1. Purpose and scope
Safety Management Group (Pty) Ltd ("SMG", "we", "us", or "our") is an outsourced health and safety compliance partner providing risk advisory, safety systems, audits, accredited training, and industrial relations support across South Africa.
We respect the privacy of every individual and organization with whom we engage. This Privacy Policy details how we collect, store, utilize, disclose, and secure personal information in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act 2 of 2000 (PAIA).
In the course of delivering professional services, SMG acts as:
- Responsible Party: When determining the purpose and means for processing information relating to our prospective clients, website visitors, training attendees, suppliers, and our own employees.
- Operator: When processing health and safety records, appointment letters, training registers, and incident data strictly on behalf of and under instructions from our client organizations.
2. Information we collect
We collect only the personal information necessary to deliver compliance services, manage commercial relationships, assess site risks, and fulfill legal requirements under South African law.
Client representatives and business contacts
- Full names, professional titles, and roles within the organization.
- Business email addresses, direct telephone numbers, and site addresses.
- Company registration numbers and VAT details for contracting and billing.
Health and safety operational data
- Workplace appointment details under Section 16.2, 17, and relevant regulations of the Occupational Health and Safety Act (OHS Act).
- Incident and accident reports, including incident date, workplace location, witness statements, and corrective actions.
- Contractor compliance packs, safety files, and competencies.
Training candidates and attendees
- Learner full names, national identity numbers or passport details.
- Attendance registers, competency assessments, and certification outcomes required for statutory Department of Employment and Labour, QCTO, and Saiosh accreditations.
Website visitors and digital tools
- Information submitted via our contact, consultation, checklist, and audit calculator forms.
- Technical usage data including IP address, browser type, and navigation paths captured through essential session logs.
3. Lawful basis for processing
Under POPIA Chapter 3, personal information may only be processed if specific conditions are met. SMG processes personal information on the following legal grounds:
- Performance of a contract: Delivering agreed health, safety, audit, training, or industrial relations services.
- Compliance with an obligation imposed by law: Fulfilling mandatory statutory duties under the Occupational Health and Safety Act 85 of 1993, the Compensation for Occupational Injuries and Diseases Act 130 of 1993 (COIDA), the Basic Conditions of Employment Act, and tax legislation.
- Legitimate interests: Protecting client workplace safety, defending legal claims, preventing occupational hazards, and maintaining system security.
- Consent: Where individuals explicitly agree to receive our insights newsletter or request assessment summaries via our online tools.
4. Special personal information
Special personal information under POPIA includes health information, biometric data, and trade union membership. Because SMG provides occupational risk and industrial relations services, we may process special personal information under the strict authorizations provided in Sections 26 to 32 of POPIA:
- Medical certificates of fitness and health data: Processed solely to establish compliance with medical surveillance requirements under the OHS Act and the Construction Regulations.
- Injury on duty and incident investigations: Processed to meet statutory reporting obligations under Section 24 of the OHS Act and COIDA claim administration.
- Industrial relations documentation: Processed in connection with disciplinary inquiries, dispute resolution, and CCMA proceedings where authorised by law.
Access to special personal information is strictly restricted to designated safety consultants and legal specialists on a need-to-know basis.
5. Security safeguards
In accordance with Condition 7 of POPIA, SMG maintains reasonable and appropriate technical, physical, and organizational measures to prevent loss of, damage to, or unauthorized destruction of personal information:
- Encryption and transmission: All data submitted through our digital interfaces is protected with TLS cryptographic protocols.
- Access controls: Strict role-based permissions, multi-factor authentication, and audited access to client files and candidate databases.
- Confidentiality agreements: All SMG consultants, safety auditors, and administrative staff are bound by non-disclosure and confidentiality obligations.
- Physical security: Hard-copy audit registers and branch files are stored in locked archives with monitored access control across our Cape Town, Johannesburg, Port Elizabeth, and East London offices.
6. Retention of records
Personal information is retained only for as long as necessary to fulfill the purpose for which it was collected, or as prescribed by South African statute:
| Record type | Governing statute | Retention period |
|---|---|---|
| Medical surveillance records & certificates of fitness | OHS Act Regulations | 40 years from the date of last entry |
| Incident registers (Annexure 1) & Section 24 reports | General Administrative Regulations | Minimum 3 years |
| Accredited training registers & learner files | QCTO & Saiosh standards | Minimum 5 years from certification |
| Commercial contracts, invoices & client files | Companies Act & Tax Administration Act | 7 years |
Once the statutory or contractual period expires, records are permanently destroyed, deleted, or de-identified using certified secure methods.
7. Your statutory rights under POPIA
As a data subject under South African law, you hold specific enforceable rights regarding your personal information held by SMG:
- Right of access: You may request confirmation of whether we hold personal information about you, and request a copy of that record in accordance with our PAIA Manual.
- Right to request correction: You may request the correction or updating of inaccurate, irrelevant, excessive, or out-of-date information using prescribed Form 2.
- Right to request deletion: You may request the destruction or deletion of personal information that SMG is no longer authorised to retain.
- Right to object: You may object at any time to the processing of personal information on reasonable grounds relating to your particular situation, using prescribed Form 1.
- Right to lodge a complaint: You may lodge a complaint with the Information Regulator if you believe your rights under POPIA have been infringed.
8. Information Officer & Regulator contact details
To exercise any of your rights or request further clarification regarding this policy, please contact our National Information Officer:
Safety Management Group Information Officer
Information Officer: R. Liebenberg
Physical address: The Atrium, 9th Floor on 5th Street, Sandton, Johannesburg, 2196
Postal address: PO Box 78120, Sandton, 2146
Email:[email protected]
Direct line: 083 564 6663 / 011 883 0000
If you are dissatisfied with our response, you have the right to contact the Information Regulator (South Africa):
The Information Regulator (South Africa)
Physical address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
General enquiries:[email protected]
POPIA complaints:[email protected]
Website:inforegulator.org.za
