Privacy Notice
Privacy Notice
Protection of personal information on the Brotherhood of Blessed Gérard website
Effective date: 17 September 2026
This Privacy Notice explains how the Brotherhood of Blessed Gérard collects, uses, stores, shares and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 and the Promotion of Access to Information Act 2 of 2000.
1 Responsible Party
| Particular | Details |
|---|---|
| Legal name | Brotherhood of Blessed Gérard |
| Legal form | Universitas personarum and association of persons established under the laws of the Republic of South Africa |
| Public benefit status | Public Benefit Organisation operated on a non-profit basis |
| PBO reference | 18/11/13/2769 |
| Income Tax reference | 9230442155 |
| Order of Malta registration | 1/AF |
Physical address: 61 Anderson Road, Mandeni 4490, KwaZulu-Natal, Republic of South Africa
Postal address: P O Box 440, Mandeni 4490, Republic of South Africa
Telephone: +27 82 492 4043
Email: bbg@bbg.org.za
Website: www.bsg.org.za
Blessed Gérard's Care Centre is a separate legal entity. Where the Care Centre collects personal information for its own medical, nursing, child-care, employment or operational purposes, it is responsible for that processing and should provide an appropriate separate or supplementary privacy notice.
2 Information Officer and POPIA Contact
POPIA Officer: Dr. Douglas Patrick Ross
Official position: Administrator of Goods
Email: managing-director@bgcc.ngo
Telephone: +27 32 940 1152
Physical address: 61 Anderson Road, Mandeni 4490, KwaZulu-Natal, Republic of South Africa
The Brotherhood will publish the name and contact details of the Information Officer or authorised Information Officer registered with the Information Regulator. Requests concerning personal information may be submitted to the contact stated above.
3 Scope
This Privacy Notice applies when a person visits this website, contacts the Brotherhood, makes a donation, applies for supporting membership, enquires about membership or voluntary service, subscribes to communications, or otherwise provides personal information through the website.
4 Personal Information We May Process
- identity and contact details, including name, address, email address and telephone number;
- information provided in correspondence and contact forms;
- membership, volunteer and application information;
- donation, payment, banking and tax-related information;
- communication preferences and records of consent;
- technical information, including Internet Protocol address, browser, device, referring page, access time, requested page, error and security logs;
- photographs, recordings or other information supplied or authorised for publication;
- any other information voluntarily provided for a stated purpose.
5 Purposes and Justification for Processing
We process personal information only where there is an adequate lawful justification under POPIA. Depending on the circumstances, processing may be necessary to obtain or perform an agreement, comply with a legal obligation, protect a legitimate interest, pursue the legitimate interests of the Brotherhood or a third party, perform a public-law duty, or act with the consent of the data subject.
The purposes may include operating and securing the website; responding to enquiries; administering membership and voluntary service; processing donations and issuing acknowledgements or tax documents; maintaining financial and organisational records; communicating about the Brotherhood and its charitable work; preventing fraud or misuse; and complying with legal and regulatory obligations.
6 Website and Server Data
When the website is accessed, the hosting provider and technical service providers may process an Internet Protocol address, date and time of access, requested page or file, access status, browser and device information, referring page, and technical error or security information. This information is used to deliver and secure the website, diagnose problems and prevent misuse.
Hosting provider: [Insert provider, address and country]
Normal server-log retention period: [Insert period]
7 Contact Enquiries
When a person contacts us by form, email or telephone, we process the information supplied to receive, assess and answer the enquiry. Mandatory fields are identified where applicable. If required information is not supplied, we may be unable to process the request. General correspondence is retained for [insert period], unless a longer legal or evidentiary period applies.
8 Donations and Supporting Memberships
For donations and supporting memberships, we may process names, contact details, addresses, payment information, donation amounts, payment dates and tax-related information. We use this information to administer payments, allocate donations, maintain accounting records, issue acknowledgements or tax certificates, and comply with financial, audit and tax obligations.
Payment provider or bank: [Insert provider and country]. A donation is not conditional upon consent to non-essential advertising or marketing communications.
9 Membership and Voluntary Service
Where a person applies for membership or voluntary service, we may process identification and contact details, qualifications, references and other information reasonably required to assess and administer the application. Additional information and applicable retention periods should be stated on the relevant application form.
10 Special Personal Information and Children
The Brotherhood may process information relating to religious beliefs and, in limited circumstances, other special personal information. Such information is processed only where permitted by POPIA or with the required consent. Personal information concerning a child is processed only where authorised by law or with the required consent of a competent person. Enhanced confidentiality and access controls apply.
Medical, nursing and child-care information collected by Blessed Gérard's Care Centre is governed by the Care Centre's own notices, consent documents and legal responsibilities.
11 Cookies and Similar Technologies
The website uses cookies or similar technologies required for technical operation, functionality and security. Analytics, marketing, advertising or personalisation technologies will be activated only after appropriate information has been provided and consent obtained where required. Consent may be withdrawn through the website privacy or cookie settings.
The website must maintain a current cookie list identifying each provider, purpose, information collected, cookie or technology used, storage period, recipient, international transfer and method of withdrawal. In particular, the use of Google Tag Manager, Google Analytics, Google Ads, YouTube, Facebook, Instagram and other embedded services must be documented if they are enabled.
12 Recipients and Operators
Where necessary, personal information may be disclosed to website-hosting, information-technology, email and security providers; banks and payment providers; accounting, audit and legal advisers; postal and communication providers; and competent authorities, courts or regulators. Operators processing information on our behalf must be subject to appropriate written confidentiality and security obligations. We do not sell personal information.
13 Transfers Outside South Africa
Some technical, communication, cloud-storage or payment providers may process personal information outside South Africa. Information is transferred to a foreign country only where the requirements of section 72 of POPIA are met, including adequate protection under law or a binding agreement, valid consent, contractual necessity or another permitted justification.
14 Retention and Destruction
We retain personal information only for as long as required for the purpose for which it was collected or by applicable legal, financial, tax, employment, safeguarding or archival obligations. When no longer required, information is securely deleted or destroyed, or de-identified so that it can no longer be linked to an identifiable person. Specific periods are recorded in the Brotherhood retention schedule.
15 Security
We maintain reasonable technical and organisational safeguards against loss, damage, unauthorised destruction, unlawful access, disclosure, alteration and misuse. Safeguards are reviewed as risks and technology change. Where there are reasonable grounds to believe that an unauthorised person has accessed or acquired personal information, the Information Regulator and affected data subjects will be notified in accordance with section 22 of POPIA.
16 Rights of Data Subjects
Subject to POPIA and PAIA, a data subject may ask whether we hold personal information about them; request access; request correction of inaccurate or incomplete information; request deletion or destruction where retention is no longer authorised; object to certain processing; withdraw consent for future processing; object to electronic direct marketing; and lodge a complaint with the Information Regulator.
We may require reasonable proof of identity before disclosing or changing information. Requests should be addressed to the POPIA contact above. The Brotherhood PAIA Manual and prescribed request forms are available at [insert link].
17 Direct Marketing and Fundraising Communications
Electronic promotional or fundraising communications are sent only where permitted by law. Every such message will identify the sender and provide a simple method of declining future communications. Consent may be withdrawn, or an objection submitted, at any time and without charge by contacting [insert email address] or using the unsubscribe facility.
18 External Websites and Social Media
This website may link to external websites and social-media platforms. Their operators are responsible for their own processing. Where embedded external content would transmit information merely because a page is opened, it will be activated only after consent where consent is required.
19 Automated Decision Making
We do not use information collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, affected persons will receive appropriate information before the processing begins.
20 Complaints to the Information Regulator
Information Regulator South Africa
Woodmead North Office Park
54 Maxwell Drive
Woodmead, Johannesburg 2191
Republic of South Africa
Postal address: P O Box 31533, Braamfontein, Johannesburg 2017
Email: enquiries@inforegulator.org.za
Website: inforegulator.org.za
Toll-free telephone: 0800 017 160
21 Changes to This Privacy Notice
We may amend this Privacy Notice when our processing activities, service providers or legal obligations change. The current version and its effective date will be published on this page.
Protection of Personal Information Policy
Introduction
Section 14 of the Constitution of the Republic of South Africa, 1996, provides that everyone has the right to privacy. The right to privacy includes a right to protection against the unlawful collection, retention, dissemination and use of personal information. With this in mind, the Protection of Personal Information Act was introduced.
The POPI Act requiresus, as a Non-Profit Organistation, to protect our Information assets from threats, whether internal or external, deliberate or accidental.
The purpose of this policy is to enable Blessed Gerard’s Care Centre to:
- Comply with the law in respect of the data it holds about individuals.
- Follow good practice.
- Protect Blessed Gerard’s Care Centre staff and other individuals.
- Protect the organisation from the consequences of a breach of its responsibilities.
This policy and compliance framework establishes measures and standards for the protection and lawful processing of information of both natural persons, juristic persons and legal entities within our organisation and provides principles regarding the right of individuals to privacy and to reasonable safeguarding of their Personal Information.
Information Officer Responsibilities
The Act requires that an Information Officer be appointed. The General Manager of Blessed Gerard’s Care Centre will hold this position.
The Information Officer is responsible for:
- The development, implementation and monitoring of this policy and compliance framework.
- Ensuring that this policy is supported by appropriate documentation.
- Ensuring that documentation is relevant and kept up to date.
- Ensuring this policy and subsequent updates are communicated to relevant managers, representatives, staff and associates, where applicable.
- Ensuring that appropriate policies and controls are in place for ensuring the information quality of Personal Information.
- Ensuring that appropriate security safeguards in line with the POPI Act for Personal Information are in place.
- Handling all aspects of relationship with the Regulator as foreseen in the POPI Act.
All employees, departments and individuals are responsible for adhering to this policy and for reporting any security breaches or incidents to the Information Officer.
Protection of Personal Information Act Principles
There are eight Principles defined within the Act which must be addressed to be compliant. These are well-accepted attributes which are adopted throughout South Africa as the guidelines for a successful POPIA implementation:
Principle 1: Accountability
Blessed Gerard’s Care Centre will take reasonable steps to ensure that all processing conditions that relate to the collection of Personal Information obtained from employees, volunteers, contractors or service providers, prospective contractors or service providers, prospective employees and patients is stored safely and securely in accordance with the POPI Act. For ease of reference, these groups will be termed as “Data Subjects” with regards to this policy.
Principle 2: Processing Limitation
The processing of Personal Information is only lawful if, given the purpose of processing, the information is adequate, relevant and not excessive.
- Blessed Gerard’s Care Centre will only collect and process information where absolutely necessary.
- Blessed Gerard’s Care Centre undertakes to gain written consent from Data Subjects where appropriate.
- Blessed Gerard’s Care Centre will collect Personal and Business Information directly from the above stipulated groups where possible.
- Once in Blessed Gerard’s Care Centre’s possession we will only process or release information with their consent, except where we are required to do so by law. In the latter case we will always inform the business or person.
Principle 3: Purpose Specification
Blessed Gerard’s Care Centre will only collect and process information for a specific purpose as set out and defined above.
- Blessed Gerard’s Care Centre will collect Personal and Business Information from Data Subjects to enable us to maintain mandatory human resources records, financial and legal records, medical records and prospective employment records.
- Where any information or media is used on the Brotherhood of Blessed Gerard’s website, this information or media will have prior permission of use by any referred to or presented party.
- The organisation has in place retention periods for any data collected.
Principle 4: Further Processing Limitation
Personal Information may not be processed further in a way that is incompatible with the purpose for which the information was collected initially. Blessed Gerard’s Care Centre collects Personal Information for specific reasons, as stated above and it will only be used for that purpose.
Personal Information may only be further processed if:
- The Data Subject has consented to the further processing.
- Personal Information is contained in a public record.
- Personal Information has been deliberately made public by the Data Subject.
- Further processing is necessary to maintain, comply with or exercise any law or legal right.
- Further processing is necessary to prevent or mitigate a threat to public health or safety, or the life or health of the Data Subject or a third party.
Principle 5: Information Quality
Blessed Gerard’s Care Centre shall take reasonable steps to ensure that Personal Information is complete, accurate, not misleading and updated. Blessed Gerard’s Care Centre shall periodically review Data Subject records to ensure that the Personal Information is still valid and correct.
- Blessed Gerard’s Care Centre is responsible for ensuring that all information collected is complete, up to date and accurate before we use it. This means that it may be necessary to request information from all relevant parties, from time to time, to update records and confirm
- that it is still relevant.
- Systems are in place to encourage and facilitate the entry of accurate Personal Information.
- Personal Information on any Data Subject will be held in as few places as possible.
- Plans are in place to ensure that when any information changes with regards to a Data Subject, systems are updated.
- All information will be stored securely and irrelevant or unneeded Personal Information will be deleted or destroyed.
Principle 6: Transparency / Openness
Blessed Gerard’s Care Centre will follow a policy of total transparency.
- Where any information is collected and processed the Data Subject will be made aware of the source of the information, what information has been collected and the purpose of collection and processing.
- The Data Subject will be made aware when the supply of Personal Information is mandatory or voluntary and the consequences to provide such information.
- The Data Subject will be made aware when the collection of Personal Information is a mandatory requirement of law.
- The Data Subject will be made aware if any Personal Information is requested or needs to be shared with a third party.
Principle 7: Security Safeguards
Blessed Gerard’s Care Centre will identify all reasonably foreseeable risks to information security and establish and maintain appropriate safeguards against such risks by ensuring technical and organisational measures are in place to secure and control the integrity of all Personal and Business Information. Measures are also in place to guard against the risk of loss, damage or destruction of Personal and Business Information. Personal Information and Business Information will also be protected against any unauthorised or unlawful access or processing. Blessed Gerard’s Care Centre is committed to ensuring that information is only used for legitimate purposes with consent and only by authorised employees of Blessed Gerard’s Care Centre.
- All written records are kept in secure areas and when in use will not to be left unattended. If left unattended, all Personal Information must be secured by locked doors.
- All electronic records must be saved to the Dataserver and not kept on local hard drives where reasonably practicable.
- All electronic equipment which holds Personal Information must be password protected.
- All CCTV camera footage is stored on the Digital Video Recorder (DVR) for a three week period before being overwritten.
- All Biometric data is safely secured on the Process-server.
- Any loss or theft of, or unauthorised access to, Personal Information must be immediately reported to the Information Officer and action taken.
Principle 8: Participation of Individuals
Data Subjects are entitled to know particulars of their Personal Information held by us, as well as the identity of any authorised employees of Blessed Gerard’s Care Centre that have access thereto. Data Subjects have the right to request access to, amendment of, or deletion of their Personal Information where appropriate through the correct channels. Blessed Gerard’s Care Centre will not disclose any Personal Information to any authorised party unless the identity of that party has been verified.
Processing of Special Personal Information
Blessed Gerard’s Care Centre will adhere to the legislation with regards to the processing of Special Personal Information which relates to the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or lifestyle or biometric information of a Data Subject. Special Personal Information includes criminal behaviour relating to alleged offences or proceedings dealing with alleged offences. Unless a general authorisation, alternatively a specific authorisation relating to the different types of Special Personal Information applies, a responsible party is prohibited from processing Special Personal Information.
Processing of Personal Information of Children
Blessed Gerard’s Care Centre will adhere to the process of Personal Information of Children. This applies to under-18 individuals, so an age check is required for all Personal Information records. General authorisation concerning Personal Information of Children only applies where under-18s are involved.
Operational Considerations
Monitoring
The Management of Blessed Gerard’s Care Centre and Information Officer are responsible for administering and overseeing the implementation of this policy and, as applicable, supporting guidelines, standard operating procedures, notices, consents and appropriate related documents and processes. All employees, departments and individuals directly associated with us are to be trained, according to their functions, in the regulatory requirements, policies and guidelines that govern the Protection of Personal Information. Blessed Gerard’s Care Centre will conduct periodic reviews and audits, where appropriate, to ensure compliance with this policy and guidelines.
Operating Controls
Blessed Gerard’s Care Centre shall ensure appropriate standard operating procedures that are consistent with this policy and regulatory requirements are in place. This will include:
Allocation of information security responsibilities.
Incident reporting and management.
Information security training and education.
Data backup.
Policy Compliance
Any breach/es of this policy may result in disciplinary action and possible termination of employment