Privacy Policy

POPIA-compliant notice on how Labour Shield processes your personal information.

POPIA Compliant – Protection of Personal Information Act, 4 of 2013

Last updated: 04 April 2026 • Effective date: 1 July 2021

1. Introduction & Responsible Party

Labour Shield (Pty) Ltd ("Labour Shield", "we", "us", "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and all applicable South African data-protection legislation.

Labour Shield is the Responsible Party as defined in POPIA. Our Information Officer can be contacted at:

  • Address: Suite 5, Tasica House, 12 Charles Way, Kloof, 3610
  • Phone: 031 263 0037
  • Email: info@labourshield.net

2. Personal Information We Collect

We collect personal information necessary to deliver our HR, industrial relations, and payroll services, including but not limited to:

  • Identity information: full name, South African ID number, date of birth
  • Contact details: email address, phone number, physical address
  • Employment information: employer name, position, department, employment type, start date
  • Financial information: salary, banking details, PAYE tax number, UIF reference number
  • Disciplinary records: warnings, hearings, outcomes (where applicable)
  • Leave records: leave requests, balances, and approvals
  • Login credentials: username (passwords are hashed and never stored in plaintext)
  • Communication records: contact form submissions, consultation booking details

3. Purpose of Processing (Section 13 – POPIA)

We process personal information only for the following specific, lawful purposes:

  • Providing HR, payroll processing, and industrial relations services to employer clients
  • Managing employee self-service functions (payslips, leave, disciplinary records)
  • Statutory compliance: PAYE, UIF, COIDA/IOD submissions, SDL levy administration
  • Service request management and client communication
  • Consultation bookings and scheduling
  • Legal compliance, dispute resolution, and CCMA/Bargaining Council proceedings
  • Improving our services and internal administration

4. Lawful Basis for Processing

We process your personal information on one or more of the following lawful grounds:

  • Consent: You have given explicit consent during registration or engagement
  • Contract: Processing is necessary to fulfil a contract with you or your employer
  • Legal obligation: We are required to process certain data by law (e.g. SARS, Department of Labour)
  • Legitimate interest: Processing is necessary for our legitimate business interests, balanced against your rights

5. Security of Personal Information (Section 19 – POPIA)

Labour Shield implements appropriate technical and organisational security measures to protect your personal information against loss, damage, unauthorised access, interference, modification, or disclosure. Specifically:

  • All sensitive personal data is encrypted at rest using AES-256-CBC encryption
  • Passwords are hashed using bcrypt (cost factor 12) and never stored in plaintext
  • CSRF token protection on all web forms
  • Session security with session regeneration on login
  • Access to personal data is restricted to authorised personnel only
  • Secure HTTPS transmission of all data

6. Sharing of Personal Information (Section 11 – POPIA)

We do not sell, rent, or trade your personal information to third parties. We may share your information only:

  • With your employer (in our role as HR/payroll service provider)
  • With South African Revenue Service (SARS) for PAYE and other statutory submissions
  • With the Department of Employment and Labour for UIF and COIDA/IOD purposes
  • With the CCMA or Bargaining Council where we represent parties in disputes
  • With service providers who assist us in delivering our services, subject to data processing agreements
  • Where required by law, court order, or lawful government instruction

7. Retention of Personal Information (Section 14 – POPIA)

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

  • Payroll records: 5 years (SARS requirement)
  • Employment records: Duration of employment + 3 years
  • UIF records: 4 years
  • Disciplinary records: Duration of employment
  • General contact/enquiry records: 2 years

8. Your Rights as a Data Subject (Section 23–25 – POPIA)

You have the following rights regarding your personal information:

  • Right to access: Request a copy of your personal information we hold
  • Right to correction: Request correction of inaccurate or incomplete information
  • Right to deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Right to object: Object to the processing of your personal information
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
  • Right to lodge a complaint: Lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, contact our Information Officer at info@labourshield.net.

9. Information Regulator

If you believe we have not handled your personal information in accordance with POPIA, you may lodge a complaint with:

10. Cookies & Website Usage

Our website uses session cookies solely for authentication and security purposes (CSRF protection). We do not use tracking cookies, analytics cookies, or third-party advertising cookies. No personal information is collected through cookies beyond what is necessary for secure session management.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of material changes via the portal. The date of the most recent update appears at the top of this page.

For any privacy-related queries, contact our Information Officer at info@labourshield.net or call 031 263 0037.