eKash Logo eKash
  • Products
    eBoleka eTrader eInsurance
  • Social Initiatives
    FREE
  • Contact Us
  • Features
  • Products
  • eboleka
  • eTrader
  • eInsurance
  • Social Initiatives
  • Free
  • Contact Us
Legal

PAIA Manual

eKash Group's POPIA Compliance and Personal Information Protection Policy — how we collect, use, protect and retain personal information, and how to exercise your rights as a data subject.

eKash Group Republic of South Africa

On this page

  1. Purpose
  2. Scope
  3. Legal and Regulatory Framework
  4. Definitions
  5. POPIA Processing Principles
  6. Categories of Personal Information
  7. Purposes for Processing Information
  8. Lawful Basis for Processing
  9. Customer Onboarding, KYC and Financial Information
  10. Credit and Financial Assessments
  11. Special Personal Information
  12. Children’s Personal Information
  13. Data Minimisation
  14. Data Accuracy
  15. Privacy Notices
  16. Data Subject Rights
  17. Direct Marketing
  18. Information Sharing
  19. Third-Party Operators and Service Providers
  20. Cross-Border Transfers
  21. Information Security
  22. Access Control
  23. Information Security Incidents and Data Breaches
  24. Security Compromise Notification
  25. Record Retention
  26. Secure Destruction
  27. Employee Responsibilities
  28. Information Officer
  29. Privacy Impact Assessments
  30. Privacy by Design and Default
  31. Automated Decision-Making and Artificial Intelligence
  32. Cookies and Digital Tracking
  33. Employee Training and Awareness
  34. Third-Party Risk Management
  35. Record of Processing Activities
  36. Regulatory Cooperation
  37. Complaint Management
  38. Monitoring and Auditing
  39. Non-Compliance
  40. Supporting Policies and Procedures
  41. Contact Details
  42. Policy Review
Policy Owner
Information Officer
Approved By
Board / Managing Executive
Version
1.0
Effective Date
16 September 2025
Review Date
Annual, or upon material regulatory/operational change
Classification
Corporate Governance Policy

1. Purpose

The purpose of this Policy is to establish the principles, responsibilities, controls and procedures implemented by eKash Group (“eKash”) for the lawful and responsible processing of personal information.

The Policy is intended to ensure compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), applicable regulations and other relevant South African legislation.

eKash recognises privacy and protection of personal information as fundamental components of responsible corporate governance, digital financial services, customer trust and information security.

eKash is committed to ensuring that personal information is:

  • processed lawfully and transparently.
  • collected for specific and legitimate purposes.
  • adequate, relevant and not excessive.
  • accurate and kept up to date where reasonably practicable.
  • retained only for as long as reasonably required.
  • protected against loss, damage, unauthorised destruction, access or disclosure.
  • processed in a manner that respects the rights of data subjects.

2. Scope

This Policy applies to all personal information processed by or on behalf of eKash, irrespective of whether the information is processed electronically, digitally, manually, through paper records or through third-party platforms.

It applies to:

  • directors and officers.
  • permanent and temporary employees.
  • contractors and consultants.
  • agents and representatives.
  • customers and prospective customers.
  • borrowers and finance applicants.
  • merchants and SMMEs.
  • suppliers and service providers.
  • business partners.
  • investors and shareholders.
  • employees and job applicants.
  • website and application users.
  • beneficiaries of programmes administered by eKash.
  • visitors to eKash premises.
  • any other natural or juristic person whose personal information is processed by eKash.

The Policy applies to all eKash systems and platforms, including websites, mobile applications, finance platforms, eBoleka or related financial solutions, customer relationship management systems, accounting systems, payment systems, cloud services and databases.

3. Legal and Regulatory Framework

This Policy must be read together with applicable South African legislation and regulatory requirements, including, where applicable:

  • Protection of Personal Information Act 4 of 2013.
  • Promotion of Access to Information Act 2 of 2000 (“PAIA”).
  • Electronic Communications and Transactions Act 25 of 2002.
  • Financial Intelligence Centre Act 38 of 2001 (“FICA”).
  • National Credit Act 34 of 2005, where applicable.
  • Companies Act 71 of 2008.
  • Consumer Protection Act 68 of 2008.
  • Tax Administration Act 28 of 2011.
  • Basic Conditions of Employment Act 75 of 1997.
  • applicable Information Regulator regulations, guidance and codes of conduct.
  • other laws requiring eKash to collect, maintain, disclose or retain information.

Where another applicable law requires a longer retention period or additional processing of personal information, eKash shall comply with that legal obligation.

4. Definitions

For purposes of this Policy:

Data Subject
means the person to whom personal information relates.
Personal Information
means information relating to an identifiable living natural person and, where applicable under POPIA, an identifiable existing juristic person.
Processing
includes collecting, receiving, recording, organising, storing, updating, retrieving, using, distributing, transmitting, merging, linking, restricting, deleting or destroying personal information.
Responsible Party
means the party that determines the purpose and means of processing personal information.
Operator
means a person or organisation that processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that responsible party.
Information Officer
means the person responsible for ensuring that eKash complies with POPIA and PAIA and performs the statutory responsibilities associated with that role.
Special Personal Information
includes categories of information afforded additional protection under POPIA.
Security Compromise
means unauthorised access to, acquisition, loss, destruction or disclosure of personal information, or reasonable grounds for believing that such access or acquisition has occurred.

5. POPIA Processing Principles

eKash shall manage personal information according to the conditions for lawful processing established by POPIA. These principles include:

5.1 Accountability

eKash shall take appropriate measures to ensure that the requirements of POPIA are implemented throughout the organisation.

5.2 Processing Limitation

Personal information shall be processed lawfully and in a reasonable manner that does not unjustifiably infringe the privacy of a data subject.

5.3 Purpose Specification

Personal information shall be collected for specific, explicitly defined and lawful purposes related to the activities and functions of eKash.

5.4 Further Processing Limitation

Where information is subsequently used for another purpose, eKash shall ensure that such further processing is compatible with the purpose for which the information was originally collected or is otherwise permitted by law.

5.5 Information Quality

eKash shall take reasonably practicable measures to ensure that personal information is complete, accurate, not misleading and updated where necessary.

5.6 Openness

eKash shall process information transparently and provide appropriate privacy notices explaining relevant processing activities.

5.7 Security Safeguards

Appropriate technical and organisational measures shall be maintained to protect personal information.

5.8 Data Subject Participation

Data subjects shall be provided with appropriate mechanisms to exercise their rights regarding their personal information.

6. Categories of Personal Information

Depending on the relevant product, service or relationship, eKash may process:

6.1 Identification and KYC Information

  • full name.
  • identity or passport number.
  • date of birth.
  • nationality.
  • photograph.
  • signatures.
  • company registration information.
  • director/shareholder information.
  • beneficial ownership information.
  • verification documentation.

6.2 Contact Information

  • residential and business addresses.
  • email addresses.
  • mobile and telephone numbers.
  • preferred communication methods.

6.3 Financial Information

  • bank account information.
  • bank statements.
  • income information.
  • financial statements.
  • turnover information.
  • payment records.
  • transaction history.
  • assets and liabilities.
  • loan information.
  • credit-related information.
  • affordability information.
  • funding requirements.

6.4 Business Information

  • company registration records.
  • tax information.
  • B-BBEE information.
  • ownership information.
  • contracts.
  • invoices.
  • purchase orders.
  • supplier information.
  • business performance information.

6.5 Employment Information

  • CVs.
  • employment history.
  • qualifications.
  • employment contracts.
  • payroll information.
  • performance records.
  • leave information.
  • statutory employment records.

6.6 Digital and Technical Information

  • IP addresses.
  • device identifiers.
  • application usage information.
  • browser information.
  • authentication records.
  • login records.
  • security logs.
  • cookies and similar technologies.
  • audit trails.

7. Purposes for Processing Information

eKash may process personal information for legitimate operational and legal purposes including:

  • opening and managing customer accounts.
  • customer onboarding.
  • identity and business verification.
  • KYC and due diligence.
  • financial diagnostic assessments.
  • processing finance applications.
  • affordability and credit assessments.
  • fraud detection and prevention.
  • anti-money-laundering controls.
  • processing payments and transactions.
  • administering loans and financial products.
  • managing collections and repayments.
  • providing business development services.
  • customer service and complaints handling.
  • regulatory reporting.
  • tax administration.
  • supplier management.
  • employment administration.
  • contractual administration.
  • cybersecurity and fraud monitoring.
  • statistical and management reporting.
  • improving eKash products and services.
  • marketing where legally permitted.
  • protecting eKash’s legitimate business interests.
  • complying with applicable laws and lawful regulatory requirements.

8. Lawful Basis for Processing

eKash shall ensure that a lawful justification exists before processing personal information. Depending on the circumstances, processing may occur where:

  • the data subject has provided consent.
  • processing is necessary for the conclusion or performance of a contract.
  • processing complies with an obligation imposed by law.
  • processing protects a legitimate interest of the data subject.
  • processing is necessary for the proper performance of a public-law duty by a public body.
  • processing is necessary for pursuing the legitimate interests of eKash or a third party to whom information is supplied, subject to the rights and interests of the data subject.

Consent shall not automatically be relied upon where another appropriate lawful basis exists.

Where consent is required, it must be capable of being demonstrated.

9. Customer Onboarding, KYC and Financial Information

Because eKash provides technology and financial-services-related solutions, enhanced controls shall apply to customer financial information. eKash shall, where appropriate:

  • verify customer identity.
  • verify business registration and ownership.
  • verify banking information.
  • conduct required KYC and due-diligence processes.
  • obtain supporting documents necessary for finance applications.
  • verify invoices and purchase orders where relevant.
  • assess financial information.
  • maintain appropriate audit trails.
  • restrict access to financial documents.
  • disclose information only to authorised parties.

Information collected for financial applications shall not be used for unrelated purposes unless permitted by POPIA or another applicable law.

10. Credit and Financial Assessments

Where eKash conducts or facilitates a financial diagnostic, affordability assessment, credit assessment or funding-readiness assessment, the information used may include:

  • bank statements.
  • credit information.
  • financial statements.
  • management accounts.
  • cash-flow information.
  • turnover.
  • liabilities.
  • existing finance.
  • repayment history.
  • invoices.
  • purchase orders.
  • other relevant financial information.

eKash shall implement appropriate controls around access to and use of this information.

Where decisions involving automated processing materially affect a data subject, eKash shall ensure that such processing complies with applicable POPIA requirements and that appropriate human review, transparency or other safeguards are implemented where required.

11. Special Personal Information

Special personal information shall only be processed where permitted by POPIA.

Access to such information shall be restricted to employees or service providers with a legitimate and authorised need to process it.

Additional technical and organisational safeguards may be implemented depending on the sensitivity and risk associated with the information.

12. Children’s Personal Information

eKash does not intentionally process children’s personal information unless such processing is necessary, lawful and appropriately authorised.

Where children’s information must be processed, eKash shall ensure that the processing complies with the specific requirements of POPIA and any applicable authorisation requirements.

13. Data Minimisation

eKash shall endeavour to collect only the personal information that is adequate, relevant and reasonably necessary for the identified processing purpose.

Employees must not collect personal information merely because it may potentially be useful at some future date.

Forms, systems and onboarding processes should periodically be reviewed to remove unnecessary data fields.

14. Data Accuracy

Reasonable measures shall be taken to maintain accurate and current information.

Data subjects may request correction of inaccurate or incomplete information.

Employees who become aware of materially inaccurate personal information must take appropriate steps to correct or escalate the information.

15. Privacy Notices

Where required, eKash shall provide data subjects with appropriate privacy notices explaining matters including:

  • the information being collected.
  • the purpose of collection.
  • whether providing the information is mandatory or voluntary.
  • consequences of failing to provide required information.
  • relevant legal authority.
  • potential recipients of the information.
  • cross-border processing where relevant.
  • data-subject rights.
  • contact information for privacy-related queries.

Privacy notices should be presented in clear and reasonably understandable language.

16. Data Subject Rights

Subject to applicable legislation, data subjects may:

  • request confirmation of whether eKash holds their personal information.
  • request access to personal information held about them.
  • request correction of inaccurate information.
  • request deletion or destruction where legally permissible.
  • object to certain processing.
  • withdraw consent where processing is based on consent.
  • object to certain direct marketing.
  • submit complaints concerning the processing of personal information.
  • lodge complaints with the Information Regulator.

Requests shall be directed to the Information Officer or designated privacy contact.

eKash shall maintain a procedure for verifying the identity of persons submitting requests before disclosing personal information.

17. Direct Marketing

eKash shall conduct electronic direct marketing in accordance with POPIA and other applicable legislation.

Where consent is required, appropriate consent shall be obtained before marketing communications are sent.

Marketing communications must provide an appropriate mechanism for recipients to opt out of future marketing.

Opt-out requests shall be implemented within a reasonable period and recorded to prevent inappropriate re-enrolment.

18. Information Sharing

Personal information may only be disclosed where there is an appropriate lawful basis. Potential recipients may include:

  • authorised eKash employees.
  • banks and payment service providers.
  • lenders and funding partners.
  • credit bureaux where legally permissible.
  • identity-verification providers.
  • KYC and compliance service providers.
  • accountants and auditors.
  • legal advisers.
  • cloud and technology service providers.
  • debt collection service providers.
  • insurers.
  • government departments.
  • SARS.
  • regulatory authorities.
  • law-enforcement agencies where legally authorised.
  • other contracted service providers.

Disclosure must be limited to information reasonably required for the intended purpose.

19. Third-Party Operators and Service Providers

Where a third party processes personal information on behalf of eKash, eKash shall conduct appropriate risk-based due diligence and establish contractual safeguards. Agreements should, where applicable, require operators to:

  • process information only under eKash’s authority.
  • maintain confidentiality.
  • implement appropriate security safeguards.
  • notify eKash promptly of suspected or confirmed security compromises.
  • restrict unauthorised subcontracting.
  • return or securely destroy information when required.
  • assist eKash with applicable POPIA obligations.

20. Cross-Border Transfers

Personal information shall not be transferred outside South Africa unless the requirements governing transborder information flows under POPIA are satisfied.

Before implementing material cross-border processing arrangements, eKash shall consider:

  • the country where information will be processed.
  • applicable privacy protections.
  • contractual protections.
  • security measures.
  • nature and sensitivity of the information.
  • whether any regulatory approval or prior authorisation is required.

Cloud-service arrangements shall be assessed for the geographic location and legal jurisdiction of data hosting and processing.

21. Information Security

eKash shall implement appropriate and reasonable technical and organisational security safeguards having regard to the nature of the information and foreseeable risks. Controls may include:

  • encryption.
  • multi-factor authentication.
  • role-based access controls.
  • password controls.
  • network security.
  • endpoint protection.
  • secure backups.
  • vulnerability management.
  • patch management.
  • logging and monitoring.
  • secure software development practices.
  • data-loss prevention measures.
  • physical security.
  • employee confidentiality obligations.
  • secure document disposal.
  • periodic security assessments.
  • incident-response procedures.

Access to personal information shall be based on the principle of least privilege.

22. Access Control

Employees shall only have access to information reasonably required to perform their duties. eKash shall establish processes for:

  • authorising user access.
  • modifying access when responsibilities change.
  • terminating access when employment or contracts end.
  • periodically reviewing privileged access.
  • maintaining audit trails for critical systems.

Sharing user accounts or passwords is prohibited.

23. Information Security Incidents and Data Breaches

All employees, contractors and service providers must immediately report suspected loss, unauthorised disclosure, cybersecurity incidents or compromise of personal information. Examples include:

  • lost or stolen devices.
  • phishing incidents.
  • compromised passwords.
  • ransomware.
  • emails sent to incorrect recipients.
  • unauthorised database access.
  • lost documents.
  • disclosure of customer information.
  • malicious insider activity.
  • unauthorised access by service providers.

Upon becoming aware of a suspected compromise, eKash shall:

  1. contain the incident.
  2. preserve relevant evidence.
  3. determine the nature and extent of the compromise.
  4. identify affected systems and information.
  5. assess risks to affected data subjects.
  6. implement remediation measures.
  7. determine notification obligations.
  8. notify relevant parties as required by law.
  9. document the incident and response.
  10. implement corrective and preventative measures.

24. Security Compromise Notification

Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, eKash shall follow the notification requirements prescribed by POPIA.

The Information Officer shall coordinate any required notification to the Information Regulator and affected data subjects.

Notifications shall be made in accordance with applicable statutory and regulatory requirements and shall provide sufficient information to enable affected persons to take appropriate protective measures.

25. Record Retention

Personal information shall not be retained longer than permitted or necessary for the purpose for which it was collected, unless:

  • retention is required or authorised by law.
  • eKash reasonably requires the record for lawful purposes.
  • retention is required by a contract.
  • the data subject has consented to retention where legally appropriate.

eKash shall maintain a Records Retention Schedule covering major categories of business information.

26. Secure Destruction

When personal information is no longer required, it shall be destroyed, deleted or de-identified in a manner that prevents reconstruction in an intelligible form. Appropriate methods may include:

  • secure shredding.
  • certified document destruction.
  • secure electronic deletion.
  • cryptographic erasure.
  • media destruction.
  • irreversible anonymisation.

27. Employee Responsibilities

All employees and contractors are responsible for protecting personal information. They must:

  • comply with this Policy.
  • maintain confidentiality.
  • use personal information only for authorised purposes.
  • protect passwords and authentication credentials.
  • follow information-security requirements.
  • avoid unauthorised downloads or transfers.
  • immediately report security incidents.
  • complete required privacy training.
  • cooperate with investigations and audits.

Unauthorised access, disclosure, copying, alteration or destruction of personal information may constitute misconduct and may result in disciplinary action.

28. Information Officer

The eKash Information Officer shall oversee the organisation’s POPIA compliance programme. Responsibilities include:

  • promoting organisational compliance.
  • overseeing implementation of privacy policies.
  • managing data-subject requests.
  • monitoring privacy risks.
  • maintaining required regulatory registrations.
  • overseeing privacy impact assessments.
  • coordinating breach-response activities.
  • engaging with the Information Regulator.
  • overseeing privacy awareness and training.
  • monitoring third-party privacy risks.
  • reporting significant privacy matters to management.

Deputy Information Officers may be appointed where necessary.

29. Privacy Impact Assessments

eKash shall conduct appropriate privacy assessments when introducing new products, systems or processing activities that may create significant privacy risks. This should particularly apply to projects involving:

  • large volumes of financial information.
  • credit scoring.
  • automated decision-making.
  • biometric information.
  • artificial intelligence.
  • behavioural profiling.
  • new mobile applications.
  • integration with external databases.
  • cloud migration.
  • new lending platforms.
  • material cross-border processing.

Privacy should be incorporated into system and product design from the earliest reasonable stage.

30. Privacy by Design and Default

eKash shall seek to integrate privacy controls into the design of its digital platforms. Systems should, where appropriate:

  • collect only necessary information.
  • use secure authentication.
  • encrypt sensitive information.
  • restrict access by role.
  • maintain audit trails.
  • provide appropriate consent mechanisms.
  • provide privacy notices.
  • facilitate data-subject requests.
  • support secure deletion and retention management.

31. Automated Decision-Making and Artificial Intelligence

Where eKash uses algorithms, artificial intelligence, credit-scoring models or automated systems in assessing customers, finance applications or risks, eKash shall ensure compliance with applicable POPIA requirements. Controls may include:

  • documenting the purpose of the model.
  • controlling the data used.
  • testing data quality.
  • monitoring model outputs.
  • implementing human oversight where appropriate.
  • maintaining audit trails.
  • providing appropriate transparency.
  • ensuring that automated processing does not unlawfully prejudice data subjects.

32. Cookies and Digital Tracking

eKash websites and applications may use cookies or similar technologies for:

  • authentication.
  • security.
  • application functionality.
  • performance monitoring.
  • analytics.
  • marketing where legally permissible.

Appropriate notices and consent mechanisms shall be implemented where required.

33. Employee Training and Awareness

Employees with access to personal information shall receive appropriate POPIA and information-security awareness training. Training should address:

  • POPIA principles.
  • confidentiality.
  • phishing.
  • password security.
  • customer information.
  • handling financial documents.
  • data-subject requests.
  • breach reporting.
  • direct marketing.
  • secure disposal.

Training shall be refreshed periodically.

34. Third-Party Risk Management

eKash shall consider privacy and information-security risks when appointing service providers. Higher-risk providers may be subject to enhanced due diligence, particularly providers that:

  • host customer databases.
  • process financial information.
  • conduct KYC.
  • process payments.
  • perform credit assessments.
  • provide cloud infrastructure.
  • have privileged access to eKash systems.

35. Record of Processing Activities

eKash should maintain an appropriate information inventory or processing register identifying material processing activities. The register should record, where appropriate:

  • information categories.
  • data subjects.
  • processing purposes.
  • lawful justification.
  • information sources.
  • recipients.
  • systems used.
  • operators.
  • storage locations.
  • cross-border transfers.
  • retention periods.
  • applicable security measures.

36. Regulatory Cooperation

eKash shall cooperate with lawful requests, investigations, assessments and enforcement processes conducted by the Information Regulator and other authorised regulators.

All regulatory communications concerning POPIA shall be escalated to the Information Officer and executive management.

37. Complaint Management

Privacy complaints shall be:

  • acknowledged.
  • recorded.
  • investigated.
  • appropriately escalated.
  • responded to within reasonable or legally required periods.
  • retained for audit purposes.

Where appropriate, root-cause analysis shall be conducted and corrective measures implemented.

38. Monitoring and Auditing

eKash shall periodically assess its compliance with this Policy. Reviews may include:

  • access-control reviews.
  • information-security assessments.
  • privacy audits.
  • data-retention reviews.
  • operator assessments.
  • breach-register reviews.
  • consent-management reviews.
  • direct-marketing reviews.
  • employee-training reviews.
  • assessments of new systems and products.

Material findings shall be reported to management and corrective actions tracked.

39. Non-Compliance

Failure by employees, contractors or representatives to comply with this Policy may result in:

  • suspension or restriction of system access.
  • disciplinary action.
  • termination of contractual arrangements.
  • internal investigation.
  • civil or regulatory consequences.
  • referral to appropriate authorities where legally required.

40. Supporting Policies and Procedures

This Policy should be supported by appropriate operational documents, including:

  • Privacy Notice.
  • PAIA Manual.
  • Information Security Policy.
  • Data Retention and Destruction Policy.
  • Data Breach Response Procedure.
  • Data Subject Access Request Procedure.
  • Operator/Data Processing Agreement template.
  • Employee Confidentiality Undertaking.
  • Direct Marketing and Consent Procedure.
  • Cookie Policy.
  • Access Control Policy.
  • Acceptable Use Policy.
  • Records Management Policy.
  • Privacy Impact Assessment template.
  • POPIA Compliance Register.

41. Contact Details

All requests or queries concerning personal information should be directed to:

Information Officer
eKash Group
Email: POPIAQUERIES@ekashgroup.co.za
Telephone: 087-152-5853
Physical Address: 6 Kikuyu Road, Sunninghill, Sandton, 2191

Data subjects may also lodge complaints with the Information Regulator (South Africa) through the Regulator’s prescribed processes.

42. Policy Review

This Policy shall be reviewed at least annually and whenever there is:

  • a material change in POPIA or associated regulations.
  • regulatory guidance affecting eKash.
  • a significant change to eKash’s operations.
  • introduction of a new financial or technology product.
  • significant change to information systems.
  • material security incident.
  • introduction of material automated decision-making.
  • significant change in the categories of personal information processed.

Have a question about this policy?

Contact Us
Back to top

Stay in the loop

Get updates on new features, services, and tips for your business.

eKash Logo eKash

A South African-built digital finance platform for small businesses, SMMEs, individuals, and informal traders who need transparent and responsible financial access.

6 Kikuyu Road, Sunninghill, Sandton, 2191, South Africa

Product

  • eBoleka
  • eTrader
  • eInsurance

Company

  • About Us
  • Contact
  • FAQ

Legal

  • Terms of Use
  • Refund Policy
  • PAIA Manual

© eKash Group (Pty) Ltd. All rights reserved.

NCR Registered · National Credit Regulator · Reg. No. NCRCP23248 · goAML Registered · Financial Intelligence Centre · ID 81141