- Akiva Medical NPC (Registration number: 2021/946061/08) (“Akiva”) is a non-profit organization assisting members of the Jewish community with medical aid coverage. Akiva is not a medical aid, but it refers clients to Cratos Life and Discovery Medical Aid. Akiva provides financial assistance, in conjunction with co-sponsors, to Jewish applicants requiring medical aid.
- As part of managing the business and creating value for its various stakeholders, Akiva is required to process personal information. Accordingly, Akiva is obligated to comply with The Protection of Personal Information Act 4 of 2013 (“POPIA/The Act”) insofar as it processes personal information, including special personal information, during its ordinary course of business. Under POPIA, Akiva is defined as the Responsible Party for all Personal Information it processes.
- Akiva is also obligated to comply with the National Health Act No 61 of 2003 (NHA); the Medical Schemes Act 131 of 1998 (MSA); and the Promotion of Access to Information Act No 2 of 2000 (PAIA).
- Akiva guarantees its commitment to protecting the data subjects privacy, ensuring that their personal information is processed appropriately, securely and in accordance with all applicable legislation, both within South Africa and outside of it.
- This Policy sets out the manner in which Akiva processes personal information and stipulates the purpose for which said information is used, specifically addressing:
- Types of Personal Information Akiva collects on a Data Subject and the basis thereof
- The use and protection of the Personal Information of a Data Subject
- Retention periods of the Personal Information of a Data Subject
- The rights of a Data Subject regarding their Personal Information
- The process the Data Subject should follow if he does not want to provide Akiva with his personal information.
This policy applies to all the Personal Information Akiva processes in the ordinary course of business but does not deal in detail with the Personal Information of employees, consultants and contractors which is the subject of a different policy (The Employee Data Privacy Policy).
- Data Protection Legislation applies to information relating to identifiable individuals and juristic persons (collectively referred to as Data Subjects), in terms of the Protection of Personal Information Act 4 of 2013 (POPIA) as well as the General Data Protection Regulation (EU) 2016/679 (GDPR).
- The purpose of POPIA is to give effect to the constitutional right to privacy, by safeguarding personal information when processed by a responsible party, in order to:
- Balance the right to privacy against other rights, particularly the right of access to information
- Regulate the way in which Personal Information may be processed, by establishing conditions which prescribe the minimum requirements for the lawful processing of personal information.
- POPIA provides Data Subjects with measurable rights and remedies to protect their personal information from processing which is not in accordance with the Act.
Akiva is committed to following best practice; to aligning with the principles of good governance and to adhering to legislative compliance requirements in all aspects of our business.
Akiva guarantees its commitment to protecting the data subject’s privacy and ensuring their Personal information and Special Personal Information is processed in accordance with all applicable legislation relevant to our industry.
As the Responsible Party, Akiva processes Personal Information in accordance with the requirements of the Protection of Personal Information Act, 2013 (POPIA) as well as the General Data Protection Regulation (EU) 2016/679 (GDPR).
This Policy must be read in conjunction with POPIA and its Regulations, where applicable.
In this policy:
- Clause headings are for convenience and reference only and shall not be used in the interpretation thereof
- Any gender includes the other genders and a natural person includes a juristic person and vice versa
- All the annexures (if any) hereto are incorporated herein and shall have the same force and effect as if they were set out in the body of this policy
- The following words and/or expressions shall, unless the context indicates otherwise, bear the meaning assigned to them below and in POPIA
- Data Subject means the person to whom personal information relates
- Child means a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take any action or decision in respect of any matter concerning himself. A child is afforded special protection under POPIA in relation to the lawful processing of his information
- Competent Person is any person who is legally competent to consent to any action or decision in respect of a Child, i.e. a Child's parent or legal guardian;
- POPIA refers to the Protection of Personal Information Act 4 of 2013;
- GDPR refers to the General Data Protection Regulation (EU) 2016/679
- Responsible Party means a public or private body or any other person which, alone or in conjunction with others determines the purpose of and means for processing personal information. Called Controllers in other jurisdictions (GDPR)
- Operator means a person who is contracted to process personal information on behalf of the responsible party but is not controlled by the Responsible Party. Called Processors in other jurisdictions (GDPR)
- Processing means any operation or activity, whether by automatic means or not, concerning personal information, including:
- The collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use of data
- Dissemination by means of transmission, distribution or making available in any other form
- Merging, linking, restriction, degradation, erasure or destruction of information.
- Record means any recorded information
- Regardless of form or medium, including any of the following:
- Writing of any material
- Information produced, recorded or stored by means of any tape-recorder, computer equipment, whether hardware or software or both, or other device, and any material subsequently derived from information so produced, recorded or stored
- Label, marking or other writing that identifies or describes anything of which it forms part, or to which it is attached by any means
- Book, map, plan, graph or drawing
- Photograph, film, negative, tape or other device in which one or more visual images are embodied to be capable, with or without the aid of some other equipment, of being reproduced, in the possession or under the control of a responsible party
- Whether or not it was created by a responsible party and
- Regardless of when it came into existence.
- Personal Information means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to
- Information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, wellbeing, disability, religion, conscience, belief, culture, language and birth of the person.
- Information relating to the education or the medical, financial, criminal or employment history of the person
- Any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other assignment to the person
- The biometric information of the person
- The personal opinions, views or preferences of the person
- Correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence
- The views or opinions of another individual about the person
- The name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person
- Special Personal Information refers to the personal information concerning the following: the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject.
- De-identify means to delete any information which identifies the data subject; can be used or manipulated by a reasonably foreseeable method to identify the data subject; or can be linked by a reasonably foreseeable method to other information that identifies the data subject.
- Consent is defined as the voluntary, specific and informed expression of will in terms of which permission is granted for the Processing of Personal Information;
- Medical Service Providers (MSP’s) means all Medical Service providers (Doctors, Nurses, Physiotherapists, Radiologists, Surgeons etc…) as well as Private Hospitals and Clinics.
All Data Subjects have the following rights, which Akiva is committed to uphold. The practical implementation of this policy will be in alignment with these rights as well as the principles of lawful processing as set out in POPIA (Section 5)
- Objection to the use of Personal Information on reasonable grounds relating to his situation
- Notification if:
- Information is being collected
- Information is being used for something other than the original purpose for which consent was given
- Information has been accessed or acquired by an unauthorised person
- Notification if:
- Establishing whether the responsible party holds Personal Information and to request, in a format legible and readable, access to said information
- Requesting that Personal Information be corrected, destructed or deleted
- Refusing processing for direct marketing by unsolicited electronic communications
- Lodging a complaint with the Information Regulator
- Instituting civil proceedings against a party who has acted unlawfully in relation to the Data Subjects Personal Information (Sec 99)
Akiva undertakes to adhere to the 8 Conditions for Lawful Procession of Personal Information as set out in POPIA (Sections 8-35):
- Accountability
Akiva accepts full responsibility and accountability to responsibly manage and protect all the Personal Information we process
- Processing Limitation
- Akiva will, wherever reasonably possible, collect information directly from the Data Subject, unless collection from another party is specifically permitted; the data subject has consented and the collection of information from a third party will not prejudice the data subject:
- Processing Limitation
- In the case of Patient data, regarding a child or mentally incompetent adult, where a competent adult provides information on their behalf
- In the case of medical history, information will be collected from the Medical Service Provider/s
- In the case of financial information relating to their eligibility for Akiva assistance, information will be collected from the Jewish Helping Hand and Burial Society (“the Chev”)
- In all cases Data subjects express consent will be obtained. In the event that they are unable to consent due to their status as a minor or incompetent adult, consent will be sought from their next of kin/competent person.
- All Personal Information is processed to:
- Protect the legitimate interest of data subject: in this case to protect their right to access quality medical care
- All Personal Information is processed to:
- We respect the right of the Data Subject to, at any time, object or withdraw consent to any further processing and we have procedures in place for these instances
- Purpose Specification
- Akiva will collect and process the absolute minimum data reasonably required in order to approve the Data Subject for financial assistance and to facilitate the successful handover to the Medical Insurance Broker (Cratos Life):
- This data will be that which is stipulated by Cratos Life and Discovery Health in their application and assessment documentation.
- This data does fall into the category of Special Personal Information, as it includes details of the Data Subjects medical treatment and medical history. This information is collected only insofar as it is required by Akiva for the verification of eligibility for financial assistance, as well as for the submission of their application to Cratos Life and Discovery.
- Akiva will only process Personal Information which is essential to enable us to approve them for eligibility for the funding of their medical aid premiums, and to ensure their application to Discovery is successful.
- The Data Subject will be made aware of the purpose of the collection through their consent form signed before the assessment commences.
- We shall only retain and store Personal Information for the period for which the data is required to serve its primary purpose or a legitimate interest or for the period required to comply with an applicable legal requirement, whichever is longer.
- All records will be de-identified and/or destroyed at the time dictated by POPIA and other relevant governing legislation (National Health Act 61 of 2003; the Medical Schemes Act 131 of 1998; the Promotion of Access to Information Act 2 of 2000; and the Children’s Act 38 of 2005). Please see Record Retention Policy for further information.
- Personal Information will be destroyed, deleted or de-identified as soon as is reasonably practical, preventing its reconstruction in an intelligible form.
- Further Processing Limitation
- Akiva will ensure that any further processing will be in accordance or compatible with the purpose for which it was originally collected, and will not take place without the express consent of the Data Subject.
- The Information Officer shall ensure that the information collected will not be used for any other purpose before obtaining the data subjects approval, unless the new purpose is required by law
- Akiva will not share any Personal Information with anyone or for any reason if not required for the finalization of the claim, or as required in terms of legislation or regulations
- Information Quality
- Reasonably practicable steps will be taken to ensure that the Personal Information is complete, accurate, not misleading and that the Personal Information is updated where necessary.
- Information Quality
- Data subjects will provide updated financial and medical information to Akiva on an annual basis upon the anniversary of their initiation of service.
- Akiva will regularly review the purpose for which personal information is collected or further processed.
- Openness
Akiva will take reasonably practicable steps to be open and transparent on the nature, extent and reasons for processing Personal Information
To that end, we will ensure, through the use of a consent form, that the Data Subject is aware of:
- The information being collected
- Our name and address
- The purpose for which the information is being collected
- Whether or not the supply of the information is voluntary or mandatory
- The consequences of failure to provide the information
- The right of access to and the right to rectify the information collected
- The right to object to the processing of the information
The Information Officer shall also ensure that a person collecting Personal Information will be able to explain to the individual why this is being done: this will involve adequate training of all staff and partners (MSP’s and the Chev).
- Security Safeguards
- Akiva will adequately safeguard and protect all Personal Information in our possession by adopting the appropriate, reasonable technical organisational measures expected for our industry and within South Africa
- We will, on an ongoing basis, continue to review our security controls and related processes to ensure that all Personal Information we hold remains secure
- Generally accepted standards of technology and operational security have been implemented to protect information from loss, misuse, alteration, or destruction.
The Physical Security Measures include, but are not limited to:
- Physical barriers to entry to the premises, according to the generally accepted South African norm: locked doors, security gates, alarm system, electric fencing
- Physical locks on all internal doors
- Locks on all filing cabinets and desk drawers
The IT security measures include, but are not limited to:
- Adequate password and passphrase protection on every device, system and sensitive document, governed by the Password Policy which all staff will be trained on
- High quality antivirus software on all devices
- All data backed up to cloud-based servers approved by the American Data Protection Legislation and the General Data Protection Regulation of the European Union
- A comprehensive Data Recovery Plan
- Staff training to avoid phishing scams, and email warnings on all outside emails
- A protocol to always maintain updated software
- A comprehensive Information Security and IT Change Management Policy
- All our employees, advisors and volunteers are trained on information security and are required to keep Personal Information confidential and only authorised persons have access to such information.
- Any Operator processing information on behalf of Akiva will be required to sign a Non-Disclosure agreement and an Operator Agreement in order to ensure:
- Information is treated as confidential and not disclosed required by POPIA
- They apply at least the same security measures as Akiva
- The Information Officer shall ensure that all employees, consultants, advisors and volunteers have signed Non-Disclosure Agreements and have been adequately trained on the contents of this Policy, and other relevant Policies and Procedure Manuals
- The Information Officer shall ensure that care is taken when personal information is disposed of or destroyed to prevent unauthorized parties from gaining access to it
- Akiva will notify data subject and the Regulator of any breach of data.
- Data Subject Participation
- Akiva commits to freely confirm what Personal Information we hold on Data Subjects, to update and rectify the Personal Information upon request and to keep it for no longer than required.
- We respect that the Data Subject may request us to:
- Correct or delete information, which is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully
- Delete or destroy information that we are no longer authorised to retain
- We will not use Personal Information for any other purpose than that set out in this Policy, and we will take the necessary steps to secure the integrity and confidentiality of Personal Information in our possession and under our control by taking appropriate and reasonable measures to prevent loss of, damage to or unauthorised destruction of Personal Information and to prevent the unlawful access to, or processing of Personal Information.
- Information is processed in order to:
- Partially fund the medical aid premiums of eligible members of the Jewish community
- Facilitate the transaction between the Data Subject/Community Member and Cratos Life and Discovery Health for them to secure Medical Aid cover.
- Information is processed in order to:
- The Patient Personal Information:
- General Personal Information
- Name
- ID Number
- Date of Birth and Age
- Gender
- Contact Details (Email; Telephone Number)
- Residential Address
- ID Document
- Dependent Names and ID Numbers
- Rabbi Name and Contact Details
- Financial Information
- Bank Statements
- Employment Status
- Personal Income
- Family Income
- Previous Medical Aid Memberships and reasons for leaving
- Details of Financial Assistance received from other organizations (the Chevra Kadisha or Yad Aharon)
- Name and Contact Details of Co-Sponsor
- Financial Information
- Full Medical File
- Medical Conditions/Comorbidities
- Diagnosis Date(s) and Doctor(s)
- Medications used, past and present
- Allergies
- Hospitalization history
- GP Name and contact details
- Any Specialists Names and contact details
- The Medical Service Provider Personal:
- Name
- Contact Details
- Physical Addresses
- Practice Numbers
- Co-Sponsor Details
- Name
- Contact Information
- Co-Sponsor Details
- All the above Personal Information is processed in order to:
- Approve the applicant for the subsidy of their Medical Aid Premium
- To complete the required documentation for submission to Cratos Life and Discovery Health
- To comply with all legislative or regulatory requirements related to services provided by us
- To satisfy any requirement by a professional body or network to which we are a member
- To fulfil our moral obligations to funders and donors, to ensure the eligibility of applicants and prevent fraud.
- Information is stored on DropBox
- Information is accessible only to Akiva staff and Operators who have a verifiable need to access the information in order to meet an objective/requirement of either the organization or the data subject.
- Any physical sources of data are scanned in and stored electronically, and the original hard copy is, wherever permitted by legislation, destroyed.
- Where a hard copy needs to be kept, it is kept in a locked, fireproof filing cabinet to which only limited staff have access.
- Data is stored on secure servers owned and managed by compliant operators, with whom Akiva has signed NDA’s, SLA’s and privacy agreements.
- All electronic files or data are backed up by the IT Service Provider who is also responsible for system security which protects third party access and physical threats. Please see Information Security Policy for further details.
- Information is only processed in so far as it is necessary to fulfil the requirements of the data subject or to meet a need of the Responsible Party
- A Security Incident Management Register will be kept to log any security incidents
Our employees will have access to Personal Information to administer and manage our services and internal business processes.
We do not share Personal Information with third parties unless we have a lawful basis for doing so:
- Akiva shares Personal Information it has collected from the Medical Service Providers with Cratos Life/Discovery Health in the furtherance of its legitimate interest to assist members in securing medical aid cover.
- Akiva will never disclose any of the Personal Information it collects to any other third parties, unless:
- The sharing of the information is essential in order to fulfil a need of the Data Subject, but will only be shared in this instance with express consent of the data subject.
- We have a duty or a right to disclose in terms of legislation, regulations or industry codes
- We believe it is necessary to protect our rights
- It is explicitly requested by the Data Subject;
- Akiva will never disclose any of the Personal Information it collects to any other third parties, unless:
- At this stage we do not have the need to share Personal Information outside of South Africa. If ever a legitimate need for cross-border data transfer to arise, it will only be done in very limited circumstances and in strict adherence to all requirements of POPIA and other relevant legislation (Section 72).
Akiva has appointed an Information Officer and will ensure the Information Officer is aware of the IO Core Focus/Duties under POPIA, which include, as per POPIA (Section 55)
- Encouraging compliance with the information protection conditions in terms of Section 55 of POPIA
- Developing, publishing and maintaining this Privacy Policy which addresses all relevant provisions of POPIA
- Reviewing POPIA and periodic updates as published
- Ensuring that POPIA induction training takes place for all staff
- Ensuring that periodic communication awareness on POPIA responsibilities takes place
- Ensuring that Privacy Notices for internal and external purposes are developed and published
- Handling data subject access requests
- Approving contracts with Data Operators
- Ensuring that appropriate policies and controls are in place for ensuring the quality of Personal Information
- Ensuring that appropriate Security Safeguards are in place
- Considering requests made pursuant to POPIA
- Working with the Regulator in relation to investigations conducted pursuant to Chapter 6 against Akiva
- Identifying and governing all privacy related risks
- Mapping all activities performed concerning the collection and storage of personal information i.e., before and post enactment of POPIA
- Mapping all privacy laws and industry codes relevant to our activities
- If applicable: knowing; understanding and ensuring corporate compliance with all relevant laws of foreign jurisdictions in which we conduct business
- Coordinating the development, implementation, and maintenance of corporate customer (external) and employee (internal) privacy policies
- Ensuring compliance with corporate privacy policies and procedures
- Liaising with Human Resources and Legal Departments to ensure standards of disciplinary action and sanctions for non-compliance.
- Liaising with Public Relations and Marketing Departments to create public information communications and procedures on privacy efforts, related issues and breaches
- Creating standards or scripts for responding to customer or public enquiries
- Creating and implementing procedures and standards to facilitate customer verification of captured and stored personal information files.
- Monitoring and controlling the privacy requirements and responsibilities of information processing service providers or operators in terms of sections 20 and 21 of POPIA.
- Managing breach and incident investigation processes
- Creating and implementing our privacy breach management plan, privacy alerts, and other privacy related operational issues.
- Creating standards and procedures to manage any compromise in the security of the stored personal information correctly and appropriately.
- Investigating, analysing and documenting all privacy related incidents and complaints.
- Applying investigation findings to update standards, processes and systems as an on-going operational improvement routine.
The Information Officer is Chana Rosen whose details are available below and who is responsible for compliance with the conditions of the lawful processing of personal information and other provisions of POPIA
Additional Policies, relevant to Privacy and POPIA, and expanding on the topics contained herein:
- PAIA Policy
- Privacy Statement
- Information Security Policy
- IT Change Management Policy
- Financial Data Policy
- Employee Data Privacy Policy
- Employee Exit Policy
- Record Retention Policy
- Incident Response Policy
- Complaints Policy
- Clean Desk Policy
- Password Policy
- This Policy has been implemented throughout Akiva and comprehensive team training on this policy and POPIA has been completed.
- The documentation for staff is contained in this policy document and other materials made available by the Information Officer. The Information Officer will ensure that all staff with access to any kind of personal information will have their responsibilities outlined during their induction procedures.
- Ongoing programmes will provide opportunities for staff to explore POPIA issues through training, team meetings, and supervisions.
- Each new employee will be required to sign an Employment Contract containing relevant clauses for the use and storage of employee information, or any other action so required, in terms of POPIA
- Every employee currently employed by Akiva has been required to sign an addendum to their Employment Contracts containing relevant consent clauses for the use and storage of employee information, or any other action so required, in terms of POPIA.
- The Information Officer will ensure that all staff sign acceptance of this policy once they have had a chance to understand it, as well as their responsibilities in terms of the policy and POPIA.
- The Information Officer is responsible for an annual review to be completed prior to the policy anniversary date.
- The Information Officer will ensure relevant stakeholders are consulted as part of the annual review to be completed prior to the policy anniversary date.
- This policy shall also be reviewed whenever:
- There have been changes in International, National or Internal references that may impact on this policy.
- There are improvements or changes within the Akiva systems or processes which should be reflected in this policy
Information Officer Details Name: Chana Rosen
Email Address: admin@akivamedical.co.za
If you have an inquiry or complaint regarding this Policy or the collection or use of your Personal Information, including any rights of access, ability to limit the use or disclosure of Personal Information, or to correct or delete inaccurate Personal Information, please email popia@akivamedical.co.za.
If the Data Subject is not satisfied with the response, Akiva acknowledges the Data Subjects right under POPIA to lodge a complaint directly with the Information Regulator, and will direct the Data Subject to this in the Complaints Policy
The Information Regulator (South Africa) is an independent body established in terms of Section 39 of the POPIA of 2013. It is, among other things, empowered to monitor and enforce compliance by public and private bodies, and is subject only to the constitution and accountable to the National Assembly.