South Africa-wide association info@ndoda.org

Privacy notice

A production-ready starting point for explaining how NDODA processes applicant and member information.

Legal review required.This draft must be reviewed and completed with NDODA’s registered details, Information Officer, retention periods, operators and complaint channels before publication.

1. Who is responsible for your information

The National Drivers & Owner Drivers Association (NDODA) will act as the responsible party for personal information collected through ndoda.org. Official registration and contact details will be inserted before launch.

2. Information collected

The site may collect identification and contact details, residential and operating province, driving credentials, work experience, vehicle and insurance information, uploaded documents, application status, payment reference and communications.

3. Why information is used

Information may be used to assess membership applications, verify documents, administer memberships and vehicle registrations, communicate with applicants, support compliance, match eligible members to relevant opportunities, process payments and maintain records.

4. Special and sensitive information

NDODA should minimise collection of criminal, health and other special personal information. Where such information is genuinely required, a separate lawful basis, notice and consent process should be used.

5. Sharing

Information should only be shared with authorised service providers, verification providers, payment processors and opportunity partners where necessary and subject to appropriate agreements and notices.

6. Security

Identity and vehicle documents should be stored in protected locations, access-controlled, encrypted where appropriate, monitored and removed in line with an approved retention schedule.

7. Your rights

Applicants and members may request access, correction or deletion where applicable; object to certain processing; withdraw marketing consent; and lodge a complaint with NDODA or the Information Regulator.

8. Direct marketing

Marketing consent must be separate from application consent. Every marketing message must include a practical opt-out method.

9. Contact

Information Officer details, privacy email and physical address to be inserted before launch.