Acceptable Use Policy
Summary: This policy governs the secure and lawful use of The National Debt Review Center's information and IT systems, setting clear rules to protect personal and company data, prevent misuse, and enforce compliance through monitoring and disciplinary action where necessary.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing personal information as set out in the Privacy Policy and Information Security Policy.
Scope
This policy applies to:
- All our information, whether electronic or otherwise, in any location;
- All information systems and applications; and
- Employees, contractors, and other individuals who have access to our information.
You must be familiar with this policy and comply with its terms. We may supplement or amend this policy with additional policies and guidelines from time to time.
Purpose
The purpose of this policy is to direct all employees of The National Debt Review Center Pty Ltd in the acceptable use and security of the business's IT system and infrastructure. These standards contain directions for employees, indicating both acceptable and unacceptable internet use to control employee behaviour and actions that contribute to the business's internet risks while maximising the benefits gained by The National Debt Review Center Pty Ltd through internet usage. As the software, hardware, and computer network is the property of The National Debt Review Center Pty Ltd, we reserve the right to keep our systems secure through monitoring electronic information and regular checks on the system.
Roles and Responsibilities
- The National Debt Review Center Pty Ltd management will establish a periodic reporting requirement to measure the compliance and effectiveness of this policy.
- The National Debt Review Center Pty Ltd management is responsible for implementing the requirements of this policy or documenting non-compliance.
- All of the business's employees are required to read and acknowledge this policy.
Policy Directives
Part I: Management Requirements
- The National Debt Review Center Pty Ltd will establish formal standards and processes to support the ongoing development and maintenance of the business's IT system and infrastructure;
- The National Debt Review Center Pty Ltd management will commit to the ongoing training and education of the business's staff responsible for the administration and/or maintenance and/or use of the business's IT system and infrastructure facilities;
- The National Debt Review Center Pty Ltd management will establish a formal review cycle for all Acceptable Use initiatives;
- Any security issues discovered must be reported to the Information Officer or Deputy Information Officer.
Part II: Ownership
Electronic files and communications created, sent, received, or stored on information resources owned, leased, administered, or otherwise under the custody and control of The National Debt Review Center Pty Ltd are the property of The National Debt Review Center Pty Ltd and employee use of these files and communications is neither personal nor private. The IT Department / IT Service Provider and the Information Officer or Deputy Information Officer may access all such files and communications at any time without the knowledge of the user or owner. The Information Officer or Deputy Information Officer and the IT Department / IT Service Provider and reserves the right to monitor and/or log all employee use of the business's information resources with or without prior notice.
Part III: Acceptable Use Requirements
- Employees will only be given sufficient rights to all systems to enable them to perform their job functions. User rights will be kept to a minimum at all times;
- Employees must report any weaknesses in the business's computer security to the IT Department. Weaknesses in computer security include unexpected software or system behaviour, which may result in unintentional disclosure of information or exposure to security threats;
- Employees must report any incidents of possible misuse of the IT system and infrastructure or violation of this Acceptable Use Policy to The National Debt Review Center Pty Ltd management;
- Employees must not attempt to access any data, documents, email correspondence, or programs contained on the business's systems for which they do not have authorisation;
- Employees must not attempt any access penetration tests, any investigations, or perform any other activities to compromise the access controls of the business's computing facilities unless there is a demonstrated business requirement to do so and The National Debt Review Center Pty Ltd management has approved of such activities;
- Systems administrators and authorised users must not divulge remote connection modem phone numbers or other access points to the business's computer resources to anyone without proper authorisation in writing;
- Employees must not share their account(s), passwords, Personal Identification Numbers (PIN), security tokens (i.e., smartcard), or similar information or devices used for identification and authorisation purposes;
- Employees must not make unauthorised copies of copyrighted software or software owned by the The National Debt Review Center Pty Ltd;
- Employees must not use non-standard shareware or freeware software without approval from The National Debt Review Center Pty Ltd management;
- Employees must not purposely engage in activity that may harass, threaten, or abuse others or intentionally access, create, store, or transmit material that The National Debt Review Center Pty Ltd may deem to be offensive, indecent, or obscene, or that is illegal in terms of legislation;
- Employees must not engage in activity that may degrade the performance of information resources, deprive authorised user access to the business's resources, obtain extra resources beyond those allocated, or circumvent the business's computer security measures;
- Employees must not download, install, or run security programs or utilities such as password cracking programs, packet sniffers, or port scanners that reveal or exploit weaknesses in the security of the business's computer resources unless approved by The National Debt Review Center Pty Ltd management;
- The business's information resources must not be used for personal benefit, political activity, unsolicited advertising, unauthorised fundraising, or for the solicitation of performance of any activity that is prohibited by relevant legislation;
- Access to the internet from home-based computers or computers owned by The National Debt Review Center Pty Ltd must adhere to all the policies. Employees must not allow family members or other non-employees to access non-public accessible computer systems of the business. Employees are not allowed to use personal computers or laptops for business use or connections to The National Debt Review Center Pty Ltd's network, locally or via VPN;
- Employees must not attempt to change the configuration of desktop computers and notebooks. All configuration changes must be handled by The National Debt Review Center Pty Ltd management for example, upgrading operating systems, changing Windows settings, installing new software or systems, and installing modems, memory, or storage upgrades.
Prohibited Uses
In particular, the business's IT system and infrastructure may not be used for any of the following:
- Communications in connection with the personal business interests of the user or the user's family;
- Downloading, transmission, and possession of pornographic and sexually explicit materials;
- Transmitting defamatory, slanderous, threatening, and abusive messages, inflammatory statements, or any message that may be construed as such;
- Political or religious statements, foul language, or any other statements viewed as harassing others based on race, creed, colour, age, sex, national origin, disability, or physical attributes are prohibited;
- Unauthorised attempts to bypass or any attempt to circumvent any security mechanisms of computers connected to the internet;
- Propagating, sending, responding to, redirecting, forwarding, or otherwise participating in chain letters or junk email;
- The alteration, destruction, or infringement of the privacy of other employees' computer-based information residing on the IT system and infrastructure and email systems;
- Playing computer games or engaging in any other form of entertainment or sporting activities during business hours;
- Any communications or activity which could harm the good name and reputation of the business.
Confidentiality Requirements
- Employees of The National Debt Review Center Pty Ltd may not send or publish confidential and private material of The National Debt Review Center Pty Ltd (internal memos, policies, etc.) on any publicly accessible or internet-accessible system of The National Debt Review Center Pty Ltd unless the owner of the information has first approved the publication of these materials.
- Employees should not transmit confidential information, information of the business, copyrighted materials, or any trade secrets of The National Debt Review Center Pty Ltd or its clients over any public computer system or network unless properly protected through encryption methods.
- Any security issues discovered must be reported to The National Debt Review Center Pty Ltd management and the Information Officer or Deputy Information Officers.
Enforcement, Auditing, Reporting
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Any employee must, at any time, report policy violations to the The National Debt Review Center Pty Ltd management which report will be reported as confidential and may be done anonymously.
Access Control Policy
Summary: This policy governs how The National Debt Review Center manages and controls user access to its information systems, ensuring only authorised individuals have appropriate privileges to protect confidentiality, integrity, and availability of company data, with strict enforcement for non-compliance.
1. Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing personal information.
2. Purpose
This policy establishes the guidelines for managing user access to information of the business. The purpose is to ensure the necessary user access controls are in place for controlling the actions, functions, applications and operations of legitimate users. The aim is to protect the confidentiality, integrity, and availability of all the business's information resources.
All managers of the business's information resources will ensure that access to the business's information is properly authorised and granted with correct access levels and privileges applied.
3. Scope
This policy applies to all information resources, systems, and technology and to all users of these resources, systems and technology within the business's operating environment or connected to the business's information infrastructure.
4. Operational Definitions
4.1. Authentication
Verification that the user's claimed identity is valid and is usually implemented through a user password at logon.
4.2. Discretionary user access
The ability to manipulate data using custom or general-purpose programs. The only information logged for discretionary control mechanisms is the type of data accessed and at what level of authority.
4.3. Identification
The act of a user professing an identity to a system, usually in the form of a logon to the system.
4.4. Non-discretionary user access
The access obtained in the process of specific business transactions that affect information in a predefined way. For example, the business's deployment specialists need to access participant information to make travel arrangements, but may not need the ability to change any existing information.
4.5. Password
An arrangement of characters entered by a system user to substantiate their identity, authority, and access rights to an information system they wish to use.
4.6. Privilege
The level of user authority or permission to access information resources. Privileges can be established at the folder, file, or application levels or for other conditions as applicable.
4.7. Special user access privileges
Privileges that allow users to perform specialised tasks that require broad capabilities. For example, changing control functions such as: access control, logging, and violation detection, require special access privileges.
4.8. User account
An issued name with authority, granted to an individual to access a system or software application. System administrators, with proper management approval, typically grant accounts. To access an account, a user needs to be authenticated, usually by providing a password.
4.9. User access controls
The rules and deployment of mechanisms, which control access in information resources, and physical access to premises.
5. Access Control Measures
5.1. User accounts
The creation of a user account must be initiated through a request to the Information Officer who is authorised to approve access to the specified resources.
5.2. Account management
The National Debt Review Center Pty Ltd management manages user accounts for the business's systems. Records of processed and denied requests for creation of user accounts must be kept for auditing purposes. Records will be retained for one year, unless otherwise specified in the Data Retention Policy.
5.3. User accounts characteristics
All employee user accounts must be unique, and traceable to the assigned user. The National Debt Review Center Pty Ltd management of the business will take appropriate measures to protect the privacy of user information associated with user accounts. The use of group accounts and group passwords is not allowed, unless specifically approved by The National Debt Review Center Pty Ltd management.
5.4. Password reset
The National Debt Review Center Pty Ltd management of the business will establish a procedure for verifying a user's identity prior to resetting their password.
5.5. User account privileges
Users will be granted the minimum access required to perform their specific tasks. Granting access levels to resources shall be based on the principle of least privilege, job responsibilities and separation of duties. The level of minimum access requires the recommendation of the user's manager and the evaluation of the Information Officer. The Information Officer has final determination as to the level of a user's access for their system.
5.6. Inactive accounts
Accounts will be disabled after 30 days of inactivity. Users planning to deploy to field operating locations or to be away from the office for other approved periods of extended absence should coordinate with The National Debt Review Center Pty Ltd management to ensure proper disposition of the account.
5.7. Temporary user accounts
All requests for temporary user accounts shall provide an expiration date to be applied at the time the account is created. Applications for temporary user accounts should be submitted for approval to The National Debt Review Center Pty Ltd management.
6. Roles and Responsibilities
- The National Debt Review Center Pty Ltd management will establish a periodic reporting requirement to measure the compliance and effectiveness of this policy;
- The National Debt Review Center Pty Ltd management is responsible for implementing the requirements of this policy or documenting non-compliance;
- The Information Officer and/or Deputy Information Officer(s), are required to train employees on the policy and document issues with policy compliance;
- All of the business's employees are required to read and acknowledge this policy by signing it;
- The Information Officer has primary management responsibility for administering user access to the business's information resources.
7. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Antivirus Policy
Summary: This policy establishes minimum anti-virus requirements for all computers connected to the business networks to ensure effective virus detection and prevention, protecting the integrity and availability of company information systems.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to the Anti-Virus's use and procedures within the business.
Purpose
The purpose of this policy is to establish minimum anti-virus requirements which must be met by all computers connected to the business's networks and to ensure effective virus detection and prevention.
Scope
This policy applies to all of the business's computers that are Macs, PC-based or utilise PC-file directory sharing. This includes, but is not limited to, desktop computers, laptop computers, file/ftp/tftp/proxy servers.
Roles and Responsibilities
All of the business's PC-based computers must have the business's standard, supported anti-virus software installed and scheduled to run at regular intervals. In addition, the anti-virus software and the virus pattern files must be kept up to date. Virus-infected computers must be removed from the network until they are verified as virus-free. The National Debt Review Center Pty Ltd management is responsible for creating procedures that ensure anti-virus software is run at regular intervals, and computers are verified as virus-free.
Any activities with the intention to create and/or distribute malicious programs into the business's networks (e.g., viruses, worms, Trojan horses, email bombs, etc.) are prohibited, in accordance with the Information Security Policy and/or Acceptable Use Policy.
Users must not attempt to remove viruses themselves. If a virus infection is detected, users must disconnect from the business's networks, stop using the infected computer immediately and notify The National Debt Review Center Pty Ltd management.
Users must be cautious of email attachments from an unknown source as viruses are often hidden in attachments. If a virus is suspected the attachment must not be opened or forwarded and must be deleted immediately.
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals are subject to loss of the business's information resources access privileges, civil, and criminal prosecution.
Clean Desk Policy
Summary: This policy sets minimum requirements for a "clean desk" to ensure all personal and sensitive information, whether in physical or electronic form, is secured when unattended, thereby preventing unauthorised access and protecting confidentiality.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd to establish minimum requirements to ensure information is not left unattended at your workstation.
Scope
This policy applies to all The National Debt Review Center Pty Ltd employees and affiliates contractors, and other individuals who have access to any information systems and/or records containing personal information processed by The National Debt Review Center Pty Ltd.
Purpose
The purpose of this policy is to establish the minimum requirements for maintaining a "clean desk" – where all personal information is used.
Policy Requirements
- Employees are required to ensure that all information in hardcopy or electronic form is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
- Computer workstations must be locked when workspace is unoccupied.
- Computer workstations must be shut down completely at the end of the workday.
- Any personal information must be removed from the desk and locked in a drawer when the desk is unoccupied, and at the end of the workday.
- File cabinets containing personal information must be kept closed and locked when not in use or when not attended.
- Keys used for access to personal information must not be left unattended.
- Laptops must be either locked with a locking cable or locked away in a drawer or office.
- Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
- Printouts containing personal information should be immediately removed from the printer.
- Upon disposal, documents containing personal information should be shredded in the official shredder bins or placed in the lock confidential disposal bins.
- Whiteboards containing restricted and/or sensitive information should be erased.
- Employees must treat mass storage devices such as CDROM, DVD or USB drives as sensitive, and secure them in a locked drawer.
- All printers and fax machines should be cleared of papers as soon as they are printed; this helps ensure that sensitive documents are not left in printer trays for the wrong person to pick up.
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Data Retention Policy
Summary: This policy sets out how The National Debt Review Center retains, protects, and securely disposes of business records and personal information in line with legal requirements, ensuring data is kept only for as long as necessary and destroyed in accordance with the Data Destruction Policy.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to data retention and procedures within the business.
Scope
This policy applies to all documents which are collected, processed, or stored by the business and includes but is not limited to documents in hardcopy and electronic format, for example, email, web and text files, PDF documents etc.
Purpose
The purpose of this policy is to ensure that necessary records and documents of the business are adequately protected and maintained to ensure that records are not retained for longer than necessary. This policy is also for the purpose of aiding employees of the business in understanding their obligations in retaining documents.
Guidelines for the Retention of Documents
- The business may suspend the destruction of any record or document due to pending or reasonably foreseeable litigation, audits, government investigations or similar proceedings. Employees will be notified of applicable documents to which they have access where the destruction has been suspended.
- All documentation and personal information that is being stored by the business in accordance with this policy must be stored and guarded in compliance with all the business's policies.
- The documentation and information listed below may not contain all the records and documents processed and in the possession of the business and should merely be used as a guideline.
- In the event that a document and/or information is no longer required to be stored in accordance with this policy and relevant legislation, it should be deleted and destroyed in accordance with the Data Destruction Policy of the business.
- The Information Officer should be consulted where there is uncertainty regarding the retention and destruction of a document and/or information.
Retention Schedules
Companies Act 71 of 2008
| No. | Type of Document | Retention Period |
|---|---|---|
| 1 | General Rule: Documents, communication etc, not listed below | Seven (7) years |
| 2 | Certificate of Incorporation | Seven (7) years |
| 3 | Memorandum of Incorporation and amendments | Indefinite |
| 4 | Rules | Indefinite |
| 5 | Register of Company Secretary and Auditors | Indefinite |
| 6 | Register of Beneficial Ownership greater than 5% | Indefinite |
| 7 | Documentation related to shareholder meetings | Seven (7) years |
| 8 | Reports presented at the AGM | Seven (7) years |
| 9 | Accounting records and annual financial statements | Seven (7) years |
| 10 | Securities register | Indefinite |
Basic Conditions of Employment Act 75 of 1997
| No. | Type of Document | Retention Period |
|---|---|---|
| 1 | Employee's employment contract, as well as other written records | Three (3) years after termination of employment |
| 2 | Time worked by employee | Three (3) years from last entry |
| 3 | Remuneration to be paid to each employee | Three (3) years from last entry |
| 4 | Date of birth of any employee under 18 years of age | Three (3) years after termination of employment |
National Credit Act 34 of 2005
| No. | Type of Document | Retention Period |
|---|---|---|
| 1 | Enquiries | One (1) year |
| 2 | Payment profile | Five (5) years |
| 3 | Adverse classification of enforcement action or consumer behaviour | One (1) year |
| 4 | Civil court judgements | The earlier of 5 years or until the judgement is rescinded by a court or abandoned |
| 5 | Maintenance judgments | Until rescinded by the court |
| 6 | Administration orders | Five (5) years or until the order is rescinded by a court |
| 7 | Sequestrations | Five (5) years or until rehabilitation order is granted |
| 9 | Rehabilitation orders | Five (5) years |
| 10 | Records to be retained in terms of Regulation 55(1)(a) – (d) | Three years from the earliest date on which the registrant created, signed, or received the document |
| 11 | Records kept in terms of Section 170 | Three (3) years for date of termination of the agreement, or for a refused application, the date of such application |
Consumer Protection Act 68 of 2008
| No. | Type of Document | Retention Period |
|---|---|---|
| 1 | Information provided to a consumer by an intermediary | Three (3) years |
| 2 | Written disclosure of conflict of interest by an intermediary | Three (3) years |
| 3 | Record of advice given to consumer | Three (3) years |
| 4 | Written instruction given to consumer | Three (3) years |
| 5 | Details pertaining to Promotional Competitions – Section 36 and Regulation 11 | Three (3) years |
| 6 | Written agreement containing terms and conditions regarding the sale of goods at auctions | Three (3) years |
Additional Legislative Requirements
The complete Data Retention Policy also includes specific retention periods for documents under:
- • Close Corporations Act 69 of 1984
- • Labour Relations Act 66 of 1995
- • Employment Equity Act 55 of 1998
- • Unemployment Insurance Act 63 of 2001
- • Occupational Health and Safety Act 85 of 1993
- • Income Tax Act 58 of 1962
- • Value Added Tax Act 89 of 1991
- • Financial Intelligence Centre Act 38 of 2001
For complete retention schedules covering all applicable legislation, please contact our Information Officer.
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Email Policy
Summary: This policy regulates employee use of The National Debt Review Center's email system to ensure it is used strictly for business purposes, prohibits offensive or confidential information misuse, allows monitoring without notice, and enforces compliance through disciplinary action.
1. Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing personal information. This policy and procedures are a supplement to The National Debt Review Center Pty Ltd's Information Security Policy.
2. Scope
This policy applies to:
- all our information, whether electronic or otherwise, in any location;
- all information systems and applications; and
- employees, contractors, and other individuals who have access to our information.
You must be familiar with this policy and comply with its terms. We may supplement or amend this policy with additional policies and guidelines from time to time.
3. Purpose
The business provides employees with electronic communication tools, including an email system. This email policy, which governs employee use of the business email system, applies to email use at the business's premises, as well as remote locations, including, but not limited to employee homes, airports, hotels and client and supplier offices. The business's email rules and policies apply to full-time employees, part-time employees, independent contractors, interns, consultants, suppliers, clients, and other third parties. Any employee who violates the business's email rules and policies is subject to disciplinary action, up to and including termination.
4. Email exists for business purposes
The business allows email access primarily for business purposes and employees may not use the email system for any personal use.
5. Email monitoring activities
The business reserves the right to monitor, inspect, copy, review, and store any and all employee's email use at any time and without prior notice. In addition, the business may monitor, inspect, copy, review, and store any files, information, software, and other content created, sent, received, downloaded, uploaded, accessed, or stored through the business's email system. The business reserves the right to disclose e-mail information and images to regulators, courts, law enforcement agencies and other third parties without the employee's consent.
6. Offensive content and harassing or discriminatory activities are banned
Employees are prohibited from using e-mail to engage in activities or transmit content that is harassing, discriminatory, menacing, threatening, obscene, defamatory, or in any way objectionable or offensive.
7. Employees are prohibited from using email to
- Send, receive, solicit, print, copy, or reply to text, images, or jokes that disparage others based on their race, religion, colour, gender, sex, sexual orientation, national origin, veteran status, disability, ancestry, or age.
- Send, receive, solicit, print, copy or reply to messages that are disparaging or defamatory.
- Spread gossip, rumours, or innuendos about employees, clients, suppliers, or other outside parties.
- Send, receive, solicit, print, copy or reply to sexually orient messages or images.
- Send, receive, solicit, print, copy or reply to messages or images that contain foul, obscene, disrespectful, or adult-oriented language.
- Send, receive, solicit, print, copy or reply to messages or images that are intended to alarm others, embarrass the business, negatively impact employee productivity, or harm employee morale.
8. Confidential, proprietary, and personal information must be protected
Unless authorised to do so, employees are prohibited from using email to transmit confidential information to outside parties. Employees may not access, send, receive, solicit, print, copy or reply to confidential or proprietary information about the business, its employees, clients, suppliers, and other business associates unless there is a legitimate reason to do so. Confidential information includes, but is not limited to, client lists, credit card numbers, identification numbers, employee performance reviews, salary details, trade secrets, passwords and information that could embarrass the business and its employees if the information were disclosed to the public.
9. Information exchange and internet transactions
- All messages communicated on the business's internet and email system must contain the employee's name, surname, title, and contact details. No email or any other electronic communication may be sent which hides the identity of the sender or represents the sender as someone else. All emails sent must include the email signature of the sender.
- The disclaimer as prescribed by The National Debt Review Center Pty Ltd management must be used at the end of all email messages.
10. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Any employee must, at any time, report policy violations to The National Debt Review Center Pty Ltd management which report will be reported as confidential and may be done anonymously.
Handheld and Mobile Device Policy
Summary: This policy governs the authorised use, security, inventory, and management of mobile and handheld devices at The National Debt Review Center Pty Ltd to protect business data and ensure compliance, with violations subject to disciplinary and legal action.
1. Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing the confidentiality and integrity of personal information processed by The National Debt Review Center Pty Ltd by governing the use handheld and mobile devices.
2. Scope of application and obligations
This policy applies to all employees, consultants, vendors, contractors, students and others using business or private mobile handheld devices on any premises occupied by the business.
Adherence to these requirements and the security policies derived from them and implementation of provisions is binding across the whole of the business, its subsidiaries and majority holdings.
Wilful or negligent infringement of the policies jeopardises the interests of the business and will result in disciplinary, employment and/or legal sanctions. In the case of the latter the relevant line managers and where applicable legal services shall bear responsibility.
These requirements and the security policies derived from them and implementation provisions also apply to all suppliers of the business. They shall be contractually bound to adhere to the security directives. If a contractual partner is not prepared to adhere to the provisions, he must be bound in writing to assume any resulting consequential damage.
3. Purpose
This policy establishes rules for the proper use of handheld and mobile devices in the business in order to protect the confidentiality of sensitive data, the integrity of data and applications and the availability of services at the business, protecting both handheld devices and their users, as well as corporate assets (confidentiality and integrity) and continuity of the business.
4. Roles and responsibilities
- The National Debt Review Center Pty Ltd management must ensure that all employees using devices falling into the category of "handheld devices" have acknowledged this security policy and the associated procedures before they are allowed to use corporate services using handheld devices.
- The National Debt Review Center Pty Ltd management must ensure that handheld devices and their users comply with this security policy and all security policies as stipulated by the business.
- In a general sense, all users are required to use their common sense in order to act in the best interest of the business, its assets and its services.
- In case of doubt, users must contact The National Debt Review Center Pty Ltd management to clarify a given situation.
- Users of handheld devices must diligently protect such devices from loss and disclosure of private information belonging to or maintained by the business.
- Before connecting a mobile handheld device to the network at the business, users must ensure it is on the list of approved devices issued by The National Debt Review Center Pty Ltd management.
- The National Debt Review Center Pty Ltd management must be notified immediately upon suspicion of a security incident, especially when a mobile device may have been lost or stolen.
- The cost of any item beyond the standard authorised equipment is the responsibility of the employee.
5. Use of private handheld devices
The Information Officer and/or Deputy Information Officer/ IT Department / IT Service Provider must define whether private handhelds are authorised to connect to the business's networks.
Private handhelds are authorised:
- Any non-business-owned (private) device able to connect to the business's network must first be approved by the The National Debt Review Center Pty Ltd management.
- If allowed, privately-owned handheld devices must comply with this policy and must be inventoried along with corporate handheld devices, but identified as private. This is in order to prevent theft of corporate data with unmanaged handhelds.
8. Inventory of mobile handheld devices
The National Debt Review Center Pty Ltd management must keep inventory of handhelds in use in the business, using associating owner names and identity for network access control.
The inventory must take into account at least but not limited to the following list of identifiers:
- Device name;
- Owner's ID;
- Device serial number;
- Device IMEI;
- Device's MAC address;
- Owner's ID (user);
- User's MSISDN;
- Device capabilities (Bluetooth, IrDA, camera, etc.);
- Supplementary accessories provided.
11. Unauthorised actions
Users must not modify security configurations without request to and approval by The National Debt Review Center Pty Ltd management
Unauthorised actions:
- Installing and/or using unauthorised applications or services;
- Removing root certificates from certificate stores;
- Conducting any careless actions leading to an interruption of service;
- Disabling security features.
13. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Incident Response Policy
Summary: This policy establishes clear procedures for all staff to promptly identify, report, and respond to personal information breaches, ensuring containment, risk assessment, notification to affected individuals and the Information Regulator as required by POPIA, and continuous evaluation to prevent future incidents. Training is mandatory for all employees, and failure to comply may result in disciplinary or legal action.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing personal information breaches effectively.
2. Scope
This policy applies to all staff. You must be familiar with this policy and comply with its terms. This policy supplements our other policies relating to information use. We may supplement or amend this policy by additional policies and guidelines from time to time.
5. Data breaches
Data breaches may be caused amongst other things, by employees, external parties, third party service providers and computer system errors or vulnerability. Below are a few examples of possible ways in which a data breach can occur:
5.1 Human error
- Loss of computing devices (portable or otherwise), data storage devices, or paper records containing personal information;
- Disclosing data to a wrong recipient/s;
- Handling data in an unauthorised way (downloading information owned by The National Debt Review Center Pty Ltd for personal use);
- Unauthorised access or disclosure of personal information by employees (sharing passwords);
- Improper disposal of personal information (hard disk, storage media, or paper documents containing personal information sold or discarded before data is properly deleted).
5.2 Malicious activities
- Hacking incidents / illegal access to databases containing personal information;
- Theft of computing devices (portable or otherwise), data storage devices, or paper records containing personal information;
- Scams that trick The National Debt Review Center Pty Ltd staff into releasing personal information of individuals.
5.3 Computer system error
- Errors or bugs in The National Debt Review Center Pty Ltd's software platforms or websites;
7. Responding to a data breach
Upon being notified of a suspected or confirmed data breach, the Data Breach Team should immediately activate the data breach management and response plan.
The National Debt Review Center Pty Ltd's data breach management and response plan is:
- Confirm the breach;
- Contain the breach;
- Assess risks and impact;
- Report the incident;
- Evaluate the response & recovery to prevent future breaches;
7.1.2 Contain the Breach
The Data Breach Team must consider the following measures to contain the breach, where applicable:
- Shut down the compromised system that led to the data breach.
- Establish whether steps can be taken to recover lost data and limit any damage caused by the breach (remotely disabling / wiping a lost notebook containing personal information of individuals).
- Prevent further unauthorised access to the system.
- Reset passwords if accounts and / or passwords have been compromised.
- Isolate the causes of the data breach in the system, and where applicable, change the access rights to the compromised system and remove external connections to the system.
7.1.4.2 What to notify
The business must ensure that the written notification provide sufficient information to allow the data subject to take protective measures against the potential consequences of the compromise, including –
- A description of the possible consequences of the security compromise;
- A description of the measures that the business intends to take or has taken to address the security compromise;
- A recommendation with regard to the measures to be taken by the data subject to mitigate the possible adverse effects of the security compromise; and
- If known to the business, the identity of the unauthorised person who may have accessed or acquired the personal information.
8. Consequences of failing to comply and enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Information Classification Policy
Summary: This policy governs the classification, handling, and protection of information at The National Debt Review Center Pty Ltd, ensuring appropriate access and security levels, with violations subject to disciplinary and legal action.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd to classify information within the business.
Purpose
The purpose of this policy is to classify information to ensure that the correct standards and principles are applied to that information.
Scope
This policy applies to all employees, contractors, and other individuals who have access to our information systems, infrastructure, and applications of the business and all records collected, processed, and/or stored by the business and includes, but is not limited to, documents in hardcopy and electronic format, for example, email, web and text files, PDF documents etc.
Responsibility
All of the business's employees share in the responsibility for ensuring that the information receives an appropriate level of protection:
- Managers of the business or information "owners" shall be responsible for assigning classifications to information according to the standard information classification system presented below: "owners" have approved management responsibility, "owners" do not have property rights.
- All employees of the business shall be guided by the information category in their security-related handling of the business's information.
- All information of the business and all information entrusted to the business from third parties fall into one of three classifications in the table below, presented in order of increasing sensitivity.
Information Classification System
| Category | Description | Examples |
|---|---|---|
| Unclassified Public | Information is not confidential and can be made public without any implications for the business. | Product brochures widely distributed. Information widely available in the public domain, including publicly available web site areas of the business. Sample downloads of the business's software that is for sale. Financial reports required by regulatory authorities. Newsletters for external transmission. |
| Proprietary | Information is restricted to management approved internal access and protected from external access. Unauthorised access could influence the business's operational effectiveness, cause an important financial loss, provide a significant gain to a competitor, or cause a major drop in customer confidence. Information integrity is vital. | Passwords and information on corporate security procedures. Know-how used to process client information. Standard Operating Procedures used in all parts of the business activities. All software codes developed by the business, whether used internally or sold to clients. |
| Confidential Data | Information collected and used by the business in the conduct of its business to employ people, to log and fulfil client orders, and to manage all aspects of corporate finance. Access to this information is very restricted within the business. The highest possible levels of integrity, confidentiality, and restricted availability are vital. | Salaries and other personnel data. Accounting data and internal financial reports. Confidential customer business data and confidential contracts. Non-disclosure agreements with client's/vendor's business plans. |
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Information Security Policy
Summary: This policy governs the use, security, and management of The National Debt Review Center Pty Ltd's information systems, infrastructure, and applications to protect business data, ensure compliance with POPIA, and outline user responsibilities. Violations may result in disciplinary or legal action.
1. Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to the Information Systems' use and procedures within the business. This policy and procedures is an overview that consist of various supplementary policies referenced within this policy.
The National Debt Review Center Pty Ltd is required to take appropriate, reasonable technical and organisational measures to protect the information systems, infrastructure, and applications that we possess or control, to prevent unauthorised access, collection, use, disclosure, or similar risks.
For The National Debt Review Center Pty Ltd to prosper and comply with the above stated requirement and its commitment to accountability in terms of POPIA, we need to protect the information and systems entrusted to us. That is why we have created this policy, and the supplementary policies, to ensure that our information is adequate and secured against irresponsible use, breaches of confidentiality, failures of integrity, and interruptions to availability.
2. Scope
This policy applies to:
- All our information, whether electronic or otherwise, in any location.
- All information systems, infrastructure, and applications.
- Employees, contractors, and other individuals who have access to our information systems, infrastructure, and applications.
- IT equipment that includes desktop PCs, laptops, tablets, printers, physical and wireless network, VPN, and all data centre equipment (servers, switches, routers).
3. Purpose
The purpose of this policy is to inform all The National Debt Review Center Pty Ltd employees of their responsibilities and guidelines when making use of and accessing information systems, infrastructure, and applications provided by The National Debt Review Center Pty Ltd, as well as to inform employees of the technical and organisational measures to secure the integrity and confidentiality of all IT systems, infrastructures and applications.
8. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Physical Security Policy
Summary: This policy governs the physical protection of The National Debt Review Center Pty Ltd's premises, IT resources, and equipment against unauthorised access and physical threats. It mandates controlled access, secure areas, visitor management, and the safeguarding of devices, with violations subject to disciplinary and legal action.
Introduction
This Policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to the business's premises that include computers and other types of information technology resources which must be safeguarded against unlawful and unauthorised physical intrusion, as well as fire, flood, and other physical threats.
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Privacy Policy – General Processing of Personal Information
Summary: This policy establishes The National Debt Review Center Pty Ltd's commitment to full compliance with the Protection of Personal Information Act. It defines key data privacy terms, outlines roles and responsibilities, particularly of the Information Officer and sets principles for lawful, secure, and ethical processing of personal information. All staff must protect personal data integrity, confidentiality, and availability, report breaches immediately, and complete mandatory training. Violations will lead to disciplinary and legal consequences.
1. Purpose
The purpose of this policy is to establish a compliance framework for The National Debt Review Center Pty Ltd to ensure compliance with the Protection of Personal Information Act.
6. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Data Destruction Policy
Summary: This policy outlines secure data destruction procedures to ensure that all physical and electronic information, including storage media, is permanently and irretrievably destroyed in compliance with internal policies and legal requirements, preventing unauthorised access or recovery.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to data destruction and procedures within the business.
Purpose
The purpose of this policy is to provide guidance to the business's employees regarding the destruction of documentation. All forms of computer equipment, digital storage media and printed or handwritten material must be disposed of securely when no longer required. Secure disposal maintains our data security and supports compliance with the business policies and procedures.
The business realises that electronic devices and media can hold vast amounts of information, some of which can linger indefinitely and sees compliance with this policy as of the utmost importance in order to ensure that restricted data and/or personal information does not find its way into unauthorised hands.
Scope
This policy aims to ensure secure disposal of data and personal information regardless of form, and applies to all employees of the business, it's premises and networks as well as visitors and third parties. This policy applies to all information systems owned by the business and includes personal computers, laptops, mobile phones, handheld computers, servers and external or removable storage devices and hard copy materials.
Secure Disposal
- In determining whether a document and/or information should be stored or disposed of, each employee should first refer to the Data Retention Policy and in the event of any uncertainties, to the Information Officer or Deputy Information Officer of the business.
- Under no circumstances should paper documents or removable media (CD's, DVD's, discs, etc.) containing personal or confidential information be simply binned or deposited in refuse bins.
- The business will ensure that all, electronic equipment and data on disk drives be physically removed and destructed in such a way that the data will by no means be able to be retrieved.
- Employees must ensure that all paper documents that should be disposed of, must be disposed of as per the internally approve procedures and then be recycled with the minimum requirement being that the information thereon must be de-identified.
- In the event that a third party is used for data destruction purposes, this third party must also comply with the regulations as stipulated in this policy and any other applicable legislation.
Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals may be subject to loss of the business's information resources access privileges and/or further civil and criminal prosecution.
Additional Policies
The complete Protection of Personal Information Policy includes additional detailed policies covering:
For access to the complete policy documentation or specific policy details, please contact our Information Officer at[email protected]
Contact Information
Information Officer
The National Debt Review Center Pty Ltd
Address: 36 Mangold Street, Newton Park, Gqeberha, 6045, Eastern Cape
Phone: 041 012 5036
Email: [email protected]
Information Regulator
If you have concerns about how we handle your personal information, you may contact the Information Regulator:
Website: inforegulator.org.za
Email: [email protected]
Risk Management Policy
Summary: This policy directs The National Debt Review Center Pty Ltd's proactive management of risks related to personal information processing. It requires all employees to identify, assess, control, and monitor risks, supported by regular reviews and documentation. The Information Officer oversees ensuring adequate resources and processes are in place to minimise risk in line with POPIA compliance. Breaches of this policy will lead to disciplinary and legal action.
1. Introduction
This Policy aims to guide The National Debt Review Center Pty Ltd in managing all risk relating to Information Privacy and procedures within the business.
2. Purpose and scope
This policy establishes the process for the management of risks pertaining to personal information faced by the business. The aim of risk management is to maximise opportunities in all the business activities and to minimise risk. The policy applies to all activities relating to the processing of personal information in the business. It is the responsibility of all employees to identify, analyse, evaluate, respond, monitor, and communicate risks associated with any activity, function or process relating to the processing of personal information.
3. Definitions
- "Risk" means risk related to processing of personal information in the business.
- "Risk control" means taking action to first eliminate risk so far as is reasonably practicable, and if that is not possible, minimising the risks so far as is reasonably practicable.
- "Risk management" means the application of a management system and includes identification, analysis, treatment, and monitoring.
- "Risk owner" means the person(s) responsible for managing risks and is usually the person directly responsible for the strategy, activity or function that relates to the risk.
4. Principles
The business is proactive in its approach to risk management, balances the cost of managing risk with anticipated benefits, and undertakes contingency planning in the event that critical risks are realised. The business has the primary duty to ensure the reasonable technical and organisational measures are implemented to minimise internal and external risk.
5. Functions and delegations
The Information Officer must exercise due diligence to ensure that the business complies with POPIA and this policy. This includes taking reasonable steps to:
- gain an understanding of the risks associated with the operations of the business; and
- ensure that the business has and uses appropriate resources and processes to eliminate or minimise risks.
All employees must contribute to the establishment and implementation of risk management systems for all functions and activities of the business. These risk management practices must align with all policies and applicable legislation.
6. Risk management principles
The business must take into consideration the following aspects in adhering to risk management compliance:
6.1 How to assess risk
A Personal Information Impact Assessment must be conducted to ensure that all internal and external risks are identified, mitigated, and addressed.
6.2 Consulting with employees
It is imperative that the employees of the business are made aware of the inherent risks when they process personal information. It is important to have regular meetings with such employees to make sure that the employees have a thorough understanding of the processes and procedures in place to minimise such risk.
6.3 How to control risks
It is important that upon identifying potential risk areas, appropriate measures be put in place to control and/or minimise those risk areas. Where it is possible for the risk to be eliminated completely, this should be done without delay. The responsible person who oversees this potential risk area must be made aware of such risk to implement appropriate safeguards.
6.4 How to review controls
It is important that the business reviews the control measures in place to eliminate and minimise the risk areas on a regular basis.
6.5 How to keep records
It is essential that the business documents and stores all applicable information regarding potential risk areas, as well as the decisions that was made and implemented to address those risk areas. These documents should be stored in accordance with the Data Retention Policy, as well as applicable legislation.
7. Role and responsibility of the Information Officer
The business must take into consideration that the elected Information Officer needs to ensure that all employees, subcontractors, representatives, agents and suppliers have a reasonable understanding of the risks associated with the day-to-day responsibilities and operations in ensuring that the business uses all appropriate resources and available processes to eliminate the business's risk element.
8. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals are subject to loss of the business's information resources access privileges, civil, and criminal prosecution.
Surveillance and Monitoring Policy
Summary: This policy directs The National Debt Review Center Pty Ltd's responsible use of surveillance and monitoring systems to safeguard business premises, employees, clients, and visitors. It requires management and Information Officer approval for camera installations, restricts access to authorised, trained personnel, and mandates appropriate data privacy safeguards including Data Processing Agreements with third parties. Surveillance footage retention and release are controlled by management or the Information Officer. Breaches of this policy will lead to disciplinary and legal action.
Introduction
This policy aims to guide The National Debt Review Center Pty Ltd in managing all aspects related to Surveillance and Monitoring Systems and procedures within the business.
2. Purpose
The purpose of this policy is to regulate:
- the use of the surveillance and monitoring equipment;
- the safety and property of the business, its employees, and visitors; and
- the applicable legal and privacy interests of the business, its clients, and employees.
3. Scope
This policy applies to The National Debt Review Center Pty Ltd, all permanent and temporary employees, contractors, consultants, including all personnel affiliated with third parties who use surveillance cameras in the business and/or conduct surveillance monitoring and recording.
4. Definitions
Surveillance camera
Any item, system, camera, technology device, communications device used alone or in conjunction with a network for the purpose of gathering, monitoring, recording or storing an image or images of the business and/or people at the premises of the business. Images captured by surveillance cameras may be real-time or preserved for review at a later date. Such devices may include, but are not limited to the following:
- Close-circuit television;
- Web cameras;
- Real-time surveillance systems;
- Computerised visual monitoring;
- Cell phone with cameras.
4.2 Surveillance monitoring or recording
Using surveillance cameras or other related technology to observe, review or store visual images for the purpose of deterring crime and protecting the safety and security of the business.
4.3 The business premises
All areas on property owned, leased or controlled by the business, both internal and external, including offices, common spaces and other areas.
5. Compliance principles
The business is committed to integrating the best security. The business's use of surveillance cameras for surveillance monitoring or recording must be:
- Conducted in a professional, ethical, and legal manner;
- Compliant with the business's policies and procedures;
- Limited to uses that does not violate a person's reasonable expectation of privacy, as defined by current legal requirements.
6. Procedures
- Installation and/or placement of surveillance cameras in the business premises must be approved by the The National Debt Review Center Pty Ltd management and the Information Officer.
- Only employees designated by the The National Debt Review Center Pty Ltd management and the Information Officer will have access to the images captured by surveillance monitoring or recordings.
- All existing uses of surveillance cameras and surveillance monitoring or recording, subject to this policy, must comply with this policy. A request to continue using the existing surveillance cameras will be submitted to the Information Officer. Network connectivity for surveillance monitoring or recording must comply with the business's policies.
- Violations of these procedures may result in disciplinary action in accordance with the policies, contracts, rules and regulations of the business.
7. Training
The Information Officer will ensure that the designated employees will be trained on the responsible use of the information and technology. Designated employees will also be supervised by a specific supervisor, with periodic review performed by the Information Officer or the Deputy Information Officer.
8. Retention and release of information
- The business will retain images obtained through surveillance monitoring or recording for a length of time deemed appropriate for the purpose, unless such images have historical value, or are being used for a criminal investigation. Any questions regarding the retention of these images should be directed to the Information Officer.
- Only The National Debt Review Center Pty Ltd management and / or the Information Officer can authorise the release of information and results obtained through surveillance monitoring or recording.
- Where third parties have access to The National Debt Review Center Pty Ltd's Surveillance and Monitoring equipment it is the responsibility of The National Debt Review Center Pty Ltd management to enter into Data Processing Agreements with these third parties to ensure data privacy protection.
9. Enforcement
Violation of this policy will result in disciplinary action that may include termination for employees and temporaries, termination of employment relations in the case of contractors or consultants, or dismissal for interns and volunteers. Additionally, individuals are subject to loss of the business's information resources access privileges, civil, and criminal prosecution.
Conclusion
We are committed to safeguarding your personal information with the utmost care and professionalism. Your privacy is a priority at The National Debt Review Center, and we continuously review our practices to ensure compliance with POPIA and to protect your data against any unauthorised access, loss, or misuse.
Should you have any questions, concerns, or wish to exercise your rights under POPIA, please contact our Information Officer at [email protected]. By continuing to use our services, you confirm your acceptance of this policy and our commitment to protecting your privacy.
Last Updated: September 15, 2025
Next Review Date: September 15, 2026
Document Reference: NDRC-POPIA-POL-2025