GQ Beyond Holdings (Pty) Ltd is committed to protecting the personal information of all data subjects with whom it engages. This framework establishes the governance, accountability, policies, procedures, and controls by which the company ensures full compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), the Promotion of Access to Information Act 2 of 2000 (PAIA), and the Constitutional right to privacy.
Section 01
Purpose
This POPIA Compliance Framework sets out how GQ Beyond Holdings (Pty) Ltd collects, uses, stores, protects, and disposes of personal information across all its business operations. It provides a structured governance foundation that protects the rights of data subjects and ensures that all processing activities are lawful, transparent, and proportionate.
Section 02
Scope of Application
This framework applies to:
- GQ Beyond Holdings (Pty) Ltd and all its trading divisions — GQ Beyond Consulting, GQ Agentic AI, GQ Foundation, and Skills Training.
- All directors, employees, contractors, service providers, and operators acting on behalf of the company.
- All personal information processed by the company, including information relating to clients, employees, directors, suppliers, and regulatory bodies.
- Both electronic and manual (paper-based) records.
Section 03
Legislative Authority
This framework is adopted in accordance with the following legislation:
| Legislation | Relevance |
| Protection of Personal Information Act 4 of 2013 (POPIA) | Primary data protection legislation governing all personal information processing. |
| Promotion of Access to Information Act 2 of 2000 (PAIA) | Governs the right of access to information held by public and private bodies. |
| Constitution of the Republic of South Africa, 1996 | Section 14 — Right to Privacy; foundational basis for data protection in South Africa. |
Section 04
Governance Structure
4.1 Information Officer
In terms of POPIA, the Chief Executive Officer of GQ Beyond Holdings (Pty) Ltd is designated as the Information Officer:
| Name | Sartha Shrina Du Plessis |
| Capacity | Chief Executive Officer — GQ Beyond Holdings (Pty) Ltd |
| Email | info@gqbeyond.co.za |
| Telephone | 063 804 2305 |
The Information Officer is responsible for: ensuring POPIA compliance across all divisions; registration with the Information Regulator; oversight of all data protection measures; handling data subject requests and complaints; reporting breaches to the Information Regulator; and ensuring all staff and contractors are trained in their POPIA obligations.
4.2 Deputy Information Officer
| Name | Morné Du Plessis |
| Capacity | Co-Founder & Chief Information and Automation Officer — GQ Beyond Holdings (Pty) Ltd |
Section 05
Conditions for Lawful Processing
GQ Beyond Holdings adheres to all eight conditions for lawful processing as set out in POPIA:
| # | Condition | How GQ Beyond Applies It |
| 1 | Accountability | The Information Officer takes overall responsibility for ensuring POPIA compliance across all divisions. |
| 2 | Processing Limitation | Personal information is collected only for lawful, specific purposes directly related to business activities. |
| 3 | Purpose Specification | Data subjects are informed of the purpose for which their information is collected at the time of collection. |
| 4 | Further Processing Limitation | Personal information is not processed in a manner incompatible with the original stated purpose. |
| 5 | Information Quality | Reasonable steps are taken to ensure that personal information is accurate, complete, and up to date. |
| 6 | Openness | GQ Beyond maintains a PAIA Manual and privacy notices to ensure transparency about processing activities. |
| 7 | Security Safeguards | Appropriate technical and organisational measures are implemented to protect personal information against loss, damage, or unauthorised access. |
| 8 | Data Subject Participation | Data subjects may access, correct, or request deletion of their personal information, and may object to processing. |
Section 06
Personal Information Inventory
GQ Beyond Holdings maintains a record of all processing activities in a Personal Information Inventory (Processing Register). This record includes:
- Categories of personal information collected (names, contact details, identity numbers, financial information).
- The purpose for which each category is processed.
- The categories of data subjects whose information is held.
- Storage locations — electronic and physical.
- Retention periods applicable to each category.
- Third-party operators who process information on the company's behalf.
The inventory is maintained by the Information Officer and reviewed annually or upon any significant change to processing activities.
Section 07
Consent & Lawful Basis for Processing
GQ Beyond Holdings processes personal information only where a lawful basis exists. The company may process personal information where:
- The data subject has given specific, voluntary, and informed consent; or
- Processing is required by law or to comply with a legal obligation; or
- Processing is necessary for the performance of a contract to which the data subject is a party; or
- Processing is necessary to protect the legitimate interests of the data subject or the company, provided this does not override the data subject's rights.
Where consent is the lawful basis, it is: obtained prior to processing; specific to the stated purpose; freely given without coercion; recorded and retained as evidence; and capable of being withdrawn by the data subject at any time.
Section 08
Security Safeguards
GQ Beyond Holdings implements appropriate technical and organisational security measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures include:
- Access control and authentication protocols for all electronic systems.
- Secure storage of both physical and electronic records.
- Confidentiality undertakings signed by all staff, contractors, and operators with access to personal information.
- Regular review of systems and processes to identify and address security vulnerabilities.
- Password-protected devices and encrypted communications where applicable.
Security measures are risk-based and are reviewed periodically to ensure they remain effective and proportionate.
Section 09
Operators & Third-Party Processors
Where GQ Beyond Holdings engages third parties (operators) to process personal information on its behalf, the following requirements apply:
- A written operator agreement is concluded with the third party prior to any processing commencing.
- The agreement requires the operator to implement adequate security safeguards equivalent to those of GQ Beyond.
- Processing by the operator is limited strictly to the agreed purpose and scope.
- The operator may not sub-contract processing to another party without the prior written consent of GQ Beyond.
- GQ Beyond remains accountable for the lawful processing of personal information by its operators.
Section 10
Data Subject Rights
GQ Beyond Holdings recognises and upholds the rights of all data subjects. Data subjects have the right to:
- Be informed about the collection and use of their personal information.
- Access their personal information held by the company.
- Request the correction or deletion of inaccurate, irrelevant, or outdated information.
- Object to the processing of their personal information on reasonable grounds.
- Lodge a complaint with the Information Regulator of South Africa.
All requests are handled within the timeframes prescribed by POPIA. Requests may be directed to the Information Officer at info@gqbeyond.co.za.
Section 11
Data Breach Management
In the event of an actual or suspected security compromise involving personal information, GQ Beyond Holdings will:
- Immediately assess the nature, scope, and likely impact of the breach.
- Notify the Information Regulator as soon as reasonably possible after becoming aware of the compromise.
- Notify affected data subjects where the breach is likely to result in harm, unless the Information Regulator directs otherwise.
- Implement corrective and remedial measures to address the breach and prevent recurrence.
- Record the incident in the GQ Beyond Breach Register (GQB-REG-002), including details of the breach, notifications made, and remedial actions taken.
Section 12
Retention & Destruction of Personal Information
Personal information held by GQ Beyond Holdings is:
- Retained only for as long as is necessary to fulfil the purpose for which it was collected.
- Retained for any longer period required by applicable law, contract, or legitimate business need.
- Securely destroyed, deleted, or anonymised once the retention period has expired and the information is no longer required.
Retention periods are documented in the Personal Information Inventory and reviewed as part of the annual compliance review.
Section 13
Training & Awareness
GQ Beyond Holdings ensures that all persons who handle personal information are adequately trained and aware of their obligations. This includes:
- POPIA awareness training for all new staff and contractors at the time of onboarding.
- Periodic refresher training and updates when legislative or regulatory changes occur.
- Guidance on secure information handling practices, including physical document security and digital hygiene.
- Clear escalation procedures for reporting suspected breaches or data subject complaints to the Information Officer.
Section 14
Monitoring & Review
This framework is a living document. GQ Beyond Holdings commits to:
- Reviewing this framework at least annually, or whenever significant changes occur in legislation, business operations, or processing activities.
- Updating all related policies and procedures to reflect any changes identified during the review.
- Enforcing compliance through internal governance controls and, where necessary, disciplinary action.
- Keeping records of reviews, updates, and compliance activities as part of the company's governance documentation.
Section 15
Relationship with PAIA
This POPIA Compliance Framework operates in conjunction with the company's PAIA Manual (GQB-POL-002). The PAIA Manual sets out the procedures by which persons may request access to records held by GQ Beyond Holdings. The Information Officer holds responsibility for both POPIA and PAIA compliance, and the two frameworks are administered in a coordinated manner to ensure consistency and legal compliance.
Section 16
Non-Compliance
Non-compliance with this framework and with POPIA is a serious matter. Failure to comply may result in:
- Internal disciplinary action in accordance with the company's employment and contractor policies.
- Regulatory investigation and penalties imposed by the Information Regulator of South Africa.
- Criminal liability as provided for in Chapter 11 of POPIA.
- Civil claims by affected data subjects.
- Significant reputational harm to GQ Beyond Holdings and its brand.
All staff, contractors, and operators are required to familiarise themselves with this framework and to act in accordance with its provisions at all times.
Approval & Sign-Off
| Approved By | Sartha Shrina Du Plessis, CEO |
| Date | 04 June 2026 |
| Next Review Date | 04 June 2027 |
GQ Beyond Holdings (Pty) Ltd · info@gqbeyond.co.za · 063 804 2305 · Empowering Businesses the AGNETIC™ Way