Privacy Policy
Van Dyk Theron Incorporated | Registration No. 2012/046216/21
Trading as VDT
Effective Date: 1 April 2026 | Last Reviewed: 1 April 2026 | Version: 1.0
Jurisdictions: POPIA (South Africa) · GDPR (EU/EEA) · CCPA/CPRA (California) · FTC Act (United States)
1. Introduction
Van Dyk Theron Incorporated (2012/046216/21), trading as VDT ("we", "us", or "our"), is committed to protecting your personal information and respecting your right to privacy.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you access our website www.vdtreg.co.za (the "Website"), use our services, or otherwise interact with us.
This Policy is designed to comply with, and should be interpreted in accordance with:
- The Protection of Personal Information Act 4 of 2013 ("POPIA") of the Republic of South Africa, as amended by the April 2025 Regulation Amendments;
- The General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable EU/EEA member-state implementing legislation;
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"); and
- The Federal Trade Commission Act, Section 5, and other applicable US federal and state privacy and consumer-protection statutes.
Where a conflict exists between the requirements of different jurisdictions, we apply the standard that affords the highest level of protection to the individual.
2. Definitions
| Term Used | POPIA Equivalent | GDPR Equivalent | US / CCPA Equivalent |
|---|---|---|---|
| Personal Information | Personal Information (s 1) | Personal Data (Art 4(1)) | Personal Information (CCPA § 1798.140(v)) |
| Data Subject / You | Data Subject (s 1) | Data Subject (Art 4(1)) | Consumer (CCPA § 1798.140(i)) |
| Controller / We | Responsible Party (s 1) | Data Controller (Art 4(7)) | Business (CCPA § 1798.140(d)) |
| Processor | Operator (s 1) | Data Processor (Art 4(8)) | Service Provider / Contractor |
| Processing | Processing (s 1) | Processing (Art 4(2)) | Collecting, using, retaining, sharing, selling |
| Consent | Consent (s 1, s 11) | Consent (Art 4(11)) | Consent (CCPA/CPRA § 1798.140(h)) |
| Special / Sensitive Data | Special Personal Info (s 26) | Special Categories (Art 9) | Sensitive Personal Info (CPRA § 1798.140(ae)) |
| Privacy Officer | Information Officer (s 55) | Data Protection Officer (Art 37) | N/A (designated privacy contact) |
3. Scope and Application
This Policy applies to all personal information we process about:
- Visitors to our Website;
- Clients, prospective clients, and their representatives;
- Suppliers, service providers, and their personnel;
- Individuals who contact us via email, telephone, social media, or other channels; and
- Any other natural or juristic person whose personal information we process.
This Policy does not apply to personal information processed by third-party websites linked from our Website.
Territorial Reach
- POPIA applies where the responsible party is domiciled in South Africa or uses automated or non-automated means in South Africa to process personal information.
- GDPR applies where we offer goods or services to individuals in the EU/EEA or monitor their behaviour within the EU/EEA.
- CCPA/CPRA applies where our processing activities meet the statutory thresholds for California consumers.
4. Information We Collect
4.1 Information You Provide Directly
- Identity Information: Full name, title, date of birth, ID or passport number;
- Contact Information: Email address, telephone number, physical and postal address;
- Professional Information: Employer, job title, professional registrations;
- Financial Information: Banking details, billing address (where applicable for invoicing);
- Communication Records: Content of emails, enquiry forms, and other correspondence; and
- Any other information you voluntarily provide to us.
4.2 Information Collected Automatically
- Device and Browser Information: IP address, browser type and version, operating system;
- Usage Data: Pages visited, time spent on each page, referring URLs, click patterns;
- Location Data: Approximate geographic location derived from your IP address; and
- Cookies and Similar Technologies: See Section 7 below.
4.3 Information from Third Parties
- Credit bureaus, public registers, or professional bodies (for client onboarding and due diligence);
- Analytics providers (e.g. Google Analytics); and
- Social media platforms (if you interact with our social media accounts).
4.4 Special / Sensitive Personal Information
We do not generally collect special personal information (such as race, health, biometric data, or criminal records) unless strictly necessary for the legal services we provide, in which case processing is justified under POPIA s 27, GDPR Article 9(2), or applicable US law, and appropriate safeguards are in place.
5. Legal Basis for Processing
| Purpose | POPIA Basis | GDPR Basis | US Basis |
|---|---|---|---|
| Providing legal services | Contract (s 11(1)(e)) | Contract (Art 6(1)(b)) | Business relationship |
| Responding to enquiries | Legitimate interest (s 11(1)(f)) | Legitimate interest (Art 6(1)(f)) | Business relationship |
| Marketing communications | Consent (s 11(1)(a), s 69) | Consent (Art 6(1)(a)) | CAN-SPAM / CCPA opt-out |
| Legal compliance | Legal obligation (s 11(1)(c)) | Legal obligation (Art 6(1)(c)) | Applicable US statutes |
| Website analytics | Legitimate interest (s 11(1)(f)) | Legitimate interest (Art 6(1)(f)) | Disclosed in this Policy |
6. Purposes of Processing
- To provide, administer, and improve our legal services;
- To respond to enquiries and communicate with you;
- To comply with legal, regulatory, and professional obligations;
- To manage our client relationships and business operations;
- To send marketing communications (where you have opted in or we are permitted by law);
- To conduct research, analysis, and statistical reporting;
- To protect our rights, property, and safety, and those of our clients and the public; and
- To administer our Website and ensure its security and functionality.
7. Cookies and Tracking Technologies
7.1 Types of Cookies
| Category | Description | Consent Required |
|---|---|---|
| Strictly Necessary | Essential for the Website to function (e.g. session management, security) | No |
| Performance / Analytics | Measure and analyse Website usage (e.g. Google Analytics) | Yes |
| Functionality | Remembering preferences (e.g. language, display mode) | Yes |
| Marketing / Advertising | Targeted advertising and cross-site tracking (if applicable) | Yes |
7.2 Managing Cookies
When you first visit our Website, a cookie consent banner will appear, allowing you to accept or reject non-essential cookies on a granular, category-by-category basis. Pre-ticked boxes are not used. You may adjust your preferences at any time via the cookie settings link on our Website or through your browser settings.
7.3 Do Not Track (DNT)
We honour "Do Not Track" signals sent by your browser. When a DNT signal is detected, we disable non-essential analytics and advertising tracking for your session.
8. Sharing and Disclosure of Personal Information
We do not sell your personal information. We may share personal information with the following categories of recipients, strictly on a need-to-know basis:
- Service Providers / Operators: IT hosting, cloud storage, email service providers, payment processors, and professional advisers who process personal information on our behalf under written agreements;
- Professional Advisers: Auditors, legal counsel, accountants, and insurers as reasonably necessary;
- Regulatory and Government Bodies: The Information Regulator, SARS, EU supervisory authorities, US regulators, courts, and law enforcement where required by law;
- Business Transfers: In connection with a merger, acquisition, or sale of assets; and
- With Your Consent: To any other third party where you have given explicit consent.
9. Cross-Border Transfers
9.1 Under POPIA (South Africa)
Cross-border transfers are permitted where the recipient country provides an adequate level of protection, the data subject consents, the transfer is necessary for a contract, or another exception under section 72 of POPIA applies.
9.2 Under GDPR (EU/EEA)
Transfers outside the EEA are made only where an adequacy decision exists (Article 45), or appropriate safeguards are in place, including EU Standard Contractual Clauses (Article 46(2)(c)), Binding Corporate Rules (Article 47), or an applicable derogation under Article 49.
9.3 Under US Law
We ensure that transfers comply with applicable US privacy requirements. Where the EU-US Data Privacy Framework applies, we abide by its principles.
10. Data Retention
| Category | Retention Period | Governing Requirement |
|---|---|---|
| Client matter records | 7 years from completion | Prescription Act 68 of 1969 |
| FICA / AML records | 7 years after end of relationship | FICA ss 22–23 |
| Tax and financial records | 7 years | Income Tax Act; Tax Administration Act |
| Website analytics data | 7 years | Internal policy; GDPR minimisation |
| Marketing consent records | Duration of consent + 7 years | POPIA; GDPR; CAN-SPAM |
| Enquiry and correspondence records | 7 years from last interaction | Internal policy |
11. Security Measures
We take appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, destruction, use, modification, or disclosure. These include:
- Encryption of personal information in transit (TLS/SSL) and at rest;
- Access controls and role-based permissions;
- Multi-factor authentication;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Staff training on data protection and incident response;
- Physical security measures; and
- Incident response and breach notification procedures compliant with POPIA (s 22), GDPR (Articles 33–34), and applicable US breach notification laws.
12. Your Rights
| Right | POPIA | GDPR | CCPA/CPRA |
|---|---|---|---|
| Access / Right to Know | s 23 | Art 15 | § 1798.100, .110 |
| Correction / Rectification | s 24 | Art 16 | § 1798.106 |
| Deletion / Erasure | s 24 | Art 17 | § 1798.105 |
| Restriction of Processing | — | Art 18 | § 1798.121 |
| Data Portability | — | Art 20 | § 1798.130(a)(2) |
| Objection | s 11(3)(a), s 69 | Art 21 | — |
| Opt Out of Sale / Sharing | — | — | § 1798.120, .121 |
| Withdraw Consent | s 11(2)(b) | Art 7(3) | Applicable provisions |
| Non-Discrimination | s 73 | Art 77 | § 1798.125 |
| Lodge a Complaint | s 74 | Art 77 | CPPA / state AG |
12.1 How to Exercise Your Rights
Submit a verifiable request using the contact details in Section 21. We will respond within:
- POPIA: 30 days;
- GDPR: One month, extendable by two further months;
- CCPA/CPRA: 45 days, extendable by an additional 45 days with notice.
13. Children's Privacy
Our Website is not directed at children. We do not knowingly collect personal information from children under the age of 18 (POPIA), 16 (GDPR), or 16/13 (CCPA/CPRA). If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.
14. AI and Automated Decision-Making
Our Website uses artificial intelligence (AI) to generate plain-language summaries of court judgments. This AI processing is applied only to publicly available legal texts and does not involve the processing of your personal information. No automated decisions with legal or similarly significant effects are made about you based on AI processing.
15. Direct Marketing
We may send you direct marketing communications where you have provided consent or where we are permitted to do so by law. You may opt out of direct marketing at any time by contacting us or using the unsubscribe link in any marketing communication.
16. California-Specific Disclosures (CCPA/CPRA)
16.1 Categories Collected and Purpose
We collect the categories of personal information described in Section 4 for the business purposes described in Section 6.
16.2 Sale or Sharing
We do not sell or share personal information as defined by the CCPA/CPRA.
16.3 Sensitive Personal Information
We do not use or disclose sensitive personal information for purposes beyond those permitted under CPRA § 1798.121.
17. POPIA-Specific Provisions (South Africa)
17.1 Information Officer
Name: CJ van Dyk
Designation: Information Officer
Email: tiaan@vdtreg.co.za
Telephone: 082 825 8876
Physical Address: 406 Kings Highway, Lynnwood, 0081
17.2 Conditions for Lawful Processing
We process personal information in compliance with the eight conditions for lawful processing set out in POPIA Chapter 3:
- Accountability (s 8)
- Processing Limitation (s 9–12)
- Purpose Specification (s 13–14)
- Further Processing Limitation (s 15)
- Information Quality (s 16)
- Openness (s 17–18)
- Security Safeguards (s 19–22)
- Data Subject Participation (s 23–25)
17.3 PAIA Manual
Our manual compiled in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA) is available on written request.
17.4 Security Compromises
In the event of a security compromise involving personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with section 22 of POPIA.
18. GDPR-Specific Provisions (EU/EEA)
18.1 Data Controller
Controller: Van Dyk Theron Incorporated, 2012/046216/21
Registered Address: 406 Kings Highway, Lynnwood, 0081
Contact: tiaan@vdtreg.co.za
18.2 Data Protection Officer (DPO)
Not statutorily required — contact our Information Officer (tiaan@vdtreg.co.za).
18.5 Right to Lodge a Complaint
You have the right to lodge a complaint with your local EU/EEA supervisory authority. A list is available at edpb.europa.eu.
19. Complaints
If you are dissatisfied with how we handle your personal information, you may:
- Contact us directly using the details in Section 21;
- Lodge a complaint with the relevant authority:
| Jurisdiction | Authority | Contact |
|---|---|---|
| South Africa | Information Regulator | complaints.BI@inforegulator.org.za | 012 406 4818 |
| European Union | Your local supervisory authority | edpb.europa.eu |
| California, US | California Privacy Protection Agency | cppa.ca.gov |
| United States | Federal Trade Commission | ftc.gov/complaint |
20. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, the updated Policy will be posted on our Website with a revised "Effective Date". Where required by law, we will obtain your renewed consent.
21. Contact Us
Van Dyk Theron Incorporated
Information Officer / Privacy Contact: CJ van Dyk
Physical Address: 406 Kings Highway, Lynnwood, 0081
Postal Address: PO Box 36477, Menlopark, 0102
Email: tiaan@vdtreg.co.za
Telephone: 082 825 8876
Website: www.vdtreg.co.za
You may also submit requests via SMS, WhatsApp, or any other convenient channel (per the 2025 POPIA Regulation Amendments).