• Home
  • Outsourcing
    • Services
    • Customer Experience
    • Webchat
  • Careers
    • Find Us
    • Gallery
    • Share your views
  • Awards
    • Blog
  • Contact
    • Privacy >
      • Popia
Contact Centre Outsourcing Durban | Sales, CX & Tech Support
  • Home
  • Outsourcing
    • Services
    • Customer Experience
    • Webchat
  • Careers
    • Find Us
    • Gallery
    • Share your views
  • Awards
    • Blog
  • Contact
    • Privacy >
      • Popia

POPIA POLICY

EC3 (EC THREE (PTY) LTD)
POPIA and GDPR Compliance Statement
Data Protection Policy
Version: 1.2
Effective Date: 1 June 2024
Document Owner: Information Officer / Data Protection Lead
Registered Address: 305 Umhlanga Rocks Drive, La Lucia, Durban North, 4051, KwaZulu-Natal, South Africa


1. Introduction and Commitment
EC3 (EC THREE (PTY) LTD) (“EC3”, “we”, “us” or “our”) is a Business Process Outsourcing (BPO) and contact centre services provider specialising in customer experience, sales, retention, reactivation, inbound support, and related services. We operate from our facility at 305 Umhlanga Rocks Drive, Durban, South Africa.
EC3 is committed to protecting the privacy and personal information of all individuals whose data we process. This includes our clients’ customers, our employees, website visitors, job applicants, and other data subjects.
We process personal information in accordance with:
  • The Protection of Personal Information Act 4 of 2013 (POPIA) of the Republic of South Africa; and
  • The General Data Protection Regulation (EU) 2016/679 (GDPR), where applicable (particularly when processing personal data of individuals in the European Economic Area, United Kingdom, or when acting under contracts with EU-based clients).
This Compliance Statement sets out EC3’s data protection policy and demonstrates our ongoing commitment to lawful, fair, and transparent processing of personal information.


2. Roles and Responsibilities
  • Responsible Party / Data Controller: EC3 acts as the Responsible Party (under POPIA) or Data Controller (under GDPR) in respect of personal information relating to our own employees, job applicants, website users, and direct business contacts.
  • Operator / Data Processor: In the majority of our BPO engagements, EC3 acts as an Operator (POPIA) or Data Processor (GDPR) on behalf of our clients. In these cases, we process personal information strictly in accordance with the documented instructions of the client (the Responsible Party/Controller) and under the terms of a Data Processing Agreement or equivalent contractual safeguards.
EC3 has appointed an Information Officer (and Deputy where required) in terms of POPIA, who also oversees GDPR compliance matters.


3. Scope of Application
This Statement applies to all personal information processed by EC3 in the course of providing BPO and contact centre services, including (but not limited to):
  • Customer data provided by clients for service delivery (e.g., contact details, account information, interaction records).
  • Employee and contractor personal information.
  • Job applicant data.
  • Website and marketing-related personal information.
  • Any other personal information processed in connection with our business operations.


4. Key Principles of Processing
EC3 adheres to the following core principles under both POPIA and GDPR:
  1. Lawfulness, Fairness and Transparency – Personal information is processed only on a lawful basis (consent, contract, legitimate interest, legal obligation, or other permitted grounds) and in a transparent manner.
  2. Purpose Limitation – Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  3. Data Minimisation – Only adequate, relevant, and necessary personal information is processed.
  4. Accuracy – Reasonable steps are taken to ensure personal information is accurate and kept up to date.
  5. Storage Limitation – Personal information is retained only for as long as necessary to fulfil the purpose or as required by law or contract.
  6. Integrity and Confidentiality (Security) – Appropriate technical and organisational measures are implemented to protect personal information against unauthorised or unlawful processing, loss, destruction, or damage.
  7. Accountability – EC3 is able to demonstrate compliance with these principles.


5. Lawful Bases for Processing
  • POPIA: Processing is based on one or more of the conditions for lawful processing set out in Chapter 3 of POPIA (consent, contract, legal obligation, legitimate interest of the responsible party or third party, public interest, etc.).
  • GDPR: Processing is based on Article 6 GDPR (consent, contract, legal obligation, vital interests, public task, or legitimate interests) and, where special category data is involved, Article 9.
Where we act as Operator/Processor, the client is responsible for establishing the lawful basis.


6. Categories of Personal Information Processed
Typical categories include:
  • Identity and contact data (name, address, email, telephone number).
  • Account, transaction, and service-related data.
  • Communication and interaction records (call recordings, chat logs, emails – where authorised).
  • Technical data (IP address, device information – primarily for website visitors).
  • Employment-related data (for staff and applicants).
  • Any other data categories specifically authorised by the client under a processing agreement.
Special personal information (as defined in POPIA) or special category data (GDPR) is processed only where strictly necessary, with additional safeguards, and in accordance with legal requirements or explicit client instructions.


7. Security Measures
EC3 implements appropriate technical and organisational measures, including but not limited to:
  • Access controls and role-based permissions.
  • Encryption of data in transit and at rest where appropriate.
  • Secure facilities and physical access controls at 305 Umhlanga Rocks Drive.
  • Staff training and confidentiality agreements.
  • Monitoring, logging, and incident response procedures.
  • Regular security assessments and audits.
  • Secure destruction of data when no longer required.


8. Data Subject Rights
Data subjects have the following rights (subject to applicable limitations under POPIA and/or GDPR):
  • Right of access
  • Right to rectification
  • Right to erasure / destruction
  • Right to restriction of processing
  • Right to data portability (GDPR)
  • Right to object
  • Right not to be subject to automated decision-making (where applicable)
  • Right to withdraw consent (where processing is based on consent)
  • Right to lodge a complaint with the Information Regulator (South Africa) or the relevant supervisory authority (EU/UK)
Requests may be submitted to the contact details below. We will respond within the timeframes prescribed by the applicable legislation.


9. International Transfers
Personal information may be transferred outside South Africa (including to clients or sub-processors in the EEA, UK, or other jurisdictions) only where:
  • Adequate protection is in place (adequacy decision, appropriate safeguards such as Standard Contractual Clauses, or other POPIA/GDPR-compliant mechanisms); or
  • The transfer is otherwise permitted under the relevant legislation.
As a South African BPO serving international clients, EC3 ensures that all cross-border transfers are governed by appropriate contractual and technical safeguards.


10. Data Retention
Personal information is retained only for as long as necessary to fulfil the purposes for which it was collected, to meet legal, regulatory, or contractual obligations, or for the establishment, exercise, or defence of legal claims. Retention periods are defined in our internal retention schedule and in client Data Processing Agreements.


11. Data Breach Notification
In the event of a personal information breach, EC3 will notify the relevant parties (Information Regulator under POPIA, supervisory authority and/or data subjects under GDPR, and the client where we act as Operator/Processor) without undue delay and in accordance with statutory timelines and contractual obligations.


12. Contact Details
For any queries regarding this Compliance Statement, the exercise of data subject rights, or data protection matters generally:
Information Officer / Data Protection Contact
EC3 (EC THREE (PTY) LTD)
305 Umhlanga Rocks Drive
La Lucia, Durban North
4051, KwaZulu-Natal
South Africa
Email: [[email protected] or the designated contact email]
Telephone: +27 31 941 8000
Website: www.ec3.co.za
Complaints may also be directed to:
  • Information Regulator (South Africa): https://inforegulator.org.za
  • Relevant EU/UK supervisory authority (where GDPR applies)


13. Review and Updates
This Compliance Statement is reviewed periodically and updated as necessary to reflect changes in legislation, business practices, or processing activities. The latest version will be made available on request or via our website.


Approved by:


J.Volschenk
Date: 1 June 2024
 
[email protected] (outsourcing) [email protected] (recruitment)
​WhatsApp 087 725 2607
​CALL +27 31 941 8000
                                        Soft on our people. ​Tough on our standards
​
  © 2013 - 2026          ​13 Years and counting....        ​
WhatsApp
EC3
Picture
Picture
Picture
Picture
  • Home
  • Outsourcing
    • Services
    • Customer Experience
    • Webchat
  • Careers
    • Find Us
    • Gallery
    • Share your views
  • Awards
    • Blog
  • Contact
    • Privacy >
      • Popia