Healthcare access across South Africa
DropDr
Data protection

POPIA notice

How DropDr applies the Protection of Personal Information Act, who our Information Officer is, and how to exercise your rights.

Drop Doctor (Pty) Ltd Last updated: 16 September 2026 Applies to drop-dr.com and the DropDr applications

What POPIA is

The Protection of Personal Information Act 4 of 2013 is South Africa's data protection law. It sets out eight conditions for lawful processing of personal information and gives people enforceable rights over information held about them.

It matters particularly here because health information is "special personal information" under section 26 and carries a higher standard of protection than ordinary personal information.

Information Officer

Under POPIA, the head of a private body is automatically its Information Officer. For Drop Doctor (Pty) Ltd, that is Jean Claude Loh, in their capacity as director.

The Information Officer is responsible for encouraging compliance, dealing with requests, working with the Information Regulator, and ensuring a compliance framework is in place.

Information Officer
Jean Claude Loh
Organisation
Drop Doctor (Pty) Ltd
Registration number
2025/521876/07
Address
1st Floor, Office 2, 96 Jorissen Street, Braamfontein, Johannesburg, 2001

The eight conditions, and how we apply them

1. Accountability

We take responsibility for the information we process and for the service providers who process it on our behalf under written agreement.

2. Processing limitation

We collect the minimum needed for each purpose, with a lawful basis — your consent, the performance of a contract with you, or a legal obligation.

3. Purpose specification

Information is collected for the specific purposes set out in our privacy policy, and retained only as long as those purposes or the law require.

4. Further processing limitation

We do not use information for a new purpose incompatible with the one it was collected for.

5. Information quality

We take reasonable steps to keep information accurate and current, and you can correct your own details in the app.

6. Openness

We publish this notice and our privacy policy, and we tell you what we collect and why.

7. Security safeguards

Encryption in transit and at rest, role-based access, audit logging, written agreements with operators, and incident response procedures including breach notification.

8. Data subject participation

You may request access to your information, request correction or deletion, and complain to us and then to the Information Regulator.

Special personal information

Health information is special personal information. Section 26 prohibits processing it unless section 27 or section 32 applies. We rely on:

  • Section 32(1)(a) — processing by medical professionals, healthcare institutions or facilities, where it is necessary for the proper treatment and care of the person, or for the administration of the institution.
  • Your consent, given when you create an account and when you book a consultation.

Practically, this means health information is confined to the application, visible to the professional you consult and to you, shared further only where you permit it, and logged when accessed.

Obligations on healthcare professionals

Healthcare professionals on DropDr are responsible parties in their own right for the clinical information they record. As part of onboarding each professional accepts a data processing agreement setting out their obligations, which include:

  • Processing patient information only for the purpose of providing care.
  • Not copying, screenshotting, exporting or retaining patient information outside the platform except as their professional record-keeping duties require.
  • Not discussing identifiable patient information through unsecured channels.
  • Maintaining the confidentiality obligations their registering body imposes.
  • Reporting any suspected breach to DropDr without delay.

Making a request

To request access to your information, to correct it, or to ask for deletion, email info@drop-dr.com with enough detail for us to identify you and to understand what you are asking for.

We may ask you to verify your identity before we act. This is a protection for you: acting on an unverified request about health information would itself be a serious breach.

Requests are handled within the periods the law allows. Some information cannot be deleted on request because retention is legally required, and where that applies we will tell you.

If something goes wrong

Where a security compromise affects personal information, we will notify the Information Regulator and the affected people as soon as reasonably possible after establishing the extent of the compromise, as section 22 requires.

The Cybercrimes Act 19 of 2020 separately obliges electronic communications service providers to report certain offences to the South African Police Service within 72 hours of becoming aware of them. We comply with that obligation.

The Information Regulator

If you are not satisfied with how we have handled your personal information or your request, you may complain to the Information Regulator of South Africa.

The Regulator publishes its current contact details and complaint forms on its website. We encourage you to raise the matter with our Information Officer first, because most issues are resolved faster that way.