Contact Us

TRANSUNION DATA PROCESSING POLICY FOR THE PROTECTION OF PERSONAL INFORMATION

INTRODUCTION

TransUnion is a credit bureau registered in accordance with the provisions of the National Credit Act 34 of 2005 (Registration Number NCRCB4). Its operations are regulated by the NCA and by other applicable Laws, including the Protection of Personal Information Act 4 of 2013.  TransUnion protects the integrity of all information housed by it, keeping such information secure. TransUnion is sensitive to the issues regarding privacy of information.

Furthermore, TransUnion is a member of the following industry associations –

  • Credit Bureau Association (“CBA”): A voluntary industry body in the Republic of South Africa, representing the majority of credit bureaus within South Africa. The CBA operates in the industry in accordance with the NCA, as regulated by the National Credit Regulator, and related laws. The CBA’s mandate is to provide a framework for a sustainable and well-functioning credit information system by facilitating fair practice within the credit bureau industry and by promoting transparency, accountability, high-quality credit reporting and sound business practices. TransUnion is also subject to the CBA industry Code of Conduct, which has been issued by the Information Regulator in terms of the Protection of Personal Information Act.
  • South African Credit and Risk Reporting Association (“SACRRA”): A not-for-profit voluntary association of members who share credit and risk performance data of their customers (which information is known as “Payment Profile Information”). SACRRA provides the framework to facilitate the sharing of Payment Profile Information at its associate member credit bureaus enabling its members to comply with credit information sharing provisions of the NCA as well as the provisions for performing credit and risk assessments and affordability calculations.

TransUnion is committed to conducting its operations in an ethical manner and in compliance with all applicable Laws and association/industry policy directives and guidelines. To successfully ensure this, it is vital that all entities doing business with TransUnion ascribe to the same standards. Accordingly, TransUnion has set out, in this policy, obligations that need to be adhered to when an entity processes (including but not limited to the receipt and usage of), Personal Information from or supplies Personal Information to TransUnion.

NOTE: This policy may be updated from time to time to reflect any amendments made to applicable Laws or association/industry policy directives and guidelines.

  1. PURPOSE OF POLICY

    To outline obligations for protecting the integrity and confidentiality of information that is transmitted to and from TransUnion’s systems, as required by applicable Laws and associations relevant to the information services and risk services industry.

  2. APPLICATION OF POLICY
    1. This policy is applicable to all entities who (a) procure and/or use and/or process Personal Information from TransUnion (whether directly OR through an authorised TransUnion channel partner / reseller) and who (b) supply information to TransUnion (whether directly OR through an authorised TransUnion channel partner / reseller) – such parties referred to hereafter as an “Applicable Party”.
    2. The terms of this policy shall be deemed to form part of the Applicable Party’s contract with TransUnion or with a TransUnion channel partner / TransUnion reseller (as the case may be) as if specifically incorporated therein. A breach of any obligation by the Applicable Party herein (and a contravention of the National Credit Act and/or Protection of Personal Information Act) shall therefore be regarded as a breach of the contract concluded with TransUnion or the channel partner/reseller; and shall be managed as such.. Therefore, this policy shall continue to be of force and effect for as long as the either Party remains in possession of any Personal Information of the Data Subjects, regardless of the termination of any agreement or contract with TransUnion.
    3. In the event of a conflict between the provisions of this policy and any other agreement between TransUnion and the Applicable Party and any applicable agreement in place between an authorised TransUnion channel partner / reseller and the Applicable Party, the provisions of this Agreement will take precedence in regard to all aspects pertaining to any processing of Personal Information.
  3. DEFINITIONS

    For purposes of this policy, capitalised terms shall have the meanings ascribed to them below –

    1. Data Subject” means any person(both individual and juristic entity and/or the like) to whom the specific Personal Information relates, as contemplated in POPIA;
    2. “Laws” means all laws, regulations, by-laws, rules, directives, guidelines, circulars, orders and other requirements of any government or any government agency, body or authority, including any regulator or court;
    3. NCA” means the National Credit Act No. 34 of 2005 together with the Regulations, as amended from time to time;
    4. Operator” has the meaning set out in POPIA and for purposes of this policy means the Party who Processes Personal Information on behalf of the other Party or any authorised subcontractor of either of the Parties;
    5. PAIA” means the Promotion of Information Access to Information Act 2 0f 2000, together with the Regulations, as amended from time to time;
    6. Party” or “Parties” means either the Applicable Party or TransUnion or both, as the context may require;
    7. Payment Profile Information” means the payment history and financial information relating to a debt or credit transaction, including relevant payment dates, both negative and positive information and/or signs depicting action taken in respect of such debt or credit transaction;
    8. Personal Information” shall have the meaning set out in section 1 of POPIA, and includes special personal information as defined in section 26 of POPIA and relates to the Personal Information of which either Party is the Responsible Party in relation to which TransUnion renders the services to the Applicable Party;
    9. POPIA” means Protection of Personal Information Act No. 4 of 2013 together with the Regulations, as amended from time to time;
    10. Processing” or “Process” shall have the meaning set out in POPIA;
    11. “Regulations” means the National Credit Regulations promulgated in terms of the NCA and POPIA from time to time;
    12. Responsible Party” shall have the meaning ascribed thereto in POPIA, and for purposes of this Agreement shall mean either Party as the context may require;
    13. “TransUnion” means TransUnion Africa (Pty) Limited, registration number 1992/007124/07, a private company with limited liability, as well as all subsidiaries thereof, including TransUnion Credit Bureau, registration number 2004/007773/04, duly registered with the NCR (under registration number NCRCB4).
  4. COMPLIANCE WITH LAWS AND ASSOCIATED BODIES

    In its dealings with TransUnion and usage of TransUnion’s service offerings, the Applicable Party shall at all times comply with the requirements for the receipt, compilation and reporting of information as prescribed by the NCA and other applicable Laws and associated bodies.

  5. INFORMATION SECURITY
    1. The Applicable Party shall ensure that all persons accessing TransUnion’s services on its behalf have been duly authorised by the Applicable Party to do so. In addition, the Applicable Party shall ensure that only it or its authorised representatives have access to any PIN and/or password PIN issued for the purposes of requesting TransUnion services. The Applicable Party shall be liable for transactions, fees and other costs arising out of the use by any person of TransUnion’s services via the PIN and/or Password whether or not such use is or has been authorised by the Applicable Party.
    2. The Applicable Party shall notify TransUnion in writing of any breach or attempted breach of security of which the Applicable Party may become aware or ought to have become aware of and the Applicable Party shall take reasonable steps to prevent a recurrence thereof and to mitigate the effects of such breach. TransUnion shall be entitled to fully investigate such breach or attempted breach and the Applicable Party shall give TransUnion its full co-operation with such investigation. Furthermore, the Applicable Party shall be liable for transactions, fees and other costs arising out of the use by any person of the TransUnion services including use of such services arising from a security breach in accordance with applicable Laws.
    3. The Applicable Party shall install, implement and maintain the necessary software and IT security systems to ensure that no destructive elements are introduced into TransUnion’s systems. Destructive Elements means code that –
      1. is intentionally designed to disrupt, disable, harm or otherwise impede in any manner, including aesthetic disruptions or distortions, the operation of TransUnion’s software, hardware, computer systems or networks, or any other associate hardware, software, firmware, computer system or network used in relation to TransUnion’s services; or
      2. would disable TransUnion’s software, hardware, computer systems or network or impair in any way their operation based on the elapsing of a period of time, exceeding the authorised number of copies, advancement to particular date or numeral; or
      3. would permit an unauthorised person to access TransUnion’s software, hardware, computer systems or network of and/or of third parties to cause a disruption, disablement, harm or impairment, or which contains any other similar harmful, malicious or hidden procedures, routines or mechanisms which would cause such programs to cease functioning; or that can cause damage to data, storage media, programs, equipment or communications, or otherwise interfere with the operations thereof.
  6. CONSENTS

    The Applicable Party -

    1. shall ensure that prior to submitting to and/or requesting any information from TransUnion (whether directly or via a TransUnion channel partner or TransUnion reseller) it shall have validly obtained all consents (whether from natural or juristic persons – as applicable) that may be required in terms of the NCA and POPIA or any other applicable Laws to submit, request and/or receive such information;
    2. shall obtain upfront, written, express, ongoing and lawfully valid consent in respect of any requests for TransUnion to provide monitoring and account management services; and
    3. shall retain and store all consents obtained and be able to make same available to TransUnion without delay if ever
  7. SUBMISSION OF DATA TO TRANSUNION
    1. The Applicable Party shall ensure that any information requested from or submitted to TransUnion, whether directly or indirectly -
      1. shall contain, in relation to a natural person, the minimum criteria as set out in Regulation 19(1) of the NCA; and
      2. shall contain, in relation to a juristic person, the juristic person’s registered and trading name; registration number, registered address, physical and postal address.
    2. When submitting any information to TransUnion, whether directly or indirectly, the Applicable Party shall -
      1. be lawfully entitled to submit such information to TransUnion;
      2. ensure that all information reported to TransUnion is accurate, up-to-date, relevant, complete, valid and not duplicated;
      3. submit only information which falls in the permitted categories set out in Regulation 18(6) of the NCA;
      4. before submitting adverse credit information, (a) ensure that the minimum monthly or such other instalment payments have not been paid for a period of at least three consecutive billing cycles in accordance with Regulation 19(7) of the NCA; and give its customers twenty business days’ written notice, as required by Regulation 19(4), of its intention to submit adverse information regarding the customer before such information is submitted to TransUnion.
    3. The Applicable Party shall under no circumstances submit the following information to TransUnion –
      1. information in respect of a debt that has prescribed in terms of the Prescription Act, No. 68 of 1969, including any information relating to the collection or re-activation of such debt;
      2. duplicate listings –
      3. listings in relation to SABC television licences, e-Tolls, road traffic fines;
      4. cost orders;
      5. disputed adverse credit information – that is a default listing relating to an outstanding amount that had been disputed by a person prior to the date of the submission of the disputed adverse information (i.e. where such dispute had not been resolved at the time of listing). For purposes of this obligation, “disputed” refers to any instance where it can be proven that a person had communicated to the Applicable Party an uncertainty around being liable for the whole or part of the relevant debt, whether or not through the institution of legal proceedings; and
      6. information which the Applicable Party had already submitted to TransUnion in respect of a person, which information the person had successfully challenged in accordance with the information challenge process provided for in the NCA. For purposes of clarity, the Applicable Party shall not be entitled to modify the successfully challenged information in any way so as to resubmit same.
    4. The Applicable Party will fully and timeously co-operate with TransUnion’s requests for credible evidence related to an adverse credit listing when that listing has been challenged as part of any Personal Information challenge (including but not limited to ) process provided for in the NCA. Should an Applicable Party fail to respond to TransUnion within the legislated period set out in the NCA, the adverse listing in dispute will be permanently removed from the relevant person’s credit profile.
  8. USE OF INFORMATION
    1. All information received as part of services provided by TransUnion shall:
      1. be used by the Applicable Party solely and exclusively for a purpose permitted in terms of the NCA and POPIA. The Applicable Party shall not, whether directly or indirectly, sell or use any such information for any commercial purpose; and
      2. be for the Applicable Party's exclusive one-time use, which usage shall be strictly related to the lawful purpose for which the service is intended.
    2. The Applicable Party shall only access a person’s information for the purposes of assessing an employment application where that person has (a) consented to such access; AND (b) is being considered for a position that requires honesty in dealing with cash or finances, and where the job description of such position has been clearly outlined in the applicable contract of employment.
    3. In the event that TransUnion is entitled to procure and supply payslip and salary information, the Applicable Party -
      1. acknowledges that payslip and salary information may only be requested and used for lawful purposes.
      2. shall, where it has requested such information from TransUnion, have obtained the prior written consent necessary to authorise TransUnion to access and retrieve a person’s payslip and salary information (a) from the relevant payroll companies, or (b) from TransUnion, for any lawful purpose (as the case may be); and
      3. shall not share, distribute, alter or disseminate the payslip and salary information received by it from TransUnion to any third party whatsoever.
    4. The Applicable Party acknowledges that the information supplied to it pursuant to a testing request will contain information that is regulated by Laws. This test data shall be used by the Applicable Party solely and exclusively for the purpose of the test and the Applicable Party shall not share the test data with or distribute that data to any third party. The Applicable Party shall not, whether directly or indirectly, use the test data for internal business or operational purposes or sell/use the test data for any purpose whatsoever.  The Applicable Party shall destroy the test data upon completion of the testing exercise shall provide TransUnion with written confirmation of the destruction. The Applicable Party shall furthermore be able to evidence the destruction to TransUnion should TransUnion request such evidence.
  9. THE PARTIES OBLIGATION CONCERNING PROTECTION OF PERSONAL INFORMATION
    1. It is recorded that, pursuant to the obligations under this policy, either Party will Process Personal Information of Data Subjects in connection with and for the purposes of the provision of TransUnion’s services and will act as the other Party’s Operator.
    2. Unless required by Law, each Party shall Process the Personal Information only:
    3. in compliance with this policy;
    4. for the purposes connected with the provision of the Services as provided for in any agreement or contract with TransUnion or as specifically otherwise instructed or authorised by the other Party in writing;
    5. to the extent permissible in terms of applicable Laws; and
    6. in accordance with TransUnion’s technical and organisational security measures (which may be communicated and/or updated from time to time).
      1. The Parties shall treat the Personal Information that comes to their knowledge or into their possession as confidential and shall not disclose it without the prior written consent of the other Party, unless permissible by law. For avoidance of doubt, the provisions of any agreement or contract with TransUnion in relation to Confidential Information or any non-disclosure policy, or the provisions regarding confidentiality contained in any agreement or contract with TransUnion, as the case may be, entered into between the Parties shall with the necessary changes, apply to this policy.
    7. Without limiting the either Party’s obligations under this policy, each Party shall comply with applicable industry or professional rules and regulations and any Laws, in relation to the safeguarding of Personal Information, which may apply to it.
    8. Each Party shall:
      1. take steps to keep abreast and ensure that it and its Staff comply fully with all applicable laws and regulations that are applicable to the Services;
      2. limit the Processing of and access to the Personal Information to those Staff who need to know the Personal Information to enable the rendering of the Services;
      3. deal promptly, but at all times without exceeding 5 (five) business days, with all reasonable inquiries from the other Party relating to its Processing of the Personal Information;
      4. immediately inform the other Party of its inability to comply with the other Party’s instructions and this clause 9, in which case the other Party is entitled to suspend the other’s Processing of Personal Information and/or terminate any agreement or contract with TransUnion;
      5. provide the other with full co-operation and assistance in relation to any requests for access to, correction of or complaints made by the Data Subjects relating to their Personal Information;
    9. Each Party (the “Notifying Party”) shall notify the other Party in writing:
      1. within 1 (one) business day or otherwise as soon as reasonably possible, if any Personal Information under the control of the Notifying Party as a result of a Contract has been or may reasonably believe to have been accessed or acquired by an unauthorised person or if a breach has occurred with reference to the Notifying Party’s use of the Personal Information under this policy, furnish TransUnion with details of the Data Subjects affected by the compromise and the nature and extent of the compromise, including details of the identity of the unauthorised person who may have accessed or acquired the Personal Information as well as with daily reports on progress made at resolving the compromise;
      2. of any request by a Data Subject for correction of the Personal Information, or complaints received by the Applicable Party, relating to any Personal Information submitted by TransUnion in relation to that Data Subject’s obligations in terms of POPIA and provide TransUnion with full details of such request or complaint; and
      3. to the extent lawfully permissible, promptly of any legally binding request for disclosure of Personal Information or any other notice or communication that relates to the Processing of the Personal Information from any supervisory or governmental body.
    10. Each Party acknowledges and agrees that the other Party retains all right, title and interest in and to the Personal Information.
  10. AUDIT RIGHTS
    1. TransUnion shall have the right to audit the Applicable Party’s Processing facilities in respect of the services, upon separate and specific written policy regarding such audit first being reached with the other Party on each occasion, at least once per year or if there is a reasonable suspicion that the Applicable Party is not complying with the provisions of this policy or where there is a suspicion that the confidentiality, integrity and accessibility of Personal Information is likely to be compromised. The Party being audited shall offer reasonable assistance and co-operation to the other Party and/or its auditors or inspectors in the carrying out of such auditing exercise. Nothing in this clause 10 should be read as providing either Party with unlimited access to audit the other Party without just cause. If an audit takes place, TransUnion shall have no right of access to any confidential information of the Applicable Party’s clients or to any confidential information in general (including Personal Information TransUnion is not responsible for in terms of POPIA or the NCA.
  11. RETURN AND RETENTION OF PERSONAL INFORMATION
    1. Each Party (“requesting Party”) may, at any time on written request to the other Party, require, where it is practically and lawfully possible, that (a) the other Party immediately return to it any Personal Information and may, in addition, require that the other Party furnish a written statement to the effect that upon such return, it has not retained in its possession or under its control, whether directly or indirectly, any such Personal Information or material; or (b) as and when required by the requesting party on written request, destroy all such Personal Information and material and furnish TransUnion with a certificate of destruction to the effect that the same has been destroyed. Where, by the nature of the services that the other Party provides to different clients, the return of information or destruction thereof is not possible, the Party shall provide the requesting Party with written reasons as to why this is the case and seek to reach written policy with the requesting Party as to how to regulate the relevant Personal Information going forward.
    2. Each Party shall comply with any request in terms of this clause 11 within 7 (seven) days of receipt of such request.
  12. INDEMNITIES
    1. Subject to the provisions contained in the Any agreement or contract with TransUnion, each Party hereby indemnifies and holds the other Party harmless from any and all losses arising from any claim or action brought against the other Party arising from or due to the one’s Party’s breach of its obligations set out in this policy or any law with respect to the protection of Personal Information.
  13. CONFIDENTIALITY
    1. The Parties agree and undertake –
      1. Except as permitted by this policy, not to disclose or publish any Confidential Information (which for purposes of this clause shall mean any information or data (a) which by its nature or content is identifiable as confidential and/or proprietary to either Party and/or any third party; or (b) which is provided or disclosed in confidence by the one Party (“Disclosing Party”) to the other Party (“Receiving Party”); and (c). which Disclosing Party or any person acting on its behalf may disclose or provide to Receiving Party or which may come to the knowledge of Receiving Party by whatsoever means) in any manner for any reason or purpose whatsoever without the prior written consent of the other Party and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Parties to obtain the consent of such third party;
      2. Except as permitted by this policy, not to utilise, employ, exploit or in any other manner whatsoever use the Confidential Information for any purpose whatsoever without the prior written consent of the other Party and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Applicable Party to obtain the consent of such third party;
      3. To restrict the dissemination of the Confidential Information to only those of each Party’s staff who are actively involved in activities for which use of Confidential Information is authorised and then only on a “need to know” basis and each Party shall initiate, maintain and monitor internal security procedures reasonably acceptable to the other to prevent unauthorised disclosure by its staff; and
      4. To take all practical steps, both before and after disclosure, to impress upon its staff who are given access to Confidential Information the secret and confidential nature thereof.
    2. The obligations of each Party with respect to each item of Confidential Information shall endure for an indefinite period from receipt of that item of Confidential Information. The obligations referred to in this clause 13 shall endure notwithstanding any termination of this policy, any other policy entered into between the Parties or any discussions between the Parties.
    3. Each Party hereby indemnifies and holds the harmless from any and all losses arising from, or in connection with, any claim or action arising from the other Party’s breach of any obligation with respect to Confidential Information.
  14. BREACH AND TERMINATION
    1. In the event of either of the Parties committing a breach of any of the conditions of this policy and failing to remedy such breach within 7 (seven) Business Days of receipt of a notice from the other Party requesting it to remedy such breach, then the other Party shall be entitled to cancel this entire policy forthwith and claim such losses as it may have suffered. In the event of termination of this policy, the Party terminating this policy shall have a right to also exercise its rights of termination under any agreement or contract with TransUnion.
    2. Notwithstanding anything to the contrary contained in this policy, the Parties shall be entitled to terminate this policy by mutual policy in writing.
    3. The provisions of this clause 14 shall not affect or prejudice any other rights/remedies which the Parties may have in law or in any other written agreement or contract between the Parties.
  15. PAYMENT PROFILE INFORMATION
    1. Payment Profile Information may be requested by an Applicable Party who is a SACRRA member or is entitled to such information in terms of Regulation 19(13) and the related NCR guideline; provided that all SACRRA rules and standard operating procedures and/or the provisions of Regulation 19(13), regulating the supply of that information, are complied with (as may be applicable in the circumstances).  
    2. Where supplying Payment Profile Information, the Applicable Party shall ensure compliance with Regulation 19(13), including the related NCR guideline, and/or, to the extent applicable, the SACRRA data access protocols and data access standard operating procedures as published and updated by SACRRA from time to time.
  16. REMOVAL OF ADVERSE LISTINGS
    1. To the extent required by the NCA, adverse credit information must be removed from a person’s credit profile if that person has paid up the debt associated with that listing. The Applicable Party shall provide TransUnion with details regarding settlement of any obligations under a credit agreement within seven days of settlement of such obligation.
    2. To the extent required by the NCA, judgments must be removed from a person’s credit profile if that person has settled the capital amount of the judgment. The Applicable Party shall upon settlement by the person of the capital amount of a judgment advise TransUnion within seven days of settlement of such obligation
    3. An Applicable Party shall only be entitled to remove a default listing if it is factually incorrect, related to fraud or a duplicate listing.
    4. The Applicable Party shall not, unless lawfully entitled to do so, take an upfront fee in order to remove adverse credit information from a person’s credit profile.
  17. INFORMATION REQUESTED IN RESPECT OF JURISTIC PERSONS AND THEIR PRINCIPALS.
    1. The Applicable Party acknowledges that in the event that it requests information in relation to any juristic person/s, the relevant report to be provided to it may contain information relating to that juristic person’s directors, senior leadership and/or key stakeholders in the business (“Principals”). The Applicable Party shall be (a) fully authorised, as required by all applicable Laws, to obtain the information in respect of the Principals; and (ii) in the event that it requests information relating to both juristic persons and their Principals, be fully compliant with the requirements as set out in Regulation 18(5) of the NCA. It shall furthermore have obtained all required consents for obtaining and having sight of information regarding the Principals.
  18. CONSEQUENCES OF TERMINATION
    1. The termination of this policy shall not affect the rights of either of the Parties that accrued before termination of this policy or which specifically survives the termination of the policy.
    2. Upon termination of this policy and upon request by either Party, the other Party shall return or destroy any material containing, pertaining or relating to the Personal Information disclosed pursuant to this policy to the requesting Party. Such request will be regulated in accordance with clause 18 and/applicable Laws pertaining to the Processing of Personal Information.
  19. WAIVER
    1. Failure or delay by either Party in exercising any right will not constitute a waiver of that right.
    2. No waiver of any of right under this policy will be binding unless it is in writing and signed by the Party waiving the right.
  20. SEVERABILITY
    1. If any part of this policy is found to be invalid or unenforceable, it shall be severed from the remainder of this policy, which shall remain valid and enforceable.

Note: for more information of our privacy practices please visit www.transunion.co.za/legal/privacy-policy

May 2021