Accountability
Responsibility is assigned, processing activities are documented and privacy requirements are considered when services and systems are selected.
POPIA compliance approach
This page explains how Supermarketing applies the Protection of Personal Information Act, 2013 in our own business and when we process information for a client.
Last reviewed: 16 August 2026
We determine the purpose and means of processing, such as website enquiries, supplier records and our own client administration.
We process information for a client under a contract or mandate and follow the client’s lawful instructions and agreed safeguards.
The eight conditions
POPIA does not prescribe one identical control for every organisation or data set. It requires accountable, lawful and reasonable processing supported by safeguards appropriate to the circumstances and risk.
Responsibility is assigned, processing activities are documented and privacy requirements are considered when services and systems are selected.
We collect information that is relevant to a defined purpose and use an appropriate lawful justification, including consent where it is required.
Information is collected for a specific business, contractual or legal purpose and is not retained indefinitely.
Information is not reused for an unrelated purpose unless the further use is compatible, authorised or otherwise permitted by law.
Reasonable steps are taken to keep the information we rely on accurate, complete and up to date.
We explain what is collected, who is responsible, why it is needed and how a person can raise a question or request.
Reasonable technical and organisational controls are applied according to the sensitivity of the information and the risks involved.
People may request access, correction or deletion and may object to certain processing, subject to POPIA and lawful limitations.
Client and retail data
Our services can involve campaign briefs, store contacts, account permissions, customer enquiries and other client-controlled information. That information must be treated differently from ordinary creative content.
For work in the Pick n Pay retail environment, Supermarketing is subject to written data-processing obligations that reflect the operator requirements in sections 19 to 21 of POPIA and the client’s additional security standards.
Client information is processed only for the agreed service, under the client’s lawful instructions and with the knowledge or authorisation required by the contract.
Access is limited to authorised people who need the information for their role and who are subject to confidentiality and acceptable-use obligations.
We assess the systems used for client work, apply access controls and require appropriate safeguards from service providers that process information on our behalf.
Suspected unauthorised access, loss, misuse or disclosure is escalated promptly, investigated and reported under the applicable legal and contractual process.
Sub-processors and cross-border processing are handled according to POPIA, the client contract and any required notice, consent or written authorisation.
At the end of a service or when validly instructed, client information is returned, deleted or securely retained only where the law or an agreed recordkeeping requirement allows it.
These contractual controls demonstrate a formal commitment to client data protection. They do not mean that Supermarketing is certified, audited or endorsed by Pick n Pay, and they do not replace the specific instructions or responsibilities in the applicable client agreement.
Security governance
Our approach includes identifying foreseeable risks, applying safeguards, checking that controls remain effective and updating them when systems, suppliers, threats or client requirements change.
Security incidents
A suspected loss, unauthorised access, disclosure, alteration or misuse of personal information should be reported immediately to the Information Officer. We assess the facts, contain the risk, preserve relevant information and follow the notification duties that apply to the incident.
Where we act as an operator, the relevant client is notified within the timing and process required by the contract. Where Supermarketing is the responsible party, notifications to affected people and the Information Regulator are handled in accordance with POPIA.
Report a privacy or security concern
info@supermarketing.co.zaPlease mark the message for the attention of the Information Officer. Do not include passwords or unnecessary copies of the affected information.
Data-subject requests
A person may ask whether we hold information about them, request access, ask for inaccurate or outdated information to be corrected, or request deletion where we are no longer authorised to retain it.
We will confirm identity, identify the relevant records, consider any lawful limitation and respond through the process required by POPIA and PAIA. If the information is controlled by one of our clients, we may refer or coordinate the request with that client.
Continuous improvement
New services, systems, advertising tools, integrations and client requirements can change the privacy risk. We review this approach when material changes are introduced and update the public information where necessary.
Optional website tracking
With your permission, we use Meta advertising technology to understand page visits and completed enquiry forms. We do not send names, contact details, messages or other form content to Meta. Meta may receive technical information such as your IP address, browser details and its own cookie identifiers. Declining will not affect how the website works.
Read our Privacy Policy