Data Sovereignty

Privacy & Protection.

In strict accordance with the Protection of Personal Information Act (POPIA) of South Africa.

Last Updated: May 1, 2026

01. Introduction and Definitions

ISS Investigations ("we", "us", "our") is a private investigation firm operating in South Africa. We are committed to protecting the privacy and ensuring the lawful processing of Personal Information of our clients, subjects of investigation, and website visitors in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

Responsible Party

ISS Investigations determines the purpose and means for processing Personal Information.

Data Subject

The natural or juristic person to whom the Personal Information relates.

Personal Information

Information relating to an identifiable, living, natural person and juristic person.

Special Personal Information

Information concerning religious beliefs, health, biometric data, or criminal behaviour.

Legal Disclaimer

This document does not constitute legal advice. We ensure it is accurate and compliant with the specific nature of investigative tradecraft and South African jurisdiction. For specific legal advice, consult a qualified attorney.


02. Compliance Oversight

Information Officer

In charge of POPIA compliance, data security audits, and privacy inquiries.

Jonathan van Rensburg privacy@iss-investigations.co.za +27 65 308 7750 95 Houtkop Road, Vereeniging

03. Information We Collect

Identity Data

Names, ID numbers, passport details, and physical addresses.

Account Data

Hashed passwords, portal access logs, and authentication tokens.

Case Data

Investigation-related information provided for legal defense and evidence.

Technical Data

IP addresses, browser fingerprinting, and device identifiers for security.

Financial Data

Payment information processed through secure payment gateways only.

Surveillance Data

Video footage, photographs, and audio recordings collected during investigations.

Evidence Data

Documents, reports, and chain-of-custody records for legal proceedings.

Communication Data

Email correspondence, portal messages, and call recordings where applicable.


04. Purposes of Processing

We process Personal Information for the following lawful purposes under POPIA:

  • Investigation Services: To conduct investigations as requested by clients for lawful purposes including litigation support, fraud detection, and due diligence.
  • Case Management: To manage investigation cases, track progress, and deliver results through the Secure Client Portal.
  • Legal Compliance: To comply with PSIRA regulations, court orders, and other legal obligations.
  • Security: To protect the security of our systems, clients, and investigation subjects.
  • Communication: To communicate with clients about case updates, invoices, and service-related matters.
  • Payment Processing: To process payments and issue invoices for services rendered.
  • Quality Assurance: To improve our services through internal quality control and training.

05. Data Retention Policy

We retain Personal Information only for as long as necessary for the purposes outlined above, unless required by law to retain it longer:

  • Active Cases: Information related to active investigations is retained until case closure.
  • Closed Cases: Case files are retained for 5 years after closure in accordance with PSIRA requirements.
  • Legal Proceedings: Information may be retained longer if involved in ongoing legal proceedings.
  • Financial Records: Financial records are retained for 7 years in accordance with tax regulations.
  • Portal Accounts: Inactive portal accounts are deactivated after 12 months of inactivity.
  • Secure Destruction: Upon retention expiry, data is securely deleted or anonymized in accordance with POPIA.

06. Third-Party Disclosures

We may disclose Personal Information to third parties only in specific circumstances:

  • Legal Authorities: When required by court order, subpoena, or other legal process.
  • PSIRA: To the Private Security Industry Regulatory Authority for compliance purposes.
  • Service Providers: To trusted third-party service providers (e.g., payment processors, IT services) under strict confidentiality agreements.
  • Legal Counsel: To attorneys representing clients in legal proceedings.
  • Law Enforcement: To law enforcement agencies when required by law or to prevent criminal activity.
  • Subcontractors: To PSIRA-registered subcontractors assisting with investigations, bound by identical confidentiality obligations.
  • No Sale of Data: We never sell Personal Information to third parties for marketing or commercial purposes.

07. Data Security Measures

We implement industrial-grade security measures to protect Personal Information:

Encryption

End-to-end encryption for data in transit and AES-256 encryption for data at rest.

Access Controls

Multi-factor authentication, role-based access, and regular access reviews.

CSRF Protection

Cross-site request forgery protection on all forms and portal interactions.

Password Security

Bcrypt hashing with salt for all password storage and enforcement of strong password policies.

Secure Storage

South African data centre hosting with ISO 27001 certification.

Regular Audits

Quarterly security audits and penetration testing by independent security firms.


08. Data Breach Notification

In the event of a data breach, we follow POPIA notification requirements:

  • Assessment: Immediate assessment of the breach scope and potential impact on data subjects.
  • Containment: Immediate measures to contain the breach and prevent further data loss.
  • Notification to IR: Notification to the Information Regulator within 72 hours of becoming aware of the breach.
  • Notification to Data Subjects: Notification to affected data subjects if the breach poses a real risk of harm.
  • Notification Content: Breach notifications include the nature of the breach, data compromised, and remediation steps.
  • Documentation: Comprehensive documentation of the breach and response for regulatory compliance.

09. Your Rights (Data Subject)

Under POPIA, you have the following rights regarding your Personal Information:

Right to Access

Request confirmation of whether we process your Personal Information and access to that information.

Right to Correction

Request correction of inaccurate or incomplete Personal Information we hold about you.

Right to Deletion

Request deletion of your Personal Information if no longer required for the original purpose.

Right to Object

Object to processing of your Personal Information for direct marketing purposes.

Right to Portability

Request transfer of your Personal Information to another responsible party in a structured format.

Right to Complain

Submit a complaint to the Information Regulator if you believe your rights have been violated.

South African Information Regulator

For complaints about POPIA violations:

complaints.IR@justice.gov.za

Website: www.justice.gov.za/information-regulator


10. Cookies and Tracking Technologies

We use cookies and tracking technologies for the following purposes:

  • Essential Cookies: Required for the Secure Client Portal to function properly (authentication, session management).
  • Security Cookies: Used for CSRF protection and security validation.
  • Analytics Cookies: Used to understand website usage and improve our services (anonymized data only).
  • Preference Cookies: Remember your language and display preferences.

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect portal functionality.


11. Client Portal Security

The Secure Client Portal implements additional security measures:

  • Two-Factor Authentication (2FA): Optional 2FA using TOTP authenticator apps.
  • Session Management: Automatic session timeout after 30 minutes of inactivity.
  • Activity Logging: Comprehensive logging of all portal activities for audit purposes.
  • Secure File Transfer: Encrypted file upload and download for evidence and reports.
  • IP Restrictions: Optional IP whitelisting for corporate clients.
  • Password Recovery: Secure password recovery with time-limited tokens.

12. Evidence Handling Privacy

Evidence collected during investigations receives special privacy protections:

  • Chain of Custody: Strict chain-of-custody documentation for all evidence.
  • Secure Storage: Physical evidence stored in access-controlled facilities; digital evidence in encrypted systems.
  • Redaction: Sensitive information redacted from reports before sharing with third parties.
  • Court Admissibility: Evidence handling procedures designed to ensure court admissibility.
  • Subject Privacy: Investigation subjects' privacy protected unless disclosure is legally required.

13. International Data Transfers

Our approach to international data transfers:

  • Primary Storage: All Personal Information is primarily stored within South Africa.
  • Trans-Border Restrictions: We do not transfer data internationally unless essential for case performance.
  • Equivalent Protection: International transfers only to jurisdictions with data protection laws equivalent to POPIA.
  • Client Authorization: International transfers require explicit client authorization.
  • Adequate Safeguards: Appropriate contractual and technical safeguards for any international transfers.

14. Children's Privacy

Our services are not directed to children under 18. We do not knowingly collect Personal Information from children. If we discover we have collected Personal Information from a child, we will take steps to delete it immediately. In investigations involving minors, we require parental or guardian consent where required by law.


15. Updates and Amendments

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or operational needs:

  • Notice: Material changes will be communicated via email and portal notification 30 days prior to effectiveness.
  • Legal Changes: Immediate changes may be made to comply with legal requirements without notice.
  • Continued Use: Continued use of our services after amendments constitutes acceptance of the updated policy.
  • Version History: Previous versions will be archived and available upon request.

16. Contact Information

For privacy inquiries, data access requests, or to report a security concern, please contact:

ISS Investigations Privacy Desk

Email: privacy@iss-investigations.co.za

National Contact Nr: +27 65 308 7750

Address: 95 Houtkop Road, Vereeniging, Gauteng, South Africa

Response time: Within 30 days for data access requests as required by POPIA

Concerned about your data footprints?

Consult our Privacy Desk →