GDPR Privacy Statement
This statement explains AO's approach where the European Union General Data Protection Regulation applies to a relevant AO entity or processing activity.
GDPR does not necessarily apply to every interaction with every AO entity. The applicable law depends on the entity, location, processing activity and relationship involved.
Statement in preparation
Final approved GDPR statement pending publication. Contact info@aogroup.co.za for assistance.
Principles that guide our approach
Where GDPR applies, AO's approach is guided by principles including:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
What the approved statement will cover
The formally approved GDPR Privacy Statement will address the following matters. Entity-specific detail is not published until it has been verified.
- 01Scope
- 02Controller identity
- 03Contact details
- 04Categories of personal data
- 05Processing purposes
- 06Lawful bases
- 07Recipients
- 08International transfers
- 09Retention
- 10Data-subject rights
- 11Complaints
- 12Automated decision-making
- 13Document version and effective date
Lawful bases, recipients, transfer mechanisms, EU representative details and supervisory-authority details are entity- and activity-specific. AO will confirm the applicable detail on request while the statement is being finalised.
Exercising rights under GDPR
Where GDPR applies, individuals may have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent where processing relies on consent. These rights are not absolute and may be limited by legal, contractual, regulatory or evidential requirements.
Individuals may also have the right to lodge a complaint with the relevant supervisory authority.
