NNamela

Operations

POPIA Basics for Taxi Associations and Operators

Published · 4 min read

Taxi associations handle a surprising amount of personal information: drivers' and owners' contact and identity details, vehicle records, payment and payout records, and, as more associations go digital, location data and rider accounts. South Africa's Protection of Personal Information Act, 4 of 2013 (POPIA), sets rules for how that information must be handled. This article gives a plain-language overview of the basics.

This is general information, not legal advice. For advice on your association's specific situation, consult a legal professional or the Information Regulator's guidance.

What counts as personal information?

POPIA defines personal information broadly. For a taxi association it includes, among other things:

  • Names, ID numbers, phone numbers and addresses of drivers, owners, marshals and riders.
  • Financial information, such as bank details, wallet balances, payouts and payslips.
  • Location information, such as GPS tracking data from vehicles and riders.
  • Opinions about a person, such as ratings and complaints.

If information can identify a living person, or in some cases an existing juristic person, it is likely covered.

Who is responsible?

Under POPIA, the "responsible party" is whoever decides why and how personal information is processed. For many association systems, that is the association itself. Each organisation must also have an Information Officer, who by default is the head of the organisation, and who is responsible for encouraging compliance. Information Officers must be registered with the Information Regulator.

The eight conditions for lawful processing

POPIA sets out eight conditions. In simple terms:

  1. Accountability: the association must ensure the conditions are met.
  2. Processing limitation: collect only what you need, lawfully and with a valid justification, such as consent, a contract or a legal obligation.
  3. Purpose specification: collect information for a specific, defined purpose, and keep it no longer than needed.
  4. Further processing limitation: do not use information for something unrelated to the original purpose.
  5. Information quality: keep information accurate and up to date.
  6. Openness: tell people what you collect and why.
  7. Security safeguards: protect information against loss, damage and unauthorised access.
  8. Data subject participation: people may ask what information you hold about them and request corrections.

Applying it to everyday association work

Driver and owner records

Collect what you need to run operations and meet your legal obligations, keep it accurate, and restrict who can see it. Remove access for people who leave the association. Our record-keeping checklist covers good practice.

Location tracking

GPS data is personal information. Tell drivers and riders what is tracked and why, use it only for those purposes, such as operations, safety and service, and limit who can view it. Read how GPS tracking helps taxi associations.

Payments and payslips

Financial information is particularly sensitive. Use reputable payment providers, restrict access to financial records and make sure every administrative action is logged.

Ratings and feedback

Ratings are opinions about identifiable drivers. Use them fairly, for improving service rather than punishing people without a process. See using rider ratings to improve taxi service.

Security safeguards in practice

  • Give each person their own login, never a shared one.
  • Use strong passwords and protect devices with PINs.
  • Grant access by role, so people see only what they need.
  • Keep an audit trail of administrative actions.
  • Choose systems that protect financial records from being altered after the fact.
  • Keep paper records locked away, and dispose of them securely.

When something goes wrong

If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, POPIA requires the responsible party to notify the Information Regulator and the affected people as soon as reasonably possible. Have a simple plan for who investigates, who decides and who communicates.

Working with technology providers

When an association uses a software platform, the provider may process personal information on the association's behalf. POPIA calls this an "operator". The association should have a written agreement that requires the operator to keep the information secure and to report any security compromise. Ask providers how they protect data before you sign. Our software checklist includes questions to ask.

A simple starting checklist

  • Register your Information Officer with the Information Regulator.
  • List the personal information you collect and why.
  • Tell drivers, owners and riders what you collect and why.
  • Remove information you do not need.
  • Control access by role and keep an audit trail.
  • Agree data protection terms with your technology providers.
  • Plan how you will respond to a security incident.

How Namela approaches it

In the Namela Admin Portal, every action taken by an admin user is recorded in a full audit trail, and financial records stay read-only and tamper-evident. Associations manage their own drivers, owners, marshals and clients from one directory, which makes it easier to keep information accurate and to control who can see it. Learn more about Namela's features, or contact us with questions about how the platform handles your association's data.

Ready to digitise your association?

Get in touch to onboard your association, or head straight to the admin portal if you already have an account.

Related guides