Privacy Policy

Van Dyk Theron Incorporated | Registration No. 2012/046216/21

Trading as VDT

Effective Date: 1 April 2026 | Last Reviewed: 1 April 2026 | Version: 1.0

Jurisdictions: POPIA (South Africa) · GDPR (EU/EEA) · CCPA/CPRA (California) · FTC Act (United States)

1. Introduction

Van Dyk Theron Incorporated (2012/046216/21), trading as VDT ("we", "us", or "our"), is committed to protecting your personal information and respecting your right to privacy.

This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you access our website www.vdtreg.co.za (the "Website"), use our services, or otherwise interact with us.

This Policy is designed to comply with, and should be interpreted in accordance with:

  • The Protection of Personal Information Act 4 of 2013 ("POPIA") of the Republic of South Africa, as amended by the April 2025 Regulation Amendments;
  • The General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable EU/EEA member-state implementing legislation;
  • The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"); and
  • The Federal Trade Commission Act, Section 5, and other applicable US federal and state privacy and consumer-protection statutes.

Where a conflict exists between the requirements of different jurisdictions, we apply the standard that affords the highest level of protection to the individual.

2. Definitions

Term UsedPOPIA EquivalentGDPR EquivalentUS / CCPA Equivalent
Personal InformationPersonal Information (s 1)Personal Data (Art 4(1))Personal Information (CCPA § 1798.140(v))
Data Subject / YouData Subject (s 1)Data Subject (Art 4(1))Consumer (CCPA § 1798.140(i))
Controller / WeResponsible Party (s 1)Data Controller (Art 4(7))Business (CCPA § 1798.140(d))
ProcessorOperator (s 1)Data Processor (Art 4(8))Service Provider / Contractor
ProcessingProcessing (s 1)Processing (Art 4(2))Collecting, using, retaining, sharing, selling
ConsentConsent (s 1, s 11)Consent (Art 4(11))Consent (CCPA/CPRA § 1798.140(h))
Special / Sensitive DataSpecial Personal Info (s 26)Special Categories (Art 9)Sensitive Personal Info (CPRA § 1798.140(ae))
Privacy OfficerInformation Officer (s 55)Data Protection Officer (Art 37)N/A (designated privacy contact)

3. Scope and Application

This Policy applies to all personal information we process about:

  • Visitors to our Website;
  • Clients, prospective clients, and their representatives;
  • Suppliers, service providers, and their personnel;
  • Individuals who contact us via email, telephone, social media, or other channels; and
  • Any other natural or juristic person whose personal information we process.

This Policy does not apply to personal information processed by third-party websites linked from our Website.

Territorial Reach

  • POPIA applies where the responsible party is domiciled in South Africa or uses automated or non-automated means in South Africa to process personal information.
  • GDPR applies where we offer goods or services to individuals in the EU/EEA or monitor their behaviour within the EU/EEA.
  • CCPA/CPRA applies where our processing activities meet the statutory thresholds for California consumers.

4. Information We Collect

4.1 Information You Provide Directly

  • Identity Information: Full name, title, date of birth, ID or passport number;
  • Contact Information: Email address, telephone number, physical and postal address;
  • Professional Information: Employer, job title, professional registrations;
  • Financial Information: Banking details, billing address (where applicable for invoicing);
  • Communication Records: Content of emails, enquiry forms, and other correspondence; and
  • Any other information you voluntarily provide to us.

4.2 Information Collected Automatically

  • Device and Browser Information: IP address, browser type and version, operating system;
  • Usage Data: Pages visited, time spent on each page, referring URLs, click patterns;
  • Location Data: Approximate geographic location derived from your IP address; and
  • Cookies and Similar Technologies: See Section 7 below.

4.3 Information from Third Parties

  • Credit bureaus, public registers, or professional bodies (for client onboarding and due diligence);
  • Analytics providers (e.g. Google Analytics); and
  • Social media platforms (if you interact with our social media accounts).

4.4 Special / Sensitive Personal Information

We do not generally collect special personal information (such as race, health, biometric data, or criminal records) unless strictly necessary for the legal services we provide, in which case processing is justified under POPIA s 27, GDPR Article 9(2), or applicable US law, and appropriate safeguards are in place.

5. Legal Basis for Processing

PurposePOPIA BasisGDPR BasisUS Basis
Providing legal servicesContract (s 11(1)(e))Contract (Art 6(1)(b))Business relationship
Responding to enquiriesLegitimate interest (s 11(1)(f))Legitimate interest (Art 6(1)(f))Business relationship
Marketing communicationsConsent (s 11(1)(a), s 69)Consent (Art 6(1)(a))CAN-SPAM / CCPA opt-out
Legal complianceLegal obligation (s 11(1)(c))Legal obligation (Art 6(1)(c))Applicable US statutes
Website analyticsLegitimate interest (s 11(1)(f))Legitimate interest (Art 6(1)(f))Disclosed in this Policy

6. Purposes of Processing

  • To provide, administer, and improve our legal services;
  • To respond to enquiries and communicate with you;
  • To comply with legal, regulatory, and professional obligations;
  • To manage our client relationships and business operations;
  • To send marketing communications (where you have opted in or we are permitted by law);
  • To conduct research, analysis, and statistical reporting;
  • To protect our rights, property, and safety, and those of our clients and the public; and
  • To administer our Website and ensure its security and functionality.

7. Cookies and Tracking Technologies

7.1 Types of Cookies

CategoryDescriptionConsent Required
Strictly NecessaryEssential for the Website to function (e.g. session management, security)No
Performance / AnalyticsMeasure and analyse Website usage (e.g. Google Analytics)Yes
FunctionalityRemembering preferences (e.g. language, display mode)Yes
Marketing / AdvertisingTargeted advertising and cross-site tracking (if applicable)Yes

7.2 Managing Cookies

When you first visit our Website, a cookie consent banner will appear, allowing you to accept or reject non-essential cookies on a granular, category-by-category basis. Pre-ticked boxes are not used. You may adjust your preferences at any time via the cookie settings link on our Website or through your browser settings.

7.3 Do Not Track (DNT)

We honour "Do Not Track" signals sent by your browser. When a DNT signal is detected, we disable non-essential analytics and advertising tracking for your session.

8. Sharing and Disclosure of Personal Information

We do not sell your personal information. We may share personal information with the following categories of recipients, strictly on a need-to-know basis:

  • Service Providers / Operators: IT hosting, cloud storage, email service providers, payment processors, and professional advisers who process personal information on our behalf under written agreements;
  • Professional Advisers: Auditors, legal counsel, accountants, and insurers as reasonably necessary;
  • Regulatory and Government Bodies: The Information Regulator, SARS, EU supervisory authorities, US regulators, courts, and law enforcement where required by law;
  • Business Transfers: In connection with a merger, acquisition, or sale of assets; and
  • With Your Consent: To any other third party where you have given explicit consent.

9. Cross-Border Transfers

9.1 Under POPIA (South Africa)

Cross-border transfers are permitted where the recipient country provides an adequate level of protection, the data subject consents, the transfer is necessary for a contract, or another exception under section 72 of POPIA applies.

9.2 Under GDPR (EU/EEA)

Transfers outside the EEA are made only where an adequacy decision exists (Article 45), or appropriate safeguards are in place, including EU Standard Contractual Clauses (Article 46(2)(c)), Binding Corporate Rules (Article 47), or an applicable derogation under Article 49.

9.3 Under US Law

We ensure that transfers comply with applicable US privacy requirements. Where the EU-US Data Privacy Framework applies, we abide by its principles.

10. Data Retention

CategoryRetention PeriodGoverning Requirement
Client matter records7 years from completionPrescription Act 68 of 1969
FICA / AML records7 years after end of relationshipFICA ss 22–23
Tax and financial records7 yearsIncome Tax Act; Tax Administration Act
Website analytics data7 yearsInternal policy; GDPR minimisation
Marketing consent recordsDuration of consent + 7 yearsPOPIA; GDPR; CAN-SPAM
Enquiry and correspondence records7 years from last interactionInternal policy

11. Security Measures

We take appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, destruction, use, modification, or disclosure. These include:

  • Encryption of personal information in transit (TLS/SSL) and at rest;
  • Access controls and role-based permissions;
  • Multi-factor authentication;
  • Regular security assessments, penetration testing, and vulnerability scanning;
  • Staff training on data protection and incident response;
  • Physical security measures; and
  • Incident response and breach notification procedures compliant with POPIA (s 22), GDPR (Articles 33–34), and applicable US breach notification laws.

12. Your Rights

RightPOPIAGDPRCCPA/CPRA
Access / Right to Knows 23Art 15§ 1798.100, .110
Correction / Rectifications 24Art 16§ 1798.106
Deletion / Erasures 24Art 17§ 1798.105
Restriction of ProcessingArt 18§ 1798.121
Data PortabilityArt 20§ 1798.130(a)(2)
Objections 11(3)(a), s 69Art 21
Opt Out of Sale / Sharing§ 1798.120, .121
Withdraw Consents 11(2)(b)Art 7(3)Applicable provisions
Non-Discriminations 73Art 77§ 1798.125
Lodge a Complaints 74Art 77CPPA / state AG

12.1 How to Exercise Your Rights

Submit a verifiable request using the contact details in Section 21. We will respond within:

  • POPIA: 30 days;
  • GDPR: One month, extendable by two further months;
  • CCPA/CPRA: 45 days, extendable by an additional 45 days with notice.

13. Children's Privacy

Our Website is not directed at children. We do not knowingly collect personal information from children under the age of 18 (POPIA), 16 (GDPR), or 16/13 (CCPA/CPRA). If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.

14. AI and Automated Decision-Making

Our Website uses artificial intelligence (AI) to generate plain-language summaries of court judgments. This AI processing is applied only to publicly available legal texts and does not involve the processing of your personal information. No automated decisions with legal or similarly significant effects are made about you based on AI processing.

15. Direct Marketing

We may send you direct marketing communications where you have provided consent or where we are permitted to do so by law. You may opt out of direct marketing at any time by contacting us or using the unsubscribe link in any marketing communication.

16. California-Specific Disclosures (CCPA/CPRA)

16.1 Categories Collected and Purpose

We collect the categories of personal information described in Section 4 for the business purposes described in Section 6.

16.2 Sale or Sharing

We do not sell or share personal information as defined by the CCPA/CPRA.

16.3 Sensitive Personal Information

We do not use or disclose sensitive personal information for purposes beyond those permitted under CPRA § 1798.121.

17. POPIA-Specific Provisions (South Africa)

17.1 Information Officer

Name: CJ van Dyk
Designation: Information Officer
Email: tiaan@vdtreg.co.za
Telephone: 082 825 8876
Physical Address: 406 Kings Highway, Lynnwood, 0081

17.2 Conditions for Lawful Processing

We process personal information in compliance with the eight conditions for lawful processing set out in POPIA Chapter 3:

  1. Accountability (s 8)
  2. Processing Limitation (s 9–12)
  3. Purpose Specification (s 13–14)
  4. Further Processing Limitation (s 15)
  5. Information Quality (s 16)
  6. Openness (s 17–18)
  7. Security Safeguards (s 19–22)
  8. Data Subject Participation (s 23–25)

17.3 PAIA Manual

Our manual compiled in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA) is available on written request.

17.4 Security Compromises

In the event of a security compromise involving personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with section 22 of POPIA.

18. GDPR-Specific Provisions (EU/EEA)

18.1 Data Controller

Controller: Van Dyk Theron Incorporated, 2012/046216/21
Registered Address: 406 Kings Highway, Lynnwood, 0081
Contact: tiaan@vdtreg.co.za

18.2 Data Protection Officer (DPO)

Not statutorily required — contact our Information Officer (tiaan@vdtreg.co.za).

18.5 Right to Lodge a Complaint

You have the right to lodge a complaint with your local EU/EEA supervisory authority. A list is available at edpb.europa.eu.

19. Complaints

If you are dissatisfied with how we handle your personal information, you may:

  1. Contact us directly using the details in Section 21;
  2. Lodge a complaint with the relevant authority:
JurisdictionAuthorityContact
South AfricaInformation Regulatorcomplaints.BI@inforegulator.org.za | 012 406 4818
European UnionYour local supervisory authorityedpb.europa.eu
California, USCalifornia Privacy Protection Agencycppa.ca.gov
United StatesFederal Trade Commissionftc.gov/complaint

20. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, the updated Policy will be posted on our Website with a revised "Effective Date". Where required by law, we will obtain your renewed consent.

21. Contact Us

Van Dyk Theron Incorporated
Information Officer / Privacy Contact: CJ van Dyk
Physical Address: 406 Kings Highway, Lynnwood, 0081
Postal Address: PO Box 36477, Menlopark, 0102
Email: tiaan@vdtreg.co.za
Telephone: 082 825 8876
Website: www.vdtreg.co.za

You may also submit requests via SMS, WhatsApp, or any other convenient channel (per the 2025 POPIA Regulation Amendments).

Back to Homepage