
- Acceptable Use Policy.
- Records Management Policy.
- Privacy Impact Assessment template.
- POPIA Compliance Register.
41. Contact Details
All requests or queries concerning personal information should be directed to:
eKash Group
Email: POPIAQUERIES@ekashgroup.co.za
Telephone: 087-152-5853
Physical Address: 6 Kikuyu Road, Sunninghill, Sandton, 2191
Data subjects may also lodge complaints with the Information Regulator (South Africa) through the Regulator’s prescribed processes.
42. Policy Review
This Policy shall be reviewed at least annually and whenever there is:
- a material change in POPIA or associated regulations.
- regulatory guidance affecting eKash.
- a significant change to eKash’s operations.
- introduction of a new financial or technology product.
- significant change to information systems.
- material security incident.
- introduction of material automated decision-making.
- significant change in the categories of personal information processed.
Have a question about this policy?
Contact Us