Municipal contact
Privacy and Personal Information
POPIA
Protection of Personal Information Act
This notice explains how Steve Tshwete Local Municipality should handle personal information when residents, businesses, suppliers, employees, job applicants, complainants, and service users interact with the municipality.
Process
How the request should move
- Submit privacy query or correction request
- Municipality verifies identity and authority
- Relevant record owner assesses the request
- Correction, access, refusal, or further steps are communicated
- Unresolved complaints may be escalated to the Information Regulator
Guidance
Information the municipality may process
Identity and contact information, including names, identity numbers, addresses, telephone numbers, email addresses, and account references.
Municipal account, billing, payment, valuation, service application, permit, complaint, and request-tracking information.
Supplier, tender, quotation, procurement, employment, councillor, public participation, and governance-related information.
Technical website information such as form submissions, device information, basic analytics, and security logs where used for lawful website operation and protection.
Guidance
Why information is processed
To deliver municipal services, manage accounts, process payments, respond to requests, investigate service issues, and communicate with residents.
To administer procurement, recruitment, governance, public participation, council processes, and statutory reporting.
To comply with laws that apply to municipalities, including records management, financial management, access to information, and public accountability obligations.
To protect municipal systems, prevent fraud, manage security incidents, and preserve evidence where legally required.
Guidance
How personal information must be protected
Access to personal information should be limited to authorised officials, service providers, or lawful recipients who need it for municipal duties.
Electronic and paper records should be protected by appropriate access controls, security measures, retention rules, and disposal practices.
Service providers who process personal information for the municipality should be required to protect it and use it only for authorised purposes.
Security compromises involving personal information should be assessed and handled in line with POPIA and Information Regulator requirements.
Guidance
Your privacy rights
You may ask whether the municipality holds your personal information and request access to that information where the law allows.
You may ask for correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.
You may object to processing where POPIA gives you that right, and you may lodge a complaint with the Information Regulator.
Some records may need to be retained where legislation requires the municipality to keep them.
Official resources
Forms and regulator guidance
These links open official external resources for prescribed forms, guides, and regulator procedures.
