Privacy
Privacy Notice
Version 2026-07 · Last updated [date]
This notice explains how the Global CIO Forum — South Africa Chapter (“the Chapter”, “we”, “us”) collects, uses, shares, protects and retains your personal information, and your rights, in line with South Africa’s Protection of Personal Information Act, 2013 (POPIA). It covers both Chapter membership registration and our digital business card platform.
1. Who is responsible for your information
The responsible party is the Global CIO Forum — South Africa Chapter.
2. The information we collect
When you register with the Chapter, we collect the details you provide through our registration form:
- Name and surname
- Designation / job title
- Organisation or company, sector and industry vertical
- Country and city
- Company website and employee-count band
- LinkedIn profile URL
- Email address and phone number
- The date and version of the privacy notice you consented to
3. Why we collect it (purpose)
- To administer your membership of the Chapter and maintain the member register.
- To communicate with you about Chapter activities, research, workshops and events.
- To organise and manage the South Africa CIO 200 Summit and related engagements.
- To understand the composition of our community (by sector, industry and region).
We will not use your information for a materially different purpose without your consent, unless the law permits it.
4. Legal basis and consent
We process your personal information on the basis of the consent you give when you tick the consent box on the registration form. You may withdraw your consent at any time (see section 10). Where applicable, we may also process information to pursue our legitimate interests as a professional community, in a way that does not override your rights.
5. Is providing information voluntary?
Providing your information is voluntary. However, the fields marked as required are necessary to register you as a member and keep you informed — if you do not provide them, we may be unable to complete your registration.
6. Who we share it with
We treat your information as confidential. We do not sell your personal information. We may share it with:
- Trusted service providers who help us operate (for example, hosting and email delivery), under confidentiality obligations. [list your processors, e.g. hosting provider, email/CRM tool]
- The wider Global CIO Forum organisation for coordinated membership and events. [confirm if applicable]
- Authorities where we are legally required to do so.
7. Digital business cards
Members may be issued a digital business card (a public page at gcfsa.co.za/card/…, with an optional vCard, QR code and Apple Wallet pass).
- A card displays only the professional contact information the card owner has approved for public disclosure. Owners may hide individual fields or deactivate a card at any time — deactivation is actioned immediately.
- We do not collect the names, contact details or identities of people who view a card. Where analytics are enabled, we record only anonymous engagement events (e.g. that a card was viewed or a contact file downloaded) and the traffic source (e.g. a QR scan). No raw IP addresses or device identifiers are stored.
- Downloading a contact file (.vcf) or Apple Wallet pass saves the owner’s public details to your own device; we do not record who downloaded them.
8. Storage and cross-border transfers
Your information is stored in our member database hosted on our South African hosting provider. Where any service provider processes information outside South Africa, we take reasonable steps to ensure a comparable level of protection as required by POPIA. [confirm hosting location / any offshore processors]
9. How we protect it
- The registration database is not publicly accessible; the admin area is protected by authentication.
- Administrator access requires a password, and sessions use secure, HTTP-only cookies over HTTPS.
- Credentials are stored only as one-way hashes, never in plain text.
- We apply reasonable technical and organisational safeguards and review them periodically.
10. How long we keep it & your rights
We keep membership information for as long as you are a member and for a reasonable period afterwards for administrative and legal purposes, after which it is deleted or de-identified. [state a retention period, e.g. “up to 24 months after membership ends”] Card profile information is retained while a card is active; anonymous engagement statistics are retained for a maximum of 24 months.
Under POPIA you have the right:
- To be told what personal information we hold about you and to access it.
- To ask us to correct or delete information that is inaccurate, irrelevant, excessive or out of date.
- To object to processing, and to withdraw consent at any time.
- To not be subject to unsolicited direct marketing — every message includes an opt-out.
- To lodge a complaint with the Information Regulator (section 11).
To exercise any of these, or to withdraw consent, email privacy@gcfsa.co.za. We will respond within a reasonable time.
11. Complaints to the Information Regulator
If you believe we have not handled your information lawfully, you may complain to:
12. Changes to this notice
We may update this notice from time to time. The version and date at the top reflect the current version; material changes will be communicated to members.
Placeholders to complete before publishing: items shown in [gold brackets] — the Information Officer’s name, the Chapter’s address, your hosting/processor details and your chosen retention period. POPIA also requires the responsible party to register an Information Officer with the Information Regulator.