Free delivery for orders over R1000  ·  Sign up for 10% Off
NEWJCK

NewJack Apparel  ·  Official Governance Document

Data Protection & Compliance Policy

NewJack's internal and external operational procedures for processing, safeguarding, and maintaining compliance for personal data.

Effective Date: 18 July 2026

1. Purpose

This policy describes NewJack's formal operational approach to protecting customer, employee, supplier, and business-partner information.

NewJack is committed to processing personal information lawfully, reasonably, transparently, and securely in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

2. Scope

This policy applies to all personal information processed through:

  • The NewJack e-commerce website and storefront;
  • Online customer orders and checkout portals;
  • Email communications and newsletters;
  • WhatsApp customer service channels;
  • Social media interactions (Instagram, TikTok);
  • Pop-up shops and retail activations;
  • Event registrations and RSVP logs;
  • Competitions and promotional draws;
  • Customer-support records and feedback submissions;
  • Supplier, vendor, and contractor relationships;
  • Marketing platforms and analytics engines; and
  • Physical and electronic business records.

3. Core Processing Principles

NewJack adheres strictly to the 8 POPIA processing conditions:

  • Accountability: Ensuring compliance measures are enforced across all operations.
  • Processing Limitation: Collecting information lawfully, reasonably, and for specific defined needs.
  • Purpose Specification: Defining explicit, lawful reasons before collecting personal data.
  • Further Processing Limitation: Ensuring secondary data use remains compatible with the initial consent.
  • Information Quality: Taking reasonable steps to maintain accurate, up-to-date customer records.
  • Openness: Maintaining transparent policies and notifying individuals when data is collected.
  • Security Safeguards: Implementing robust technical and organizational security controls.
  • Data Subject Participation: Respecting customer rights to access, correct, or delete their information.

4. Lawful Grounds for Processing

Depending on the activity, NewJack processes information based on:

  • Explicit customer consent;
  • Performance of a contract (e.g. fulfilling a streetwear order or dispatching courier packages);
  • Compliance with statutory tax, accounting, or legal obligations;
  • Protection of legitimate customer interests; or
  • NewJack's legitimate business interests, where not overridden by individual privacy rights.

5. Data Minimisation

Only information reasonably necessary for a defined, legitimate business purpose is collected. Sensitive or special personal information (e.g. biometric data, political views) is not collected unless strictly required by law and protected accordingly.

6. Access Control & System Security

Access to personal customer information is strictly limited to authorized personnel who require it for fulfillment, support, or management duties.

Where practical, NewJack implements:

  • Password protection and credential vaulting;
  • Multi-factor authentication (MFA) on administrative portals;
  • Role-based access controls (RBAC);
  • Encrypted database connections and secure devices;
  • Restricted database administrative privileges; and
  • Periodic access reviews.

7. Third-Party Service Provider Governance

Before engaging any third-party service provider that processes personal information on our behalf, NewJack evaluates:

  • The nature and sensitivity of data shared;
  • The vendor's security controls and encryption standards;
  • Server locations and cross-border data routing;
  • Contractual confidentiality and data protection obligations;
  • Security incident reporting protocols; and
  • Data destruction and return procedures upon contract termination.

8. Data Retention Guidelines

Business records are retained strictly according to defined schedules:

  • Order and tax invoice records: 5 years (in compliance with SARS requirement);
  • Customer service logs & returns: Retained for warranty & operational review periods;
  • Marketing consent records: Maintained until consent is withdrawn;
  • Inactive or unneeded data: Securely deleted or anonymized once retention periods expire.

9. Marketing Compliance & Opt-Out

NewJack ensures that:

  • Clear records of marketing consent are maintained;
  • Functional, easy opt-out / unsubscribe options are provided;
  • Unsubscribe requests are processed promptly;
  • No purchased or unlawfully obtained contact databases are used; and
  • Communication ceases immediately upon receiving an objection.

10. Photography & Content Consent

For identifiable customer, model, or event attendee content used in campaigns, NewJack secures appropriate model releases or consent before commercial publication.

11. Security Incident Response Procedure

If a security incident or data breach occurs, NewJack follows a structured response plan:

  1. Contain the incident and secure affected infrastructure;
  2. Preserve digital evidence and conduct forensic assessment;
  3. Identify affected data records and individuals;
  4. Evaluate potential harm or risk exposure;
  5. Notify the Information Officer immediately;
  6. Issue required notifications to the Information Regulator and affected individuals;
  7. Remediate technical vulnerabilities and update security procedures; and
  8. Document the incident log and response outcome.

12. Data-Subject Request Procedure

All requests for access, correction, deletion, or objection under POPIA are logged, identity-verified, assessed under statutory law, and responded to within a reasonable period.

13. Team Training & Awareness

Staff, contractors, and event team members who handle personal information receive practical guidance on confidentiality, password hygiene, phishing defense, customer verification, and safe data handling.

14. Compliance Responsibilities

  • Management: Approving resources, policy updates, and security measures.
  • Information Officer: Overseeing POPIA compliance, handling requests, and directing incident response.
  • Contractors & Staff: Safeguarding data and adhering to operational security protocols.

15. Recommended NewJack Compliance Register

NewJack maintains formal internal registers covering:

  • Information Officer registration;
  • Personal information processing inventory;
  • Third-party service provider contracts;
  • Marketing consent and opt-out logs;
  • Security incident logs;
  • Data subject access request records; and
  • Photography & model release releases.

16. Contact & Compliance Enquiries

Information Officer: NewJack Compliance Officer

Email: newjackrsa@gmail.com / info@newjack.co.za

WhatsApp: +27 69 355 5496

Business Address: NewJack Studio, Jeppestown, Johannesburg, South Africa