Privacy notice

How the UkuThemba Procurement Verification platform processes personal information, aligned with the Protection of Personal Information Act, 2013 (POPIA).

Last updated: 26 July 2026

1. Who is responsible

Each participating government department is the responsible party (data controller) for the personal information it captures in SPPTS. The platform operator processes that information as an operator (processor) on the department's documented instructions. Direct data-subject requests to the relevant department's Information Officer.

2. What we process, and why

  • Account data — name, work email, role and department — to authenticate users and enforce least-privilege access.
  • Security data — password hashes, two-factor secrets, and a tamper-evident audit log of actions — to protect the integrity of procurement records.
  • Procurement & sustainability data — supplier details, contracts, metric values and supporting evidence — to track and verify sustainable public procurement (the platform's public-interest purpose).

The lawful basis is the performance of a public task and compliance with the department's statutory procurement and transparency obligations. Personal information is limited to what is necessary for these purposes (minimality).

3. Security safeguards

SPPTS enforces mandatory two-factor authentication, strict tenant isolation so one department cannot read another's data, encryption of traffic in transit, parameterised database access, and a hash-chained audit trail. Access is role-based and least privilege. See the security & multitenancy documentation for the full control set.

4. Retention

Procurement, evidence and audit records are retained for the period required by the Public Finance Management Act and applicable records-management directives. To preserve auditability, procurement and evidence records are never hard-deleted; they are marked as voided with a reason and retained in the immutable audit trail.

5. Your rights (data subjects)

Under POPIA you may request access to, correction of, or deletion of your personal information, and may object to processing. Because the integrity of a public procurement audit trail is protected by law, requests to erase records that form part of that trail may be lawfully declined or limited; where this applies we will explain the basis. Account personal data (such as display name and contact email) can be corrected or a departing user's account deactivated.

6. Complaints

If you believe your information has been processed unlawfully you may lodge a complaint with your department's Information Officer, and thereafter with the Information Regulator (South Africa).