V
Shap ZA
  • Ride
  • Drive
  • School Runs
  • Senior Assist
  • Safety
Join Login

POPIA Compliance

Protection of Personal Information Act, 4 of 2013

Shap ZA is fully committed to compliance with the Protection of Personal Information Act (POPIA), 4 of 2013. This page outlines our compliance framework, policies, and procedures.
1. Overview

POPIA gives effect to the constitutional right to privacy (Section 14 of the Constitution of the Republic of South Africa, 1996). Shap ZA processes personal information as a Responsible Party under POPIA and has implemented a comprehensive compliance framework aligned with the eight POPIA processing conditions.

2. Information Officer

Shap ZA has appointed an Information Officer registered with the South African Information Regulator, responsible for overseeing POPIA compliance:

  • Information Officer: Wesley (Chief Technology Officer)
  • Email: support@shapza.co.za
  • Phone: +27 12 345 6789
3. The Eight POPIA Conditions
Condition 1: Accountability

Shap ZA takes full responsibility for the lawful processing of personal information. Our Data Protection Impact Assessment (DPIA) is reviewed annually. All staff complete mandatory POPIA training.

Condition 2: Processing Limitation

Personal information is collected only for specified, explicitly defined purposes: ride fulfilment, safety monitoring, NCPR vetting, and communication. Consent is obtained through explicit checkbox acceptance on all enrolment and registration forms, with timestamps recorded in our database.

Condition 3: Purpose Specification

Personal information is collected for lawful purposes directly related to our e-hailing services. Data subjects are informed of the purpose at the time of collection via our Privacy Policy and consent forms.

Condition 4: Further Processing Limitation

Personal information is not processed further in a manner incompatible with the original purpose. Any new processing purpose requires fresh, informed consent.

Condition 5: Information Quality

We take reasonable steps to ensure that personal information is complete, accurate, and not misleading. Users may update their information at any time and can request rectification via our Information Officer.

Condition 6: Openness

Our Privacy Policy, PAIA Manual, and this POPIA Compliance page are publicly available. Data subjects are notified of data collection at the point of collection through clear, plain-language consent forms.

Condition 7: Security Safeguards

We maintain the following security measures:

  • Encryption: TLS 1.3 in transit, AES-256 at rest.
  • Access control: role-based permissions, multi-factor authentication for staff.
  • PIN codes: stored as bcrypt hashes — never in plaintext.
  • Pseudo-anonymisation: location data anonymised after 90 days.
  • Security testing: quarterly penetration tests and vulnerability scans.
  • Breach response: 72-hour notification to the Information Regulator (as required by POPIA).
Condition 8: Data Subject Participation

Data subjects have the right to request access to, correction of, or deletion of their personal information. Requests are processed within 30 days. See our Privacy Policy for full details on exercising your rights.

4. Data Breach Response

In the event of a personal information breach, Shap ZA will:

  1. Contain the breach within 1 hour of detection.
  2. Assess the scope and risk to data subjects.
  3. Notify the Information Regulator within 72 hours (POPIA Section 22).
  4. Notify affected data subjects if the breach poses a risk of substantial harm.
  5. Conduct a post-incident review and implement corrective measures.
5. Data Processing Register

Shap ZA maintains a Register of Processing Activities as required by POPIA Section 15, documenting all categories of personal information processed, purposes, retention periods, and third-party processors. This register is available for inspection by the Information Regulator.

6. International Alignment

While POPIA is our primary compliance framework, our policies are also aligned with:

  • GDPR (EU): Articles 5–9, 12–23, and 30–34.
  • UNCRC: Article 16 (right to privacy for children).
  • ISO 27701: Privacy Information Management System principles.
7. Complaints

If you believe Shap ZA has processed your personal information in violation of POPIA, you may lodge a complaint with:

  • Shap ZA Information Officer: support@shapza.co.za
  • Information Regulator (South Africa):
    JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
    justice.gov.za/inforeg

Shap ZA's POPIA compliance is reviewed annually by an external Data Protection Officer. Last review: June 2026.

S
Shap ZA

Building safer mobility for South African families. Real-time tracking, AI safety monitoring, NCPR-vetted drivers, and accessible transport for all ages.

Services
  • Request a Ride
  • Place a Bid
  • Drive with Shap
  • KidSafe Shuttle
  • SeniorAssist
  • Safety
  • View Bids
Legal & Compliance
  • Terms of Service
  • Privacy Policy
  • POPIA Compliance
  • NLTA (National Land Transport Act)
  • Children's Act & NCPR
  • UNCRPD Accessibility
  • PAIA Manual
  • Cookie Policy
Contact
  • support@shapza.co.za
  • +27 12 345 6789
  • Cape Town, South Africa
Subscribe for Deals

Get discount deals and safety updates.

© 2026 Shap ZA. All rights reserved. Shap ZA is a registered South African transport service provider compliant with NLTA, POPIA, and NCPR standards.