POPIA Compliance
Last updated: 12 May 2026
LEDGA is fully committed to compliance with the Protection of Personal Information Act 4 of 2013 (POPIA). This page explains our compliance practices and your rights as a data subject.
Fully Compliant
We comply with all 8 conditions for lawful processing under POPIA.
Bank-Level Security
256-bit encryption protects your data at rest and in transit.
Your Rights Protected
Exercise your data subject rights at any time.
What is POPIA?
The Protection of Personal Information Act (POPIA) is South Africa's data protection legislation that came into full effect on 1 July 2021. It regulates how organisations collect, store, use, and share personal information, and gives individuals (data subjects) specific rights over their personal data.
As a responsible party under POPIA, LEDGA is committed to protecting your personal information and ensuring transparent data practices.
The 8 Conditions for Lawful Processing
POPIA establishes 8 conditions for lawful processing. Here is how LEDGA complies with each:
1. Accountability
We take responsibility for complying with POPIA. Our Information Officer oversees data protection practices and can be contacted at privacy@ledga.co.za.
2. Processing Limitation
We only collect personal information that is necessary to provide our accounting services. Collection is done lawfully, with your knowledge, and only for specific, defined purposes.
3. Purpose Specification
We clearly communicate why we collect your data (accounting services, tax compliance, invoicing) and do not use it for unrelated purposes without your consent.
4. Further Processing Limitation
Any additional processing of your information is compatible with the original purpose of collection or done with your explicit consent.
5. Information Quality
We take reasonable steps to ensure your personal information is complete, accurate, and up to date. You can update your information at any time through your account settings.
6. Openness
We maintain transparency about our data practices through this POPIA notice, our Privacy Policy, and direct communication with data subjects.
7. Security Safeguards
We implement appropriate technical and organisational measures to protect your information, including encryption, access controls, regular audits, and staff training.
8. Data Subject Participation
You have the right to access, correct, and delete your personal information. We provide tools to exercise these rights and respond to requests within the required timeframes.
Your Rights Under POPIA
As a data subject, you have the following rights:
Right to Access
Request confirmation of what personal information we hold about you
Right to Correction
Request correction or deletion of inaccurate information
Right to Deletion
Request deletion of your information (subject to legal requirements)
Right to Object
Object to processing of your information for direct marketing
How to Exercise Your Rights
To exercise any of your data subject rights:
- Email our Information Officer at privacy@ledga.co.za
- Include your full name and the email associated with your account
- Specify which right you wish to exercise
- Provide any relevant details to help us locate your information
We will respond to your request within 30 days as required by POPIA. We may need to verify your identity before processing certain requests.
Data Breach Notification
In the unlikely event of a data breach that compromises your personal information, we will notify you and the Information Regulator as required by POPIA. Notification will include the nature of the breach, potential consequences, and measures we are taking to address it.
Operators (Third-Party Processors)
Where we engage third-party service providers (operators) to process personal information on our behalf, we ensure they provide sufficient guarantees of POPIA compliance. All operators are bound by written agreements that require appropriate security measures and limit processing to our instructions.
Contact Our Information Officer
For any POPIA-related queries or to exercise your rights:
LEDGA (Pty) Ltd
Information Officer: Privacy Team
Email: privacy@ledga.co.za
Phone: +27 10 123 4567
Address: Johannesburg, South Africa
Lodge a Complaint
If you believe your personal information has been processed unlawfully, you have the right to lodge a complaint with:
Information Regulator (South Africa)
Website: inforeg.org.za
Email: complaints.IR@justice.gov.za
Tel: 012 406 4818