Information Officer Notice

Protection of Personal Information Act 4 of 2013 — Regulation 4

Issued by: Toker Effective Date: 28 June 2026 Document Version: 1.0-draft

This Notice is published in compliance with Regulation 4 of the POPIA Regulations, 2018 (issued under the Protection of Personal Information Act 4 of 2013, "POPIA"). It identifies the Information Officer and Deputy Information Officer of Toker who are responsible for ensuring compliance with POPIA, and explains how they may be contacted.


1. Why this Notice exists

POPIA s.55 requires every responsible party (i.e. every entity that processes personal information) to register an Information Officer with the Information Regulator of South Africa, and to publish the Information Officer's contact details.

Regulation 4 of the POPIA Regulations, 2018, requires the Information Officer to:

  • Take responsibility for compliance with POPIA by the responsible party;
  • Manage the relationship with the Information Regulator;
  • Ensure that the responsible party's internal measures give effect to POPIA's eight processing conditions;
  • Receive and respond to data subject access requests (POPIA s.23);
  • Investigate complaints and report to the Information Regulator;
  • Maintain a register of all operators (subprocessors) of the responsible party;
  • Coordinate with the Information Regulator in case of a security breach.

2. Information Officer of Toker

FieldValue
NameNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registration number with the Information RegulatorNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Date of registrationNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registered address (postal)Not yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registered address (physical)Not yet published — available on request from the Information Officer (information.officer@go-toker.com)
TelephoneNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Emailinformation.officer@go-toker.com

2.1 Duties of the Information Officer

The Information Officer is responsible for:

DutyReference
Ensuring Toker's compliance with POPIAPOPIA s.55(1)(a)
Receiving and responding to data subject access requestsPOPIA s.23
Receiving and responding to data subject correction requestsPOPIA s.24
Receiving and responding to data subject deletion requestsPOPIA s.25
Receiving and responding to data subject objectionsPOPIA s.11(3)
Receiving and responding to data subject consent withdrawalsPOPIA s.11(2)
Coordinating with the Information RegulatorPOPIA s.55(1)(b)
Investigating data breaches and reporting to the Information RegulatorPOPIA s.22 + Cybercrimes Act 19 of 2020
Maintaining the operator registerPOPIA s.21
Staff training on POPIAPOPIA s.39 (Security measures)
Annual POPIA compliance auditPOPIA s.14 + Reg 4

3. Deputy Information Officer of Toker

FieldValue
NameNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registration number with the Information RegulatorNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Date of registrationNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registered address (postal)Not yet published — available on request from the Information Officer (information.officer@go-toker.com)
Registered address (physical)Not yet published — available on request from the Information Officer (information.officer@go-toker.com)
TelephoneNot yet published — available on request from the Information Officer (information.officer@go-toker.com)
Emaildeputy.information.officer@go-toker.com

3.1 Duties of the Deputy Information Officer

The Deputy Information Officer assists the Information Officer and may exercise the powers and perform the duties of the Information Officer in their absence. The Deputy Information Officer's responsibilities mirror those of the Information Officer (Reg 4).


4. How to contact the Information Officer

4.1 For data subject access requests (POPIA s.23)

ChannelValue
Emailinformation.officer@go-toker.com
In-appOpen a support ticket via Help & Support in your profile menu and ask for a "Data Access Request" (there is currently no self-service export)
Postal addressNot yet published — available on request from the Information Officer (information.officer@go-toker.com)

4.2 For privacy-related questions or complaints

ChannelValue
Emailprivacy@go-toker.com
Postal addressNot yet published — available on request from the Information Officer (information.officer@go-toker.com)

4.3 For security incident reports

ChannelValue
Emailsecurity@go-toker.com
EncryptionPGP key available on request

4.4 Response times

Type of requestAcknowledgementSubstantive response
POPIA s.23 access requestWithin 7 calendar daysWithin 30 calendar days
POPIA s.24 correction requestWithin 7 calendar daysWithin 30 calendar days
POPIA s.25 deletion requestWithin 7 calendar daysWithin 30 calendar days
POPIA s.11(3) objectionWithin 7 calendar daysWithin 30 calendar days
Privacy questionWithin 5 business daysWithin 30 calendar days
Security incident (incoming)Within 4 hours (24/7 on-call)Triage within 24 hours

5. The Information Regulator of South Africa

If you wish to lodge a complaint directly with the Information Regulator:

FieldValue
NameThe Information Regulator (South Africa)
Physical addressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal addressP.O. Box 31533, Braamfontein, Johannesburg, 2017
Complaints emailenquiries@inforegulator.org.za (use POPIA Complaints in the subject line)
General emailenquiries@inforegulator.org.za
Telephone+27 10 023 5200
Websitehttps://www.inforegulator.org.za/

We would, however, appreciate the opportunity to address your concern first — please email information.officer@go-toker.com.


6. Operator register (POPIA s.21)

The Information Officer maintains an Operator Register of every third party that processes personal information on behalf of Toker. The register is available on request to information.officer@go-toker.com and is summarised in the Privacy Policy §7.3.

OperatorFunctionLocationSafeguard
Not yet published — available on request from the Information Officer (information.officer@go-toker.com)

The current published summary is in the Privacy Policy §7.3.


7. Security measures (POPIA s.14)

The Information Officer is responsible for ensuring that appropriate, reasonable technical and organisational measures are in place to prevent loss, damage, unauthorised destruction, unlawful access, and unauthorised processing of personal information. These measures are described in the Privacy Policy §10 and in our internal security documentation (docs/SECURITY_AUDIT.md).


8. Data breach notification (POPIA s.22 + Cybercrimes Act)

In the event of a security incident that compromises the integrity or confidentiality of personal information:

  1. The Information Officer will be notified within 1 hour of the incident being identified;
  2. The Information Officer will assess whether the incident constitutes a "security compromise" under POPIA s.22 (i.e. there is a reasonable belief that the personal information has been accessed or acquired by an unauthorised person);
  3. If so, the Information Officer will:
  4. Notify the Information Regulator in writing within a reasonable time, providing the details required by POPIA s.22(3) and the Cybercrimes Act 19 of 2020;
  5. Notify affected data subjects in writing, by email or by prominent notice on the Platform, providing sufficient information to allow them to take protective measures;
  6. Engage with the Information Regulator's investigation;
  7. Document the incident in the audit log (7-year retention).

9. Annual compliance audit (POPIA s.14 + Reg 4)

The Information Officer conducts an annual POPIA compliance audit of Toker. The audit covers:

  • The eight processing conditions in POPIA s.8–25;
  • The security measures in POPIA s.14;
  • The operator register (s.21);
  • The breach response procedure (s.22);
  • The data subject rights procedure (s.23–25);
  • The cross-border transfers register (s.72);
  • The information security controls (technical + organisational).

The audit report is filed with the board of Toker and is made available to the Information Regulator on request.


10. Changes to this Notice

We may update this Notice from time to time. When we make a material change:

  • We will update the "Last Updated" date at the top of this document;
  • We will post a notice on the Platform;
  • We will notify the Information Regulator of any change to the designated Information Officer or Deputy Information Officer within 14 days of the change.

11. Contact

ChannelValue
Information Officerinformation.officer@go-toker.com
Deputy Information Officerdeputy.information.officer@go-toker.com
Privacy emailprivacy@go-toker.com
Information Regulatorenquiries@inforegulator.org.za

*This Notice is governed by the laws of the Republic of South Africa.* *Document version 1.0-draft — pending Information Officer registration and South African legal counsel sign-off.*