Legal

POPIA Compliance

Last updated: January 2025

Mint & Marine Dental Studio is committed to full compliance with the Protection of Personal Information Act, 4 of 2013 (POPIA) — South Africa's primary legislation governing the lawful collection, processing, storage, and sharing of personal information.

Information Officer

In terms of POPIA, Mint & Marine Dental Studio has designated a responsible Information Officer who oversees compliance with this Act.

Contact: Hello@mintandmarine.co.za  |  066 227 8515

1. What is POPIA?

POPIA is South Africa's data protection law, modelled in part on the European General Data Protection Regulation (GDPR). It came into full effect on 1 July 2021 and regulates how organisations collect and use personal information. It gives individuals ("data subjects") meaningful rights over their personal information and places responsibilities on organisations ("responsible parties") that process that information.

2. Our Commitment

As a registered healthcare practice, we handle personal information with the highest degree of care. We are committed to the eight conditions for lawful processing set out in POPIA:

Accountability

We take responsibility for all personal information under our control and ensure it is processed lawfully.

Processing Limitation

We collect only the minimum information necessary for the purpose for which it is collected.

Purpose Specification

Personal information is collected for a specific, explicitly defined purpose and not processed beyond that purpose.

Further Processing Limitation

Information is not used for a secondary purpose incompatible with the original purpose of collection.

Information Quality

We take reasonable steps to ensure that all personal information we hold is accurate, complete, and up to date.

Openness

We maintain documentation of all processing activities and notify individuals when their information is collected.

Security Safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, damage, and unlawful access.

Data Subject Participation

Individuals may request access to, correction of, or deletion of their personal information at any time.

3. Personal Information We Process

In the course of providing dental services and operating this website, we may process the following categories of personal information:

Special Personal Information (including health information) is processed only where required for the provision of healthcare, with your consent, or where permitted by applicable law.

4. Grounds for Processing

We process your personal information on one or more of the following lawful grounds:

5. Your Rights as a Data Subject

Under POPIA, you have the following rights in respect of your personal information:

To exercise any of these rights, please contact our Information Officer using the details below. We will respond within a reasonable period and, in any event, within 30 days.

6. Data Retention

Personal information is retained for only as long as necessary for the purpose for which it was collected, or as required by applicable law. Patient health records are retained in accordance with the National Health Act and HPCSA guidelines (generally a minimum of five years from the date of last treatment, or until a minor patient reaches the age of 21, whichever is longer). On expiry of the retention period, records are securely and irreversibly destroyed.

7. Security Measures

We implement appropriate physical, administrative, and technical safeguards to protect personal information against loss, theft, unauthorised access, disclosure, copying, use, or modification. In the event of a security compromise, we will notify the Information Regulator and affected data subjects as required by POPIA.

8. Third Parties and Operators

Where we share personal information with third-party service providers ("operators") — such as our website host or accounting software — we ensure that appropriate data processing agreements are in place to govern the lawful handling of your information.

We do not sell personal information to third parties and do not share it for marketing purposes without your explicit consent.

9. Information Regulator

If you are not satisfied with how we have handled your personal information, you have the right to lodge a complaint with the Information Regulator of South Africa:

Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Email: inforeg@justice.gov.za

Website: www.justice.gov.za/inforeg

10. Contact Our Information Officer

Mint & Marine Dental Studio — Information Officer

Westlake Lifestyle Centre, Cape Town, South Africa

Email: Hello@mintandmarine.co.za

Phone: 066 227 8515