GQ · BEYOND
← Back to Site
GQB-POL-001  ·  Version 2  ·  Statutory Compliance Document

POPIA Compliance Framework

Effective: 04 June 2025 Review: 04 June 2026 GQ Beyond Holdings (Pty) Ltd
Document No.
GQB-POL-001
Legislative Authority
POPIA Act 4 of 2013
Information Officer
Shrina Du Plessis, CEO
Contact
info@gqbeyond.co.za  ·  063 804 2305
GQ Beyond Holdings (Pty) Ltd is committed to protecting the personal information of all data subjects with whom it engages. This framework establishes the governance, accountability, policies, procedures, and controls by which the company ensures full compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), the Promotion of Access to Information Act 2 of 2000 (PAIA), and the Constitutional right to privacy.
Table of Contents
  1. Purpose
  2. Scope of Application
  3. Legislative Authority
  4. Governance Structure
  5. Conditions for Lawful Processing
  6. Personal Information Inventory
  7. Consent & Lawful Basis
  8. Security Safeguards
  9. Operators & Third-Party Processors
  10. Data Subject Rights
  11. Data Breach Management
  12. Retention & Destruction
  13. Training & Awareness
  14. Monitoring & Review
  15. Relationship with PAIA
  16. Non-Compliance
Section 01

Purpose

This POPIA Compliance Framework sets out how GQ Beyond Holdings (Pty) Ltd collects, uses, stores, protects, and disposes of personal information across all its business operations. It provides a structured governance foundation that protects the rights of data subjects and ensures that all processing activities are lawful, transparent, and proportionate.

Section 02

Scope of Application

This framework applies to:

  • GQ Beyond Holdings (Pty) Ltd and all its trading divisions — GQ Beyond Consulting, GQ Agentic AI, GQ Foundation, and Skills Training.
  • All directors, employees, contractors, service providers, and operators acting on behalf of the company.
  • All personal information processed by the company, including information relating to clients, employees, directors, suppliers, and regulatory bodies.
  • Both electronic and manual (paper-based) records.
Section 03

Legislative Authority

This framework is adopted in accordance with the following legislation:

LegislationRelevance
Protection of Personal Information Act 4 of 2013 (POPIA)Primary data protection legislation governing all personal information processing.
Promotion of Access to Information Act 2 of 2000 (PAIA)Governs the right of access to information held by public and private bodies.
Constitution of the Republic of South Africa, 1996Section 14 — Right to Privacy; foundational basis for data protection in South Africa.
Section 04

Governance Structure

4.1 Information Officer

In terms of POPIA, the Chief Executive Officer of GQ Beyond Holdings (Pty) Ltd is designated as the Information Officer:

NameSartha Shrina Du Plessis
CapacityChief Executive Officer — GQ Beyond Holdings (Pty) Ltd
Emailinfo@gqbeyond.co.za
Telephone063 804 2305

The Information Officer is responsible for: ensuring POPIA compliance across all divisions; registration with the Information Regulator; oversight of all data protection measures; handling data subject requests and complaints; reporting breaches to the Information Regulator; and ensuring all staff and contractors are trained in their POPIA obligations.

4.2 Deputy Information Officer

NameMorné Du Plessis
CapacityCo-Founder & Chief Information and Automation Officer — GQ Beyond Holdings (Pty) Ltd
Section 05

Conditions for Lawful Processing

GQ Beyond Holdings adheres to all eight conditions for lawful processing as set out in POPIA:

#ConditionHow GQ Beyond Applies It
1AccountabilityThe Information Officer takes overall responsibility for ensuring POPIA compliance across all divisions.
2Processing LimitationPersonal information is collected only for lawful, specific purposes directly related to business activities.
3Purpose SpecificationData subjects are informed of the purpose for which their information is collected at the time of collection.
4Further Processing LimitationPersonal information is not processed in a manner incompatible with the original stated purpose.
5Information QualityReasonable steps are taken to ensure that personal information is accurate, complete, and up to date.
6OpennessGQ Beyond maintains a PAIA Manual and privacy notices to ensure transparency about processing activities.
7Security SafeguardsAppropriate technical and organisational measures are implemented to protect personal information against loss, damage, or unauthorised access.
8Data Subject ParticipationData subjects may access, correct, or request deletion of their personal information, and may object to processing.
Section 06

Personal Information Inventory

GQ Beyond Holdings maintains a record of all processing activities in a Personal Information Inventory (Processing Register). This record includes:

  • Categories of personal information collected (names, contact details, identity numbers, financial information).
  • The purpose for which each category is processed.
  • The categories of data subjects whose information is held.
  • Storage locations — electronic and physical.
  • Retention periods applicable to each category.
  • Third-party operators who process information on the company's behalf.

The inventory is maintained by the Information Officer and reviewed annually or upon any significant change to processing activities.

Section 07

Consent & Lawful Basis for Processing

GQ Beyond Holdings processes personal information only where a lawful basis exists. The company may process personal information where:

  • The data subject has given specific, voluntary, and informed consent; or
  • Processing is required by law or to comply with a legal obligation; or
  • Processing is necessary for the performance of a contract to which the data subject is a party; or
  • Processing is necessary to protect the legitimate interests of the data subject or the company, provided this does not override the data subject's rights.

Where consent is the lawful basis, it is: obtained prior to processing; specific to the stated purpose; freely given without coercion; recorded and retained as evidence; and capable of being withdrawn by the data subject at any time.

Section 08

Security Safeguards

GQ Beyond Holdings implements appropriate technical and organisational security measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures include:

  • Access control and authentication protocols for all electronic systems.
  • Secure storage of both physical and electronic records.
  • Confidentiality undertakings signed by all staff, contractors, and operators with access to personal information.
  • Regular review of systems and processes to identify and address security vulnerabilities.
  • Password-protected devices and encrypted communications where applicable.

Security measures are risk-based and are reviewed periodically to ensure they remain effective and proportionate.

Section 09

Operators & Third-Party Processors

Where GQ Beyond Holdings engages third parties (operators) to process personal information on its behalf, the following requirements apply:

  • A written operator agreement is concluded with the third party prior to any processing commencing.
  • The agreement requires the operator to implement adequate security safeguards equivalent to those of GQ Beyond.
  • Processing by the operator is limited strictly to the agreed purpose and scope.
  • The operator may not sub-contract processing to another party without the prior written consent of GQ Beyond.
  • GQ Beyond remains accountable for the lawful processing of personal information by its operators.
Section 10

Data Subject Rights

GQ Beyond Holdings recognises and upholds the rights of all data subjects. Data subjects have the right to:

  • Be informed about the collection and use of their personal information.
  • Access their personal information held by the company.
  • Request the correction or deletion of inaccurate, irrelevant, or outdated information.
  • Object to the processing of their personal information on reasonable grounds.
  • Lodge a complaint with the Information Regulator of South Africa.

All requests are handled within the timeframes prescribed by POPIA. Requests may be directed to the Information Officer at info@gqbeyond.co.za.

Section 11

Data Breach Management

In the event of an actual or suspected security compromise involving personal information, GQ Beyond Holdings will:

  • Immediately assess the nature, scope, and likely impact of the breach.
  • Notify the Information Regulator as soon as reasonably possible after becoming aware of the compromise.
  • Notify affected data subjects where the breach is likely to result in harm, unless the Information Regulator directs otherwise.
  • Implement corrective and remedial measures to address the breach and prevent recurrence.
  • Record the incident in the GQ Beyond Breach Register (GQB-REG-002), including details of the breach, notifications made, and remedial actions taken.
Section 12

Retention & Destruction of Personal Information

Personal information held by GQ Beyond Holdings is:

  • Retained only for as long as is necessary to fulfil the purpose for which it was collected.
  • Retained for any longer period required by applicable law, contract, or legitimate business need.
  • Securely destroyed, deleted, or anonymised once the retention period has expired and the information is no longer required.

Retention periods are documented in the Personal Information Inventory and reviewed as part of the annual compliance review.

Section 13

Training & Awareness

GQ Beyond Holdings ensures that all persons who handle personal information are adequately trained and aware of their obligations. This includes:

  • POPIA awareness training for all new staff and contractors at the time of onboarding.
  • Periodic refresher training and updates when legislative or regulatory changes occur.
  • Guidance on secure information handling practices, including physical document security and digital hygiene.
  • Clear escalation procedures for reporting suspected breaches or data subject complaints to the Information Officer.
Section 14

Monitoring & Review

This framework is a living document. GQ Beyond Holdings commits to:

  • Reviewing this framework at least annually, or whenever significant changes occur in legislation, business operations, or processing activities.
  • Updating all related policies and procedures to reflect any changes identified during the review.
  • Enforcing compliance through internal governance controls and, where necessary, disciplinary action.
  • Keeping records of reviews, updates, and compliance activities as part of the company's governance documentation.
Section 15

Relationship with PAIA

This POPIA Compliance Framework operates in conjunction with the company's PAIA Manual (GQB-POL-002). The PAIA Manual sets out the procedures by which persons may request access to records held by GQ Beyond Holdings. The Information Officer holds responsibility for both POPIA and PAIA compliance, and the two frameworks are administered in a coordinated manner to ensure consistency and legal compliance.

Section 16

Non-Compliance

Non-compliance with this framework and with POPIA is a serious matter. Failure to comply may result in:

  • Internal disciplinary action in accordance with the company's employment and contractor policies.
  • Regulatory investigation and penalties imposed by the Information Regulator of South Africa.
  • Criminal liability as provided for in Chapter 11 of POPIA.
  • Civil claims by affected data subjects.
  • Significant reputational harm to GQ Beyond Holdings and its brand.

All staff, contractors, and operators are required to familiarise themselves with this framework and to act in accordance with its provisions at all times.

Approval & Sign-Off
Approved BySartha Shrina Du Plessis, CEO
Date04 June 2026
Next Review Date04 June 2027
GQ Beyond Holdings (Pty) Ltd  ·  info@gqbeyond.co.za  ·  063 804 2305  ·  Empowering Businesses the AGNETIC™ Way
© 2026 GQ Beyond Holdings (Pty) Ltd  ·  Reg No: 2024/598182/07  ·  POPIA Compliant  ·  PAIA Compliant
Privacy Policy Terms & Conditions POPIA Notice POPIA Framework Complaints Policy PAIA Manual