Introduction:
The purpose of this policy is to describe the way that Broad Risk Assessors (Pty) Ltd collects, stores, uses, and protects information.
Protection of Personal Information Act (POPIA) defines personal information as “information which relates to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person”. This includes, but is not limited to, a data subject’s name, sex, gender, address, contact details, identity number and medical or health information.
The GDPR “REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of the personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)” defines personal data as follows:
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
2. How Broad Risk Assessors Collects data:
Directly from data-subjects upon completion of any of the contact forms on the Broad Risk Assessors website, www.broadrisk.co.za.
From duly authorised third parties such as insurance brokers that make use of our services as loss adjusters.
The technologies for automatic data collection by means of “cookies” described below.
Cookies (or browser cookies).
A cookie is a small file placed on the hard drive of a computer. A data subject may refuse to accept browser cookies by activating the appropriate setting on their browser. However, if this setting is selected certain parts of the website may not function. Unless a data subject has adjusted their browser setting so that it will refuse cookies, our system will issue cookies when a browser is directed to our website.
3. What information Broad Risk Assessors collects:
Broad Risk Assessors (Pty) Ltd applies the principle of “data minimization” as described in Article 5 of the GDPR. We collect the following information as is required of us as a loss adjustment company:
- Personal information: Name, surname, identity number, age, date of birth, nationality, vehicle registration number and occupation.
- Contact information: Mobile phone number, physical address, work address and email address.
- Contractual information: E.g., policies held by data-subjects with insurance companies.
- Details of visits to our website, including traffic data, location data, logs, and other communication data and the resources that is accessed and used on the Website.
- Information about a user’s computer and internet connection, including IP address, operating system, and browser type.
4. How Broad Risk Assessors (Pty) Ltd uses information:
For us to conduct our business as a loss adjustment company, we will use the information provided to us by the data-subject’s insurance broker to do the following:
- Conduct loss adjustment assessment.
- Compile assessment reports.
- To meet our contractual obligations.
- For audit and record-keeping purposes;
- To comply with legislative and regulatory requirements
5. Sharing of information:
Broad Risk Assessors (Pty) Ltd will never sell, share, or trade personal information with any third party. We will disclose information only when lawfully required to do so:
- To comply with any relevant legislation.
- To comply with any legal process; and
- By any relevant regulatory authority.
6. Transfer across borders
Broad Risk Assessors (Pty) Ltd makes use of cloud storage solutions by Microsoft and Google, these service providers may make use of servers located outside of the Republic of South Africa and the European Union.
7. Security and storage of information
Broad Risk Assessors intends to protect the integrity and confidentiality of personal information/data as is good practice and is required by legislation. Broad Risk Assessors have implemented the necessary technical and organisational methods (including, encryption and data minimization) to personal information to ensure that it is secure, accurate, current, and complete. We cannot guarantee the security of any information transmitted online via contact forms and it is done at the risk of the data-subject.
Where third parties are required to process personal information in relation to the purposes set out in this policy and for other lawful requirements, Broad Risk Assessors (Pty) Ltd ensures that they are contractually bound to apply the appropriate security practices. All personal information will be held and used for as long as permitted for legal, regulatory, fraud prevention and legitimate business purposes.
8. Rights of the data-subjects
Both the GDPR and the POPIA provide the following rights for data-subjects:
- Transparent information, communication, and modalities for the exercise of the rights of the data subject.
- Information to be provided where personal data are collected from the data subject.
- Information to be provided where personal data have not been obtained from the data subject.
- Right of access by the data subject.
- Right to rectification.
- Right to erasure (“right to be forgotten”).
- Right to restrict processing.
- Notification obligation regarding rectification or erasure of personal data or restriction of processing.
- Right to data portability.
- Right to object
- Right to opt-out of automated individual decision-making, including profiling.
See for European data-subjects see GDPR Chapter 3, articles 12 through 23 and for South African Citizens see POPIA (Act no. 4 of 2013) Chapter 2, article 5.
9. Notification of breach
If there are reasonable grounds to believe that an unauthorised third party has accessed personal information as required by legislation, the relevant Regulator shall be notified without undue delay as well as the data subject/s concerned. The notification shall include:
- A description of the nature of the personal data breach including where possible, the categories and approximate number of personal data records concerned.
- The name and contact details of the data protection officer/information officer.
- A description of the likely consequences of the personal data breach.
- A description of the measures taken or proposed to be taken by Broad Risk Assessors (Pty) Ltd to address the personal data breach, including, where appropriate, measures to mitigate possible adverse effects.
10. Changes
This policy may change from time to time to meet new regulations that might be imposed by legislation.
Revision date: 07-July-2021