ActiviTrack

Compliance

POPIA Compliance

Protection of Personal Information Act, 2013 · Last updated: 22 June 2026

Overview

This page sets out how ActiviTrack, operated by Seventh Son Consulting Services (SSCS), meets its obligations under the Protection of Personal Information Act, 2013 (POPIA). It is scoped to what the platform actually does: field workforce tracking, geospatial progress monitoring, and facial-recognition clock-in. For the general privacy notice covering all data collection, see the Privacy Policy.

1. Facial Recognition — Special Personal Information

Facial recognition collects biometric information, which is special personal information under Section 26 of POPIA. This is our highest-risk processing area. POPIA imposes a general prohibition on processing biometric information, with specific authorisation available under law and labour legislation.

Each employee enrolled in facial recognition must provide explicit written consent before enrollment. Verbal acknowledgement during onboarding is not sufficient.

What we require in practice

  • A signed consent form per worker before any facial template is created.
  • The consent must name ActiviTrack, state that it is for clock-in / clock-out, and specify the retention period for stored embeddings as agreed with the responsible client.
  • A permanent, non-biometric fallback (barcode / swipe) must always be available.
  • Employees may withdraw consent at any time without penalty. On withdrawal we stop processing their biometric data, delete their facial templates, and the fallback remains a permanent option.

We store the embedding vector only (Facenet512) and never retain the raw face image.

2. Data Subject Rights

ActiviTrack supports the following rights for every data subject:

  • Right to be informed — employees are told what biometric data is collected, why, how it is stored, and for how long, before enrollment.
  • Right to access — employees can request a copy of all personal data held about them, including facial template details.
  • Right to withdraw consent — at any time, without penalty.
  • Right to erasure — employees can demand prompt deletion of their biometric templates.

Capabilities this requires

Template Deletion

Admin interface to delete a specific worker's embeddings on request.

Data Export

A worker can request and receive an export of all their records.

Audit Logs

Records showing when, by whom, and why data was deleted.

3. Automated Decision-Making (Section 71)

If attendance denial or payroll deductions occur solely because a device failed to match a template, this may trigger Section 71 (automated decision-making with legal or significant effects).

ActiviTrack does not auto-trigger payroll consequences from a failed face match. A human sign-off step is required before any adverse action.

Section 71 exposure is mitigated by inserting human review, appeal routes, and secondary evidence — supervisor confirmation, CCTV, or swipe-card logs — before any adverse action is taken.

4. Data Minimisation & Retention

We store the minimum viable template and keep data only as long as needed for attendance, access, and related disputes, then execute documented, verifiable deletion.

  • Store the embedding vector only, never the raw face image.
  • Retention periods are defined per client deployment and documented in the applicable data processing agreement. Biometric templates are deleted promptly once the retention period expires or employment ends, whichever is earlier.
  • Backups must not retain embeddings indefinitely. Scheduled deletion jobs run against the deployment, and key management enables effective crypto-shredding at end of need.

Indefinite backups containing biometric templates are not permitted.

5. Cross-Border Data Transfer (Section 72)

Where data is hosted outside South Africa, Section 72 applies: we must ensure an adequate level of protection or appropriate contractual safeguards.

ActiviTrack is currently deployed on eu-north-1 (Stockholm), which constitutes a cross-border transfer. Our controls:

  • A documented justification — the EU is subject to GDPR, which is considered an adequate level of protection.
  • A data processing clause in client contracts disclosing EU hosting.
  • Ongoing evaluation of whether af-south-1 (Cape Town) better fits a given client's risk appetite.

Client contracts must include data processing agreements that disclose the hosting region.

6. Geospatial & Location Data

Location data tracking field workers is personal information. Our handling of it follows three principles:

  • Disclosed purpose — tracking linear work progress is stated in our privacy notice.
  • Working hours only — workers are not tracked outside their shifts.
  • Access policy — a clear policy governs who can view location data and for how long.

7. Organisational Requirements

As the responsible party, SSCS maintains the organisational structures POPIA requires:

  • An appointed Information Officer, registered with the Information Regulator before commencing the role, who handles privacy requests and cooperates with the Regulator.
  • A PAIA Manual, which is mandatory for juristic persons.
  • Data processing agreements within all client contracts.
Information Regulator (South Africa)
Website: www.inforegulator.org.za
Email: enquiries@inforegulator.org.za
Tel: 010 023 5200

8. Priority Action List

The biometric consent mechanism is the most urgent item given facial recognition is actively being built.

PriorityActionRisk if skipped
CriticalSigned biometric consent per worker, pre-enrollmentSection 26 breach, R10M fine
CriticalFacial template deletion capability in admin panelData subject rights breach
CriticalRegister Information Officer with RegulatorNon-compliance on record
HighDocument EU hosting in client contracts (Section 72)Transfer violation
HighDefine and enforce embedding retention/deletion policyRetention breach
HighHuman review before adverse action on missed clock-inSection 71 exposure
StandardPrivacy notice published for ActiviTrackOpenness condition
StandardData processing agreement template for clientsOperator liability

9. Contact & Information Officer

To exercise your data rights, withdraw biometric consent, or raise a POPIA query, contact our Information Officer:

Seventh Son Consulting Services (SSCS)
Johannesburg, South Africa
Email: info@sscservices.co.za