← All guides
Guide

POPIA and Public Procurement: How Your Company Data Should Be Handled

The Protection of Personal Information Act (POPIA) applies whenever a business or tool processes personal information — including a sole proprietor's ID number, a director's contact details, or an employee's data submitted as part of a tender bid. Understanding what POPIA actually requires helps you evaluate any tool, including ours, that asks for your company profile.

What POPIA requires from a processor

A business processing your information — including a tender-matching platform — must have a lawful basis for processing (typically your explicit consent), must use the information only for the stated purpose, must not sell or share it with third parties beyond what you consented to, and must take reasonable technical measures to keep it secure.

What this means in practice for a bidder

When you provide your CIDB grade, CSD number, or compliance status to a matching tool, that information should be used only to match you against tenders and check your qualification — never resold, never shared with competing bidders, and never repurposed for unrelated marketing without a separate, explicit consent. Any legitimate procurement tool should be able to state this plainly, not bury it in unreadable legal text.

Check your own tender qualification