South Africa Privacy Centre

Data Processing Policy

Introduction

 

TransUnion is a credit bureau registered in accordance with the National Credit Act 34 of 2005 (Registration Number NCRCB4). Its operations are regulated by the NCA and other applicable laws, including the Protection of Personal Information Act 4 of 2013 (POPIA).

TransUnion is committed to protecting the integrity, confidentiality and security of all Personal Information processed in the course of its operations and is sensitive to privacy considerations.

TransUnion is a member of the following industry bodies:

  • Credit Bureau Association (“CBA”): A voluntary industry body promoting fair practice, transparency, accountability, and high-quality credit reporting. TransUnion complies with the CBA Code of Conduct issued under POPIA.
  • South African Credit and Risk Reporting Association (“SACRRA”): A voluntary association facilitating the lawful sharing of payment profile information to support credit risk assessment and affordability calculations.

TransUnion conducts its operations in compliance with applicable laws and industry standards. Entities interacting with TransUnion are required to uphold equivalent standards when processing Personal Information.

 

This notice covers the following topics:

  1. Purpose
  2. Scope and Application
  3. Definitions
  4. Compliance with Laws
  5. Information Security
  6. Lawful Basis and Consent
  7. Submission and Quality of Information
  8. Use of Information
  9. Protection of Personal Information
  10. Data Breach Notification
  11. Retention and Disposal
  12. Confidentiality
  13. Payment Profile Information
  14. Removal of Adverse Credit Information
  15. Information relating to Juristic Persons and their Principals
  16. Contact and Queries
  17. Policy Updates

 

1.  Purpose

 

This policy outlines the requirements and standards for the lawful processing, protection, and secure handling of Personal Information shared with or obtained from TransUnion.

 

2.  Scope and Application

 

1.  This policy applies to:

a. TransUnion, including its employees, contractors, and internal operations that handle personal information; and  

b. all external organisations that access, use, process, or provide personal information to or from TransUnion (whether directly or through an authorised TransUnion partner or reseller) (“Applicable Parties”).

2. This policy sets out the minimum standards for how personal information must be handled and protected. For external parties, this policy forms part of the terms under which they work with TransUnion and must be read together with any agreement in place.  

3. If an Applicable Party does not comply with this policy, this may be treated as a breach of their agreement with TransUnion and may be dealt with in terms of that agreement and applicable law.

4. This policy continues to apply for as long as TransUnion or any Applicable Party holds or uses personal information, even if the commercial relationship has ended.

5. If there is any conflict between this policy and another agreement between TransUnion and an Applicable Party, this policy will apply to matters relating to how personal information is handled, unless the law requires otherwise.

 

3.  Definitions

 

Key terms used in this policy include:

  1. “Data Subject” means any person (both individual and juristic entity and/or the like) to whom the specific Personal Information relates, as contemplated in POPIA;
  2. “Laws” means all laws, regulations, by-laws, rules, directives, guidelines, circulars, orders and other requirements of any government or any government agency, body or authority, including any regulator or court;
  3. “NCA” means the National Credit Act No. 34 of 2005 together with the Regulations, as amended from time to time;
  4. “Operator” has the meaning set out in POPIA and for purposes of this policy means the Party who Processes Personal Information on behalf of the other Party or any authorised subcontractor of either of the Parties;
  5. “PAIA” means the Promotion of Information Access to Information Act 2 of 2000, together with the Regulations, as amended from time to time;
  6. “Party” or “Parties” means either the Applicable Party or TransUnion or both, as the context may require;
  7. “Payment Profile Information” means the payment history and financial information relating to a debt or credit transaction, including relevant payment dates, both negative and positive information and/or signs depicting action taken in respect of such debt or credit transaction;
  8. “Personal Information” shall have the meaning set out in section 1 of POPIA, and includes special personal information as defined in section 26 of POPIA and relates to the Personal Information of which either Party is the Responsible Party in relation to which TransUnion renders the services to the Applicable Party;
  9. “POPIA” means Protection of Personal Information Act No. 4 of 2013 together with the Regulations, as amended from time to time;
  10. “Processing” or “Process” shall have the meaning set out in POPIA;
  11. “Regulations” means the National Credit Regulations promulgated in terms of the NCA and POPIA from time to time;
  12. “Responsible Party” shall have the meaning ascribed thereto in POPIA, and for purposes of this Agreement shall mean either Party as the context may require;
  13. “TransUnion” means TransUnion Africa (Pty) Limited, registration number 1992/007124/07, a private company with limited liability, as well as all subsidiaries thereof, including TransUnion Credit Bureau, registration number 2004/007773/04, duly registered with the NCR (under registration number NCRCB4).

 

4.  Compliance with Laws

 

When processing personal information or using TransUnion’s services, TransUnion and Applicable Parties must comply with all legal and regulatory requirements relating to the collection, handling, and reporting of personal information. This includes compliance with the National Credit Act and any other applicable laws, regulations, and industry standards.

 

5.  Information Security

 

TransUnion is committed to protecting Personal Information and has implemented appropriate technical and organisational measures to safeguard it against unauthorised access, loss, misuse, or damage.  

These measures include controls to restrict access to authorised individuals and to protect systems and information from security risks. Where third parties process Personal Information on behalf of TransUnion, they are required to apply appropriate security standards and safeguards.  

If a security incident occurs that affects Personal Information, TransUnion will take appropriate steps to investigate, contain, and address the incident in accordance with applicable laws.

 

6.  Lawful Basis and Consent

 

TransUnion processes Personal Information in a lawful and fair manner in accordance with the National Credit Act (NCA) and the Protection of Personal Information Act (POPIA).  

Where required, TransUnion ensures that appropriate consent is obtained before processing takes place and that such consent is retained in line with applicable legal requirements.  

For ongoing services, TransUnion takes steps to ensure that any required consent remains valid and up to date.

 

7. Submission and Quality of Information

 

1. TransUnion and all parties processing Personal Information must ensure that any information collected, used, or submitted is:

  • Accurate, complete, and up to date  
  • Not duplicated or misleading  
  • Processed lawfully and with proper authorisation  
  • Limited to categories of information permitted by applicable law

 

2. Where information is submitted to TransUnion or used for credit reporting purposes, additional requirements apply:

  • Only information permitted in terms of the National Credit Act may be submitted
  • Data must meet required minimum standards and reporting criteria
  • All submissions must comply with applicable legal and regulatory requirements  

 

3. The following types of information must not be submitted to TransUnion:

  • Prescribed debt
  • Duplicate or erroneous listings
  • Unresolved disputed information
  • Restricted categories as defined by law
  • Information that has previously been successfully challenged and removed  

All parties must take reasonable steps to ensure data accuracy and must cooperate in resolving disputes and correcting any inaccurate information.

 

8.  Use of Information

 

Personal Information is used responsibly and in accordance with applicable laws, including the National Credit Act (NCA) and the Protection of Personal Information Act (POPIA).  

Personal Information must:

  • Be used only for lawful and authorised purposes, such as providing services, assessing credit, or meeting legal obligations
  • Be limited to the specific purpose for which it was collected and not used in a way that is incompatible with that purpose
  • Not be sold or shared with third parties for unrelated or unauthorised purposes  

TransUnion takes steps to ensure that Personal Information is handled in a fair and responsible manner at all times.

In limited circumstances, credit information may be accessed for employment purposes. This will only take place where:

  • The individual has given their consent; and
  • The position being applied for requires a high level of trust, particularly where the role involves handling money or financial responsibilities  

Such checks are carried out in accordance with applicable legal requirements and are only undertaken where relevant and appropriate.

 

9.  Protection of Personal Information

 

TransUnion is committed to protecting Personal Information and ensuring that it is handled responsibly and securely. Personal Information is only processed for authorised and lawful purposes and access to such information is limited to individuals who require it to perform their roles.  

TransUnion takes appropriate steps to maintain the confidentiality of Personal Information and to protect it against unauthorised access, loss, or misuse through the use of appropriate safeguards.  

Where third parties process Personal Information on behalf of TransUnion, they are required to meet appropriate data protection and privacy standards.

TransUnion also supports individuals in exercising their rights under applicable laws, including the right to access, correct, or raise concerns regarding their Personal Information, and will cooperate with regulatory requirements where necessary.

 

10.  Data Breach Notification

 

TransUnion takes the protection of Personal Information seriously and has measures in place to identify, manage, and respond to any security incidents that may affect such information. 

If a security incident occurs, TransUnion will take appropriate steps to investigate the incident, contain it, and minimise any potential impact on affected individuals. This may include securing systems, reviewing what information was affected, and taking steps to prevent a recurrence. 

Where required by law, TransUnion will notify affected individuals and relevant regulators in accordance with POPIA and other applicable requirements.

TransUnion remains committed to handling any such incidents responsibly and transparently, and to supporting affected individuals where appropriate.

 

11.  Retention and Disposal

 

TransUnion retains Personal Information only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable laws and regulatory obligations.

Once Personal Information is no longer required, TransUnion takes appropriate steps to ensure that it is securely deleted, destroyed, or de-identified in a manner that protects privacy and prevents unauthorised access.

 

12.  Confidentiality

 

TransUnion treats Personal Information as confidential and takes appropriate steps to protect it from unauthorised access, disclosure, or misuse.  

Access to Personal Information is limited to authorised individuals who require it to perform their roles.  

TransUnion remains committed to maintaining the confidentiality of Personal Information, even after its relationship with an individual or organisation has ended, where required by law.

 

13.  Payment Profile Information

 

Payment Profile Information refers to information about a consumer’s payment behaviour and credit activity, which may be shared between credit providers and credit bureaus.  

TransUnion processes and provides access to Payment Profile Information in accordance with the National Credit Act (NCA), applicable regulatory guidelines, and recognised industry standards, including those set by the South African Credit and Risk Reporting Association (SACRRA).  

Access to this information is limited to authorised organisations that are legally permitted to receive it, and only for lawful purposes such as credit assessments and risk management.  

Where Payment Profile Information is shared with or received from third parties, this is done in line with applicable legal and regulatory requirements to ensure accuracy, fairness, and responsible use.

 

14.  Removal of Adverse Credit Information

 

TransUnion processes adverse credit information in accordance with the National Credit Act (NCA) and applicable regulatory requirements. Adverse credit information relating to a debt will be removed from a person’s credit profile once the debt has been settled, in line with the requirements of the NCA.  

Similarly, judgments may be removed from a person’s credit profile once the capital amount of the judgment has been settled, in accordance with applicable legal requirements.  

Adverse listings are only removed where permitted by law, including where the information is found to be incorrect, fraudulent, or duplicated.  

TransUnion does not permit the removal of adverse credit information outside of lawful processes and does not support the charging of upfront fees for the removal of such information unless allowed by law.

 

15.  Information Relating to Juristic Persons and their Principals

 

Where information is requested or processed in relation to a juristic person (such as a company or other business entity), the resulting report may include information about individuals associated with that entity, such as its directors, senior management, or key stakeholders (“Principals”).  

TransUnion processes such information in accordance with the National Credit Act (NCA) and other applicable laws.  

Where required, appropriate authorisation and consent must be obtained before information relating to such individuals is accessed or used.  

The inclusion and use of this information is subject to applicable legal requirements and is intended to support lawful credit and risk assessment processes.

 

16.  Contact and Queries

 

If you have any questions about this policy or how your Personal Information is processed, you may contact TransUnion using the following details:

  • Post: PO Box 4522, Johannesburg, 2000  
  • Telephone: Contact Centre: 0861 482 482  
  • Email: TUAPrivacy@transunion.com  

 

17.  Policy Updates

 

This policy may be updated from time to time to reflect changes in applicable laws, regulations, or industry practices.  

TransUnion will take reasonable steps to inform relevant stakeholders of any material changes to this policy. The latest version of this policy will always reflect the most recent effective date.

Effective date: 1 June 2026