Legal
Themis Legal Consulting - POPIA Information Notice
Notice regarding the processing of personal information under the Protection of Personal Information Act 4 of 2013
Status
This document is reproduced from the text supplied by Themis Legal Consulting and is for legal review before publication. It has not been amended, summarised or interpreted.
Effective 25 August 2026
This notice is intended to provide data subjects with concise but substantial information concerning Themis’s processing of personal information and should be read with the Privacy Policy and PAIA Manual.
1Responsible Party
1.1The responsible party is Themis Legal Consulting Proprietary Limited, registration number 2022/730552/07 (“Themis”), of 585 Alendale Street, Elarduspark, Pretoria, Gauteng, 0181. Themis determines the purpose of and means for processing personal information in relation to its website and ordinary business activities, except where it acts in another legally recognised capacity under a particular arrangement.
2Information Officer
2.1The Information Officer of Themis is Ms Llanell Londt, in her capacity as director of Themis. In terms of the Promotion of Access to Information Act 2 of 2000 and the Protection of Personal Information Act 4 of 2013, the head of a private body is, by default, its chief executive officer, or equivalent officer, or a director in the case of a company that has no chief executive officer, unless another person has been duly appointed and registered as Information Officer or Deputy Information Officer with the Information Regulator. Themis will keep its Information Officer registration, and the particulars published in this Notice and the PAIA Manual, up to date.
2.2Correspondence for the Information Officer may be sent to info@themislegal.co.za marked “Information Officer - POPIA”, or addressed in writing to 585 Alendale Street, Elarduspark, Pretoria, Gauteng, 0181.
3Conditions for Lawful Processing
3.1Themis seeks to give effect to the conditions for lawful processing under POPIA, including accountability; processing limitation; purpose specification; further processing limitation; information quality; openness; security safeguards; and data subject participation.
4Nature of Information
4.1The categories of information that may be processed include identity, contact, business, professional, enquiry, matter, contractual, governance, compliance, commercial, billing, technical, correspondence and other information reasonably necessary for a lawful business or professional purpose. The detailed categories are described in the Privacy Policy.
5Source of Information
5.1Information may be obtained directly from a data subject, the organisation represented by the data subject, clients, prospective clients, counterparties, professional advisers, service providers, lawful public sources, company or regulatory records and other persons who are lawfully entitled to provide it.
6Purpose of Collection and Processing
6.1Information is processed for purposes connected with website operation, enquiry management, pre-engagement assessment, scoping and proposals, professional service delivery, contract and relationship administration, communications, governance and compliance, invoicing and accounting, security and fraud prevention, legal compliance, dispute management, record keeping and other compatible legitimate business purposes.
7Consequences of Failure to Provide Information
7.1Where information is optional, a data subject may decline to provide it. Where information is reasonably necessary to respond to an enquiry, verify authority, comply with law, conclude or perform an agreement or provide a requested service, failure to provide it may prevent or delay Themis from proceeding.
8Recipients
8.1Information may be shared with authorised personnel, operators, technology providers, professional advisers, insurers, auditors, counterparties, clients, regulators, courts, law-enforcement authorities and other lawful recipients, but only to the extent reasonably necessary and permitted by law or agreement.
9Cross-Border Processing
9.1Personal information may be transferred outside South Africa where cloud, email, hosting, collaboration, security or other service infrastructure requires it. Themis will use reasonable measures to ensure that any transfer is made on a basis permitted by section 72 of POPIA or other applicable law.
10Security
10.1Themis will establish and maintain appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information in its possession or under its control, having regard to generally accepted information-security practices and the nature of the information concerned.
11Operators
11.1Where an operator processes personal information for Themis, Themis will seek to ensure through written arrangements or other legally appropriate measures that the operator establishes and maintains the security measures required by POPIA and processes information only with Themis’s knowledge or authorisation, subject to law.
12Data Subject Rights
12.1to be notified that personal information is being collected, where applicable;
12.2to be notified of a security compromise where required by law;
12.3to establish whether Themis holds personal information concerning the data subject and to request access in accordance with applicable law;
12.4to request correction, destruction or deletion of personal information where the statutory requirements are met;
12.5to object, on reasonable grounds where applicable, to processing based on specified statutory grounds;
12.6to object to processing for purposes of direct marketing by means of unsolicited electronic communications;
12.7not to be subject, in circumstances regulated by POPIA, to certain decisions based solely on automated processing that produce legal consequences or substantially affect the data subject;
12.8to submit a complaint to the Information Regulator; and
12.9to institute civil proceedings where POPIA permits.
13Requests for Access, Correction, Deletion or Objection
13.1Requests should be submitted in the form and manner prescribed by applicable law or by the Information Regulator where a prescribed form applies. Themis may require sufficient information to verify identity, authority and the record concerned. A request will be assessed subject to POPIA, PAIA, confidentiality, privilege, third-party rights, statutory retention duties and other lawful grounds.
14Automated Decision-Making
14.1Themis does not intend to make decisions concerning data subjects solely on the basis of automated processing where the decision would produce legal consequences or substantially affect the data subject, unless such processing is permitted by law and appropriate safeguards are implemented.
15Special Personal Information
15.1Themis will not process special personal information merely because it is available. Where such information is genuinely required for a lawful instruction or legal obligation, it will be processed only where a general or specific authorisation under POPIA or another applicable law exists.
16Personal Information of Children
16.1Themis will process personal information concerning a child only where authorised by POPIA or other applicable law, including where prior consent of a competent person or another statutory basis exists. General website enquiries should not include children’s information unless necessary.
17Direct Marketing
17.1Unsolicited electronic direct marketing will be undertaken only on a basis permitted by POPIA. A person may object to or opt out of marketing communications at any time using the mechanism provided in the communication or by contacting info@themislegal.co.za.
18Retention
18.1Personal information will not be retained longer than authorised or reasonably necessary, subject to statutory, contractual, evidentiary, accounting, tax, insurance, dispute-resolution and legitimate business requirements. Information may be retained for longer where required or authorised by law, reasonably required for lawful purposes, required by a contract, or consented to where appropriate.
19Complaints
19.1A data subject who is dissatisfied with Themis’s handling of personal information is encouraged to contact the Information Officer first so that the issue can be investigated. This does not limit the right to approach the Information Regulator using its official complaint procedures.
20Interpretation
20.1In this Notice, headings are for convenience only and do not affect interpretation; the singular includes the plural and vice versa; a reference to a person includes a natural or juristic person; and the words “include”, “includes” and “including” are not words of limitation.
21Limitation of Liability
21.1To the maximum extent permitted by law, Themis’s liability arising from or in connection with this Notice, or from processing carried out in accordance with it, is limited to loss directly caused by Themis’s own unlawful conduct and excludes indirect, incidental, special, punitive or consequential loss of any kind. This Notice does not create, extend or replace any liability regime separately agreed in a written professional engagement.
22Severability
22.1If a provision of this Notice is found by a competent authority or court to be invalid, unlawful or unenforceable, that provision will be severed to the minimum extent necessary and the remaining provisions will continue in full force and effect.
23Governing Law
23.1This Notice is governed by the laws of the Republic of South Africa. Any dispute concerning this Notice that is not resolved through the Information Regulator’s statutory processes is subject to the jurisdiction of the South African courts.
Related documents
Questions about these documents may be sent to info@themislegal.co.za.