Experian South Africa (“Experian”, “we”, “us” or “our”) is a leading information services company, which means we look after vast volumes of Personal Information. We are committed to using Personal Information responsibly to make a positive difference to you, and society at large. We have provided this Privacy notice to communicate all the processing activities you can expect from us, how we secure your Personal Information, your rights under applicable Data privacy legislation and how you can exercise these privacy rights. This notice is applicable in all instances where Experian determines the manner and purpose for which information is processed, i.e. when we are the Responsible Party.
This notice applies to all potential, current and former vendors, clients, consumers and suppliers (“You” or “your”) of Experian and explains how we how we collect, use and process your information as dictated by the circumstances of your relationship with us. This notice does not form part of any contract you have concluded with us, although Experian may refer to this privacy notice in your contract with Experian. We may update this notice at any time but if we do so, we will make a copy of the amended notice available to you as soon as reasonably practical. We may also notify you in other ways from time to time about the processing of your personal information.
We respect your right to privacy and are committed to being transparent about how we collect and use your Personal Information. Should you have any queries on this privacy notice or your privacy rights in general, you may contact our Africa Data Privacy Office at informationofficerafrica@experian.com. Should your query not be resolved to your satisfaction, you may contact the General Legal Counsel at africalegal@experian.com.
The responsible party is Experian South Africa.
Dual Head office:
For any enquiries on this privacy notice, please contact our privacy office via: informationofficerafrica@experian.com
Experian strives to comply with all applicable Data Privacy legislation. To ensure we respect your right to Privacy, we endeavour to adhere to the following principles when processing Personal Information. Personal Information that we hold about you must be:
"Consumer Credit Information" means information concerning—
“Information Incorporated in a business’ Credit Report” means all information which is included in a business’ credit report, including
“Information Incorporated in a consumer’s Credit Report” means all information which is included in a consumer's credit report, including
“Responsible Party”, also known as a “controller”, determines the purposes and the means for processing Personal Information i.e. determines how to collect, store, and use your Personal Information.
"Personal Information", also known as "personal data", refers to information about an identifiable person (including natural and juristic persons, such as companies and trusts). Information which identifies or relates directly to you is referred as your Personal Information. Personal Information include Consumer Credit Information.
“Processing”, Experian may collect, receive, record, organise, collate, store, update, change, retrieve, read, process, analyse, use and share your Personal Information in the ways set out in this privacy notice. When we do one or more of these actions with your Personal Information, we are “Processing" your Personal Information.
“Special Personal Information” categories of particularly sensitive Personal Information, such as information your health or sex life, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, criminal behaviour or trade union membership and biometric information, require higher levels of protection. We minimise the processing Special Personal Information to what is strictly necessary to achieve a lawful purpose. We will only process Special Personal Information when we a clear legal justification for processing as required by applicable laws and our internal policies. Experian has implemented appropriate policies and safeguards to ensure we apply the strictest privacy standards when we process Special Personal Information.
When processing Personal Information of a consumer in terms of the NCA, Experian limits the collection of Personal Information to include only what is permitted in terms of the NCA and which is necessary to our clients for credit/service application to enable them to make meaningful and accurate decisions. We also collect Personal Information of our customers and vendors to comply with contractual obligations, legal requirements or for operational business purposes. Furthermore, we ensure that our retention policies are compliant with applicable legal requirements.
Our sources of Personal Information are:
We need to collect and process certain personal information to conduct our precontract vetting process, deliver the product(s) or service(s) you have requested and to facilitate the best possible experience when you engage with us or use our products and services.
We will also collect information about you and the devices you use to access our website, or we may ask third parties to do this for us, in these cases we do so by using technologies such as cookies.
Personal Information |
Purpose for processing |
Consumer Credit Information** |
Make, or assist in making or performing duties in terms of any agreement with consumers, performing our duties and responsibilities as a registered credit bureau, as well as complying with legal obligations relating to our business. |
Information Incorporated in a consumer’s credit report** |
To form a view of consumers as individuals and to identify, develop or improve products, that may be of interest to consumers, carrying out market research, business and statistical analysis, performing administrative functions, , assist in making, credit decisions about consumers, performing duties in terms of any agreement with consumers, , operate and manage consumers’ accounts and manage any application, agreement or correspondence consumers may have with Experian, communicating (including direct marketing where we have consent) with consumers about Experian’s products and services, complying with the Experian’s regulatory and other obligations
|
Information Incorporated in a business’ Credit Report** |
Same purpose(s) as Information Incorporated in a consumer’s credit report |
Device and website usage such as IP address, how you engage with our site, your internet browser and |
Helps us understand our customers / prospective client better, manage our website functionalities and improve our marketing. |
Payment details such as credit card or debit card details, and the value of the transaction |
To facilitate payment for our product(s) and services, where the services you request carry a cost. |
Vendor / Supplier information including, name(s) and contact details, ID numbers, company registration number, and/or company information and directors’ information, Banking details and other financial information. |
Purpose include verifying information and performing necessary checks, performing obligations in agreement with the vendor or managing the business relationships between the parties, payment of invoices and complying with the Experian’s regulatory and other obligations; and |
Prospective client’s information including, Postal and/or street address, title, name(s) contact numbers and/or e-mail address, ethnic group, employment history, age, gender, marital status
|
Activities relating to the processing of a prospect’s information including verifying and updating information, pre-scoring / contractual precontract vetting and direct marketing where we have valid consent.
|
Security information which may include mother’s maiden name, username and password. |
To facilitate secure use of our platforms, to answer any queries you may have and effectively identify you when you contact us. |
** See definitions
We will only use your Personal Information for the purposes for which we collected it, or a purpose that is reasonably compatible with the original purposes for collection, as indicated above.
We will only process your Personal Information in accordance with applicable Data Privacy laws, which require that we must satisfy at least one prescribed legal basis for processing. Depending on the context of the processing activity, we rely on a number of different conditions for the activities we carry out. The legal basis we rely on include:
In rare cases, we may process your Personal Information where:
As a register Credit Bureau, Experian is required by law to collect and process your Consumer Credit Information (which qualifies as Personal Information) if you are a “consumer” under the NCA. In this instance you do not have to provide such your Consumer Credit Information, as it will be collected directly from original sources of Consumer Credit Information.
When you engage with our website, staff, products, or services:
We take the necessary technical and organisational measures to secure the integrity of information we are responsible for, using accepted technological standards to prevent unauthorised access to or disclosure of your Personal Information. We take all reasonable measures to protect your Personal Information from misuse, loss, alteration, or destruction.
We have put in place appropriate security measures to protect your Personal Information from accidental loss, unauthorised use, alteration, access, or disclosure. In addition, we limit access to your Personal Information to those employees, agents, contractors and other third parties who have a business need to access the information. They will only process your Personal Information on our instructions and are subject to a duty of confidentiality.
We review our information collection, storage and processing practices, including physical security measures from time to time, to keep up to date with good industry practice and standards.
Experian has implemented procedures to address any suspected data breaches and will notify you and any applicable regulator of a breach where Experian is legally required to do so within the period in which Experian is required to issue such a notification.
We will only retain your Personal Information for as long as necessary to achieve the purposes for which it was collected and processed. Meaning we'll keep your Personal Information for as long as we need it to provide the Experian products and services you have requested, or as long as necessary to provide marketing services for our clients, and no longer. We may also keep it to comply with our legal obligations, resolve any disputes and enforce our rights.
Experian retains your Personal Information in our credit information database in accordance with the data retention periods prescribed by the NCA. For examples, the NCA Regulations require that we that we display and use various categories of your information only for the maximum periods prescribed for the purpose of credit scoring or credit assessment. We ensure that this information is not displayed for these purposes beyond the maximum periods prescribed.
We retain certain elements of your information as long as is necessary, for the purpose of verifying the integrity of information that we may be required to process in the future or for information quality purposes (i.e. to prevent the re-loading of incorrect information). This information is securely stored and not used for any other purpose than information quality in support of our regulatory obligation to ensure the data we have is relevant and accurate and not duplicated.
Our reasons for retention may vary from one record or piece of information to the next and depends on the purposes for the storage and related operational business requirements and / or legal obligations, therefore the amount of time we keep your Personal Information for may vary.
In all cases, our need to use your personal information will be reassessed on a regular basis, and information which is no longer required for any purposes will be disposed of.
As a general rule, we will only share your Personal Information with those that need access to the information for us to achieve the purpose for which we have collected it, or to comply with an obligation imposed by law. Internally, we will only share your Personal Information on a “need-to-know” basis, i.e. with Employees who need access to the information to perform a task on our behalf.
Where consent is required by the NCA, Experian will only release Consumer Credit Information upon receipt of the consumer’s consent. Experian is obliged to comply with Section 68 of the NCA pursuant to which we use a consumer or a prospective consumer’s information only for the purpose permitted in terms of the NCA or other applicable legislation. Experian will report or release that information only to the consumer, prospective consumer or to another person:
Internally, we will only share your Personal Information on a “need-to-know” basis, i.e. with parties who need access to the information to perform a task on our behalf, which includes:
We store our personal information in South Africa.
We may also or alternatively store your Personal Information on and transfer your personal information to a central database located in outside of the borders of South Africa, for the performance centralized functions for our Group of companies.
If the location of the central database is located in a country that does not have substantially similar laws which provide the same level of protection to your Personal Information, we will take the necessary steps to ensure that your personal information is adequately protected in that jurisdiction.
We may engage service providers to support our business and they may be based or use data centres outside of South Africa. Whenever your Personal Information is transferred cross border, it will receive a similar level of protection as described in this notice.
This section is only to be used to exercise your privacy rights as provided for in Privacy legislation. All credit bureau information is governed by the NCA, and any requests which relate to bureau information should be dealt with using the NCA consumer dispute process. For more information on our dispute process, click Disputes Process.
You may have rights under applicable Data Privacy laws in relation to your Personal Information, which you may exercise under certain circumstance. To exercise these rights, kindly follow the links relating to the right which will provide you with access to the prescribed form as provided for under each right below, fill it in its entirety and send to informationofficerafrica@experian.com. For hard copy exercise of your rights, you may also request the prescribed forms from the aforementioned email address or Experian call centre (details found under the contact us section) or reception.
You may have the right to:
If you want to exercise any of these rights, please contact the Experian Information Officer.
You will not have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded, excessive or a request to access comprehensive report on all information we may hold on you.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it.
Should your request or dispute relate specifically to credit bureau information, please refer to the Bureau dispute process, which you can access by clicking here.
We encourage you to assist us in maintaining the accuracy of Personal Information by notifying us of any changes or by meeting your legal obligations regarding disputes logged.
Where Personal Information is submitted to Experian in terms of the NCA, we cannot alter the information reported by providers of Personal Information unless the information is confirmed to be wrong or inaccurate by the provider of the Personal Information (this is because the NCA has a clear procedure for managing disputes and the provider of the Personal Information is the Responsible Party, which includes responsible of maintaining the accuracy of the Personal Information).
Where Experian is the Responsible Party, and you do not agree with the accuracy of your Personal Information which Experian has on file, we have procedures to ensure that such information is verified, and, where appropriate, amended or corrected. Please refer to our privacy rights section above.
If you have questions about our privacy notice or wish to contact us, please contact our Information Officer at informationofficerafrica@experian.com. Our dedicated Data Privacy Office is available to attend to any query you may have.
Should your query not be resolved to your satisfaction, you may contact the General Legal Counsel at africalegal@experian.com
Where the above channels have not addressed your query or complaint appropriately, you have the right to make a complaint at any time to the government body / regulator responsible for enforcement of Privacy laws (e.g. the information regulator in South Africa). Details of the relevant regulator may be access online or requested via informationofficerafrica@experian.com.