GDPR & POPIA Compliance
Effective date: 7 September 2026
Black Bar Technologies serves clients in South Africa and the European Economic Area. This page explains how we comply with both the EU General Data Protection Regulation (GDPR) and South Africa's Protection of Personal Information Act (POPIA).
1. One standard, two regimes
GDPR and POPIA share the same core principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and accountability. We apply the stricter of the two applicable standards to all personal information we process, regardless of where the data subject lives.
2. Our role
For enquiries submitted through this website, we are the responsible party (POPIA) / controller (GDPR): we decide why and how your information is processed. For client systems we host or support on your behalf, we process data strictly on your documented instructions as an operator (POPIA) / processor (GDPR).
3. Lawful bases we rely on
- Consent - when you submit a form or opt in to marketing (withdrawable at any time).
- Contract - to deliver services you have requested or engaged us for.
- Legitimate interests - to secure and improve our services, balanced against your rights.
- Legal obligation - where South African or EU law requires processing or retention.
4. International transfers
Our website, email and hosting infrastructure run on Hetzner Cloud in Germany (EU). Where information moves between South Africa and the EU, we rely on appropriate safeguards, including the data-protection equivalence of POPIA and GDPR and contractual confidentiality commitments.
5. Your rights
Depending on the regime that applies to you, you have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent and to lodge a complaint with a supervisory authority:
- South Africa: the Information Regulator (inforegulator.org.za).
- EU/EEA: the data protection authority in your country of residence.
6. Exercising your rights
Email info@blackbartechnologies.co.za with your request. We verify your identity where necessary and respond within one month (GDPR) or a reasonable time under POPIA. See also our Privacy Policy for what we collect and how long we keep it.
7. Security and breach response
We apply reasonable technical and organisational measures (encrypted transport, access control, least privilege). If a breach is likely to result in a risk to your rights, we will notify affected data subjects and the relevant regulator within the statutory timeframes.