POPIA compliance approach

Privacy is an operating responsibility, not a footer statement.

This page explains how Supermarketing applies the Protection of Personal Information Act, 2013 in our own business and when we process information for a client.

Last reviewed: 16 August 2026

When we are the responsible party

We determine the purpose and means of processing, such as website enquiries, supplier records and our own client administration.

When we are an operator

We process information for a client under a contract or mandate and follow the client’s lawful instructions and agreed safeguards.

The eight conditions

The principles we use to guide each processing decision.

POPIA does not prescribe one identical control for every organisation or data set. It requires accountable, lawful and reasonable processing supported by safeguards appropriate to the circumstances and risk.

01

Accountability

Responsibility is assigned, processing activities are documented and privacy requirements are considered when services and systems are selected.

02

Processing limitation

We collect information that is relevant to a defined purpose and use an appropriate lawful justification, including consent where it is required.

03

Purpose specification

Information is collected for a specific business, contractual or legal purpose and is not retained indefinitely.

04

Further processing limitation

Information is not reused for an unrelated purpose unless the further use is compatible, authorised or otherwise permitted by law.

05

Information quality

Reasonable steps are taken to keep the information we rely on accurate, complete and up to date.

06

Openness

We explain what is collected, who is responsible, why it is needed and how a person can raise a question or request.

07

Security safeguards

Reasonable technical and organisational controls are applied according to the sensitivity of the information and the risks involved.

08

Data-subject participation

People may request access, correction or deletion and may object to certain processing, subject to POPIA and lawful limitations.

Client and retail data

Written controls support the work behind the scenes.

Our services can involve campaign briefs, store contacts, account permissions, customer enquiries and other client-controlled information. That information must be treated differently from ordinary creative content.

For work in the Pick n Pay retail environment, Supermarketing is subject to written data-processing obligations that reflect the operator requirements in sections 19 to 21 of POPIA and the client’s additional security standards.

Authorised purpose

Client information is processed only for the agreed service, under the client’s lawful instructions and with the knowledge or authorisation required by the contract.

Access and confidentiality

Access is limited to authorised people who need the information for their role and who are subject to confidentiality and acceptable-use obligations.

Systems and service providers

We assess the systems used for client work, apply access controls and require appropriate safeguards from service providers that process information on our behalf.

Incident management

Suspected unauthorised access, loss, misuse or disclosure is escalated promptly, investigated and reported under the applicable legal and contractual process.

Transfers and sub-processing

Sub-processors and cross-border processing are handled according to POPIA, the client contract and any required notice, consent or written authorisation.

Return and deletion

At the end of a service or when validly instructed, client information is returned, deleted or securely retained only where the law or an agreed recordkeeping requirement allows it.

These contractual controls demonstrate a formal commitment to client data protection. They do not mean that Supermarketing is certified, audited or endorsed by Pick n Pay, and they do not replace the specific instructions or responsibilities in the applicable client agreement.

Security governance

Controls are matched to the information and risk.

Our approach includes identifying foreseeable risks, applying safeguards, checking that controls remain effective and updating them when systems, suppliers, threats or client requirements change.

Examples of controls

Role-based and need-to-know access.
Confidentiality obligations and staff awareness.
Appropriate password, device and account security.
Secure transmission and controlled sharing.
Backup, malware protection and recovery measures.
Incident reporting and response procedures.
Review of relevant vendors and sub-processors.

Security incidents

Suspected compromises are escalated, not ignored.

A suspected loss, unauthorised access, disclosure, alteration or misuse of personal information should be reported immediately to the Information Officer. We assess the facts, contain the risk, preserve relevant information and follow the notification duties that apply to the incident.

Where we act as an operator, the relevant client is notified within the timing and process required by the contract. Where Supermarketing is the responsible party, notifications to affected people and the Information Regulator are handled in accordance with POPIA.

Report a privacy or security concern

info@supermarketing.co.za

Please mark the message for the attention of the Information Officer. Do not include passwords or unnecessary copies of the affected information.

Data-subject requests

A clear route for access, correction and deletion.

A person may ask whether we hold information about them, request access, ask for inaccurate or outdated information to be corrected, or request deletion where we are no longer authorised to retain it.

We will confirm identity, identify the relevant records, consider any lawful limitation and respond through the process required by POPIA and PAIA. If the information is controlled by one of our clients, we may refer or coordinate the request with that client.

How to submit a request

  1. 1Email info@supermarketing.co.za and mark the request for the Information Officer.
  2. 2State whether you want confirmation, access, correction, deletion or to object to processing.
  3. 3Identify the relationship, store, campaign or enquiry involved so we can locate the record.
  4. 4Provide reasonable proof of identity when requested.
  5. 5We will acknowledge and handle the request within the applicable legal and operational timeframe.

Continuous improvement

Compliance is reviewed as the business changes.

New services, systems, advertising tools, integrations and client requirements can change the privacy risk. We review this approach when material changes are introduced and update the public information where necessary.