POPIA Compliance

Privacy Policy

How DEMASA collects, uses, stores, shares and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013.

Effective Date
26 August 2026
Issued By
Debt Mediation Association of South Africa NPC

01Introduction

The Debt Mediation Association of South Africa NPC (“DEMASA”) respects the privacy of applicants, members, practitioners, consumers, complainants, website visitors and other persons whose personal information it processes.

This Privacy Policy explains how DEMASA collects, uses, stores, shares and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable South African law.

02Responsible Party

For purposes of POPIA, DEMASA is the Responsible Party in relation to personal information processed for its own purposes.

Privacy and POPIA enquiries may be directed to DEMASA at compliance@demasa.co.za, or via www.demasa.co.za.

03Personal Information We May Collect

Depending on the nature of the interaction, DEMASA may process information including:

  • names and surnames;
  • identity information;
  • contact details;
  • company names and registration numbers;
  • director and authorised representative information;
  • addresses;
  • telephone numbers and email addresses;
  • attorney and trust-account information;
  • membership and accreditation information;
  • supporting compliance documents;
  • consumer mandates and sample agreements submitted for compliance assessment;
  • complaints and investigation information;
  • correspondence with DEMASA;
  • payment and transaction information;
  • website usage and technical information; and
  • any other information reasonably necessary for accreditation, compliance or DEMASA’s legitimate functions.

04How We Collect Information

Personal information may be collected:

  • directly from you;
  • through the DEMASA website;
  • through accreditation or membership applications;
  • through correspondence with DEMASA;
  • through complaints;
  • from accredited members;
  • from authorised representatives;
  • from publicly available sources;
  • from professional or compliance service providers;
  • during compliance reviews or investigations; or
  • where otherwise permitted by law.

05Purposes of Processing

DEMASA may process personal information for purposes including:

  • assessing accreditation applications;
  • verifying eligibility and compliance;
  • administering membership;
  • issuing accreditation certificates, numbers and badges;
  • maintaining the DEMASA Public Register;
  • annual renewals and compliance reviews;
  • monitoring adherence to the DEMASA Code of Conduct;
  • investigating complaints;
  • protecting consumers;
  • communicating with members and applicants;
  • processing payments and refunds;
  • responding to enquiries;
  • referring consenting consumers to accredited providers;
  • maintaining records and audit trails;
  • fraud prevention and security;
  • complying with legal obligations; and
  • pursuing DEMASA’s legitimate organisational and industry functions.

DEMASA will endeavour to collect personal information for specific and lawful purposes and not use it incompatibly with those purposes.

06Consumer Referral Information

Where a consumer asks DEMASA to refer their enquiry to an accredited provider, DEMASA may process the information provided for that purpose.

Where appropriate, the information may be provided to the DEMASA-accredited provider or providers selected to respond to the enquiry.

DEMASA will not use optional marketing consent as a condition for requesting a provider referral.

07Accreditation and Public Register Information

Applicants acknowledge that active accreditation is intended to be publicly verifiable. DEMASA may therefore publish appropriate accreditation information on its Public Register, such as:

  • provider/company name;
  • DEMASA membership/provider number;
  • accreditation status;
  • membership category where appropriate; and
  • other limited information reasonably necessary to verify accreditation.

Sensitive or unnecessary personal information will not intentionally be published merely because it was submitted during an accreditation application.

08Payment Information

Payments made through the DEMASA website may be processed by PayFast or another authorised payment service provider.

The payment provider may process information necessary to complete, secure and record the transaction under its own applicable privacy and security arrangements.

DEMASA does not ordinarily store complete payment-card details processed through an independent payment gateway.

DEMASA may retain transactional information such as payment amount, date, reference, status and invoice information for accounting, membership and legal purposes.

09Sharing of Personal Information

DEMASA may disclose personal information where reasonably necessary to:

  • authorised DEMASA personnel and committees;
  • payment processors;
  • technology and hosting providers;
  • professional advisers;
  • auditors;
  • legal advisers;
  • accredited providers where a consumer has requested a referral;
  • regulatory, law-enforcement or governmental authorities where required by law; or
  • another party where disclosure is authorised or otherwise lawfully permitted.

Service providers receiving personal information should process it subject to appropriate confidentiality and security requirements.

DEMASA does not sell personal information.

Information is shared only where it is necessary for accreditation, compliance, consumer protection or a legal obligation.

10Security

DEMASA will implement reasonable technical and organisational measures appropriate to the information processed to protect personal information against loss, unauthorised access, misuse, alteration or destruction.

No internet-based system can be guaranteed to be completely secure. DEMASA will nevertheless take reasonable steps to safeguard information within its control.

11Retention

Personal information will be retained only for as long as reasonably necessary for the purpose for which it was collected, to satisfy legal or regulatory obligations, to maintain appropriate accreditation and compliance records, or to establish, exercise or defend legal rights.

Information that no longer needs to be retained will be securely destroyed, deleted or de-identified where appropriate.

12Cookies and Website Technologies

The DEMASA website may use cookies and similar technologies necessary for website functionality, security, analytics and user experience.

Where legally required, users will be given appropriate information and choices concerning non-essential cookies.

13Direct Marketing

DEMASA may send organisational, accreditation, compliance or membership communications reasonably necessary for administering an existing relationship.

Marketing communications will be handled in accordance with applicable law. Where consent is required, DEMASA will obtain appropriate consent and provide a reasonable means of withdrawing it.

14Your Rights

Subject to POPIA and other applicable law, a data subject may have the right to:

  • ask whether DEMASA holds personal information about them;
  • request access to qualifying personal information;
  • request correction or updating of inaccurate information;
  • request deletion or destruction where legally appropriate;
  • object to certain processing;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint concerning the processing of personal information.

DEMASA may require reasonable proof of identity before acting on a request.

15Information Relating to Other Persons

Applicants and members submitting information concerning directors, employees, attorneys, consumers or other persons must ensure that they are lawfully entitled to provide that information to DEMASA.

16Third-Party Websites

The DEMASA website may contain links to external websites. DEMASA is not responsible for the privacy practices or content of independent third-party websites.

17Information Regulator

A person who believes that their personal information has been processed unlawfully may contact DEMASA so that the matter can be investigated.

Data subjects may also have the right to lodge a complaint with the Information Regulator (South Africa) in accordance with POPIA.

18Changes to This Privacy Policy

DEMASA may update this Privacy Policy from time to time to reflect changes in its operations, technology or applicable law. The latest version will be published on the DEMASA website.

19Contact

Privacy and POPIA enquiries may be directed to the Debt Mediation Association of South Africa NPC (DEMASA) at compliance@demasa.co.za, or via www.demasa.co.za.

Where an Information Officer or Deputy Information Officer has formally been appointed and registered, their prescribed contact details should also be published as required.