1. About this notice
The Big Data Showroom (Pty) Ltd (registration number 2025/921835/07) — "TBDS", "we", "us" — provides contact tracing, identity verification and screening services to vetted South African businesses for purpose-built use cases.
This notice explains what personal information we process, why, who we share it with, how long we keep it and how we protect it. It also sets out your rights under the Protection of Personal Information Act 4 of 2013 ("POPIA") and how to exercise them. It is issued in terms of section 18 of POPIA.
It applies to everyone whose personal information we hold — including people who have never been our customer, because our services involve processing information about individuals who are the subject of a search. If you are such a person, section 12 tells you what you can ask us to do.
Our physical and postal addresses are available on request from the Information Officer, whose details are in section 14.
2. The roles we play
Under POPIA our role depends on what we are doing:
- As a responsible party. When we decide why and how to collect, match and hold the data behind our services, and when we handle our own client and website-visitor information, we determine the purpose and means of that processing ourselves. The obligations in this notice are ours.
- As an operator. Where we process information purely on a client's instruction and under their mandate, the client is the responsible party for that processing and carries the duty to notify data subjects. We process under a written agreement as section 21 of POPIA requires.
Our clients are separately responsible for what they do with results after we deliver them. Their obligations are set out in our Terms of Use.
3. Whose information we process
| Category of data subject | Why we hold their information |
|---|---|
| Search subjects | Individuals who are the subject of a search run by a vetted client — for example a debtor, a client of an attorney, or a party to a transaction. |
| Client users | The individuals at our client businesses who hold accounts and run searches. |
| Applicants | People and businesses who apply for access, including those we decline. |
| Website visitors | People who visit our website or contact us. |
| Suppliers and contacts | Individuals at our data suppliers and service providers. |
4. What we process, and where it comes from
POPIA requires us to tell you what we collect and, where we did not collect it from you directly, the source it came from.
4.1 Information about search subjects
We process the following categories of personal information about individuals who are searched:
- names and surnames;
- identity numbers;
- contact telephone numbers.
We do not collect this information from the data subject. It is supplied to us by:
- credit bureaux registered with the National Credit Regulator in terms of the National Credit Act 34 of 2005;
- commercial data providers under contract with us; and
- sources where the data subject consented to the collection and onward supply of their information.
We query those sources at the time of a search. We do not build or hold our own matched database of contact information; what we retain is a record of the searches our clients run, described in section 9.
4.2 Information about client users and applicants
- name, job title, work email address and telephone number;
- company name, registration number and trading address;
- professional registration details and any proof supplied during vetting;
- the lawful purpose recorded for the account;
- account credentials and authentication records;
- a log of every search run — the user, the timestamp and the stated purpose;
- billing and payment records.
We collect this directly from you when you apply, and generate it as you use the service.
4.3 Special personal information
We do not currently process special personal information as defined in section 26 of POPIA. Two services in development — Liveness Verification, which involves biometric information, and Compliance Screening, which involves criminal-behaviour and politically-exposed-person data — will fall into that category. Neither is live, and this notice will be updated to describe how each is handled before either is made available.
5. Why we process it, and our lawful basis
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Providing search, verification and screening results to vetted clients for their recorded lawful purpose | s11(1)(f) — the legitimate interests of the client to whom the information is supplied, as declared by that client for each search |
| Vetting applicants and confirming eligibility | s11(1)(b) — necessary to conclude or perform the contract |
| Operating accounts, authentication and billing | s11(1)(b) — performance of the contract |
| Logging searches, auditing use and investigating misuse | s11(1)(c) and s11(1)(f) — legal obligation and our legitimate interest in preventing unlawful use |
| Keeping records the law requires us to keep | s11(1)(c) — compliance with a legal obligation |
No legislation specifically authorises or requires our collection of this information.
6. Voluntary or mandatory
If you apply for an account, supplying the information we ask for is voluntary, but we cannot vet or activate an account without it. If you decline to provide it, or provide information that is inaccurate, we will decline the application or close the account.
Search subjects do not supply information to us, so nothing is required of them.
8. Cross-border transfers
We may transfer or store personal information on secure data servers located in the European Union. Such transfers are made in accordance with section 72 of POPIA: the recipients are subject to laws providing a level of protection for personal information that is substantially similar to, and in material respects not less than, that afforded by POPIA — namely the General Data Protection Regulation.
9. How long we keep it
We keep personal information only for as long as we need it for the purpose it was collected for, or for as long as the law requires, and then we delete or de-identify it.
| Record | Retention period |
|---|---|
| Search logs — user, timestamp and stated purpose | 5 years from the date of the search |
| Search results | Not retained. Results are returned to the client and are not stored by us. |
| Client account and vetting records | For the life of the account, then 5 years |
| Billing and tax records | 5 years, as required by the Tax Administration Act 28 of 2011 |
| Declined applications | 12 months |
10. How we secure it
Section 19 of POPIA requires us to secure the integrity and confidentiality of personal information with appropriate, reasonable technical and organisational measures. Ours include:
10.1 Where the data sits
Our systems run on Google Cloud Platform, with personal information held on servers located in the European Union. Data is encrypted in transit and at rest using the encryption Google Cloud applies as standard.
Google Cloud is independently certified against international information security standards. That certification covers Google's infrastructure rather than our application, so the controls we operate ourselves are set out separately below.
10.2 Getting into an account
- Two-factor authentication is required on every account and cannot be disabled. A password on its own will not get anyone in.
- Passwords are never stored in readable form.
- Sessions expire and require re-authentication.
- Access is granted by role, so a user reaches only what their role permits, and a principal controls who holds a seat.
- Every account is vetted by a person before it is activated.
10.3 What we record
- Every search is logged against a user, a timestamp and the purpose declared for it.
- We monitor usage patterns for signs of misuse, and audit an account where we see them.
- Operators who process personal information for us do so under written agreement.
If a security compromise occurs, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible, as section 22 of POPIA requires.
11. Direct marketing
We do not use information obtained through our services for direct marketing, and our clients may not either. That prohibition is written into our Terms of Use.
Section 69 of POPIA prohibits direct marketing by electronic means — automated calls, SMS, email or fax — unless you have consented, or you are an existing customer being told about our own similar services, with an opt-out offered every time. Where we market to our own business contacts on that basis, every message identifies us and carries a way to opt out. You can opt out at any time by emailing admin@thebigdatashowroom.com.
12. Your rights
Under POPIA you have the right to:
- Know whether we hold information about you, and get a copy. Ask us, or submit a PAIA request — see our PAIA manual. We may charge the prescribed fee and must verify your identity first.
- Have it corrected or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. Use POPIA Form 2 (Request for Correction or Deletion).
- Object to processing that we base on legitimate interest, on reasonable grounds relating to your situation. Use POPIA Form 1 (Objection to the Processing of Personal Information). If you object, we must stop processing your information on that basis.
- Withdraw consent, where we relied on your consent.
- Not be subject to a decision based solely on automated processing that has legal consequences for you, as section 71 provides.
- Complain to the Information Regulator — see section 15.
- Institute civil proceedings in a court of competent jurisdiction.
Send any request to our Information Officer using the details in section 14. We will respond within the period the law allows. Exercising these rights costs you nothing, except any prescribed fee for copies of records.
Note on form numbers. PAIA and POPIA each have their own numbered forms and they are not the same. A request for access to a record uses PAIA Form 02. Objection and correction use POPIA Form 1 and Form 2. Current versions of all of them are on the Information Regulator's website.
14. Information Officer
Direct any privacy question, request or complaint to:
- Information Officer
- Ruan Petrus Greeff
- Position
- Director
- admin@thebigdatashowroom.com
- Telephone
- 021 007 5899
- Address
- Available upon request
- Regulator ref.
- 2026-001232, registered 29 January 2026
Full details are on our Information Officer page.
15. Complaints to the Information Regulator
If you are not satisfied with how we have handled your information or your request, you may complain to the Information Regulator (South Africa). You do not have to come to us first, though we would prefer the chance to put it right.
- Address
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- Telephone
- 010 023 5200
- Toll-free
- 0800 017 160
- General
- enquiries@inforegulator.org.za
- POPIA complaints
- POPIAComplaints@inforegulator.org.za
- PAIA complaints
- PAIAComplaints@inforegulator.org.za
- Website
- inforegulator.org.za
A POPIA complaint uses POPIA Form 5, and complaints are generally lodged through the Regulator's eServices Portal.
16. Changes to this notice
We update this notice when our processing changes or the law does. The current version and its effective date are shown at the top of this page. Material changes affecting our clients are notified by email to the account's registered address.