Skip to main content

Privacy & POPIA Compliance

Caliper is fully compliant with South Africa's Protection of Personal Information Act (POPIA). This guide explains your privacy rights, data protection features, and how schools demonstrate compliance.

🎥 Video Tutorial: Complete Privacy Walkthrough

Watch this comprehensive guide showing all privacy features:

What's covered:

  • Privacy Settings and consent controls
  • Consent Management and history
  • My Data - what information is collected
  • Processing History - complete audit trail

Privacy Settings Overview

Privacy Settings The Privacy Settings page provides complete transparency and control over your personal data

Four Core Privacy Features

Caliper provides four comprehensive tabs for managing your privacy:

  1. 🔒 Privacy Settings - Control your privacy preferences
  2. 📋 Consent Management - View and manage your consent choices
  3. 💾 My Data - See exactly what data is collected
  4. 📊 Processing History - Complete audit trail of all data processing

1. Privacy Settings Tab

Privacy Preferences You Control

✅ Allow AI Processing

  • Purpose: Enable AI-powered automated marking
  • Protection: Personal information is anonymized before AI processing
  • Transparency: You control whether AI can mark your submissions
  • Compliance: Meets POPIA's requirement for explicit consent

📊 Performance Analytics

  • Purpose: Generate class and individual performance analytics
  • Protection: Data is anonymized for analytics
  • Benefit: Helps identify learning gaps and track progress
  • Control: Can be disabled at any time

🔬 Educational Research

  • Purpose: Improve teaching methods through research
  • Protection: All data fully anonymized
  • Voluntary: Completely optional - not required for platform use
  • Ethical: Used only for educational improvement

Data Retention Preference

Choose how long your data should be retained:

  • Minimum (Delete as soon as legally allowed)
  • Standard (Retain for academic year + 1 year)
  • Extended (Keep for educational records)

This gives you control over your digital footprint.


What You'll See

  • Current Consents: Active consents with dates
  • Consent History: Complete timeline of all consent changes
  • Consent Types:
    • Essential Processing (required)
    • School Data Sharing (required)
    • AI Processing (optional)
    • Performance Analytics (optional)
    • Educational Research (optional)

Your Rights

Right to Withdraw: Withdraw non-essential consents anytime ✅ Right to Know: See exactly what you've consented to ✅ Right to History: Complete audit trail of consent changes ✅ Right to Transparency: Clear explanations for each consent type

For School Leadership

POPIA Compliance Evidence:

  • Timestamped consent records
  • Proof of informed consent
  • Audit trail for inspections
  • Withdrawal tracking

This provides documented proof of POPIA compliance for school audits.


3. My Data Tab

Complete Data Transparency

See exactly what personal information Caliper stores:

Personal Information

  • Name and username
  • School email address
  • Student/Teacher ID
  • Class enrollment
  • Role (Learner/Teacher)

Academic Information

  • Assignment submissions
  • Grades and scores
  • Teacher feedback
  • Rubric assessments
  • Submission timestamps

Activity Information

  • Login history
  • Page views (anonymized)
  • Submission activity
  • Feature usage (anonymized)

AI Processing Data

  • Anonymized submission analysis
  • AI marking results (linked to your work)
  • Performance patterns (anonymized)

Why This Matters

For Learners: Complete transparency builds trust For Teachers: Know what student data you can access For Schools: Demonstrate POPIA's transparency requirement For Audits: Show exactly what data is collected and why


4. Processing History Tab

Complete Audit Trail

Every data processing activity is logged:

What's Logged

  • Action: What was done (submission uploaded, grade assigned, etc.)
  • Timestamp: Exact date and time
  • Purpose: Why the processing occurred
  • Legal Basis: POPIA lawful basis (consent, legitimate interest, etc.)
  • Data Categories: What types of data were processed
  • Result: Outcome of the processing

Sample Processing Events

Event: Submission Uploaded
Time: 2025-06-15 14:23:45
Purpose: Assignment submission for Gr 11 CAT PAT Task 1
Legal Basis: Consent + Educational Purpose
Data: File content, metadata, timestamp
Result: Successfully stored, backup created

Event: AI Marking Requested
Time: 2025-06-16 09:12:03
Purpose: Automated marking with anonymization
Legal Basis: AI Processing Consent
Data: Anonymized submission content
Result: Grade assigned, feedback generated

Event: Teacher Viewed Submission
Time: 2025-06-16 10:45:12
Purpose: Manual review and feedback
Legal Basis: Educational Purpose + School Data Sharing Consent
Data: Submission file, student name, grade
Result: Teacher comment added

Why Processing History Matters

🛡️ For POPIA Compliance:

  • Proves lawful processing
  • Demonstrates purpose limitation
  • Shows data minimization
  • Provides accountability

📋 For School Audits:

  • Complete evidence for inspections
  • Answers "Who accessed what, when, and why?"
  • Demonstrates responsible data handling
  • Protects school from liability

🎓 For Academic Integrity:

  • Tracks all grade changes
  • Proves fair assessment
  • Prevents disputes
  • Maintains trust

POPIA Compliance Summary

How Caliper Meets POPIA Requirements

1. Accountability

✅ Designated Information Officer ✅ Data protection policies ✅ Regular compliance audits ✅ Staff training on POPIA

2. Processing Limitation

✅ Clear, specific purposes ✅ Only process necessary data ✅ No excessive data collection ✅ Purpose documented in Processing History

3. Purpose Specification

✅ Transparent purposes (education, assessment, analytics) ✅ Communicated at consent time ✅ No "mission creep" - data used only as stated ✅ Changes require new consent

4. Further Processing Limitation

✅ Data not reused for unrelated purposes ✅ New purposes require new consent ✅ All processing logged in history ✅ Compatible use only (e.g., educational research)

5. Information Quality

✅ Data kept accurate and up-to-date ✅ Students/teachers can update info ✅ Outdated data deleted per retention policy ✅ Regular data quality checks

6. Openness

✅ Privacy Policy clearly accessible ✅ "My Data" tab shows all collected data ✅ Processing History provides full transparency ✅ Contact info for privacy questions

7. Security Safeguards

✅ HTTPS encryption (TLS) ✅ Hashed passwords ✅ Access controls (role-based) ✅ Regular security audits ✅ Backup and disaster recovery

8. Data Subject Participation

✅ Access your data (My Data tab) ✅ Correct inaccuracies (update profile) ✅ Withdraw consent (Consent Management) ✅ Request deletion (contact support) ✅ Object to processing (Privacy Settings)


For School Leadership

Demonstrating POPIA Compliance to Authorities

When audited or inspected, use Caliper's privacy features to demonstrate compliance:

  • Navigate to Consent Management tab
  • Export consent logs for all students
  • Show timestamped, informed consent
  • Demonstrate withdrawal options

2. Prove Data Transparency

  • Show My Data tab to inspector
  • Demonstrate what data is collected
  • Explain purpose for each data type
  • Show data minimization practices

3. Provide Audit Trail

  • Display Processing History
  • Show lawful basis for each processing activity
  • Demonstrate purpose limitation
  • Prove accountability

4. Evidence of Security

  • Point to HTTPS encryption in browser
  • Show role-based access controls
  • Demonstrate backup systems
  • Explain anonymization for AI/analytics

For Teachers: Privacy Best Practices

Respect Student Privacy

  • Only access data needed for teaching
  • Don't share student work publicly without consent
  • Use AI marking responsibly
  • Report privacy concerns immediately

Maintain Confidentiality

  • Keep grades private
  • Don't discuss student data outside school
  • Log out on shared devices
  • Use secure passwords

Support Student Rights

  • Help students understand privacy settings
  • Encourage students to review their data
  • Respect consent withdrawals
  • Answer privacy questions honestly

Frequently Asked Questions

Can I see all my data?

Yes. The My Data tab shows every piece of personal information Caliper stores about you.

Can I delete my data?

Yes. Contact your teacher or email info@restrat.co.za to request deletion after you complete your studies (subject to legal retention requirements).

Is my data shared with third parties?

Limited. Your submission content is sent to Anthropic's Claude AI for marking (anonymized). No other third-party sharing occurs without explicit consent.

  • Essential consents: Cannot withdraw (required for platform use)
  • Optional consents: Withdraw anytime, takes effect immediately
  • No penalties: Withdrawing optional consent doesn't affect grades or access

Who can see my submissions?

  • Your teachers: Yes (with School Data Sharing consent)
  • School admins: Yes (educational administration)
  • AI system: Yes (anonymized, if AI Processing consent given)
  • Other students: No
  • Public: No

How long is my data kept?

According to your Data Retention Preference:

  • Minimum: 1 year after course completion
  • Standard: Academic year + 1 year
  • Extended: 7 years (for academic records)

Legal requirements may override shorter retention periods.

Is Caliper POPIA certified?

Caliper is POPIA compliant as verified by legal counsel. POPIA doesn't offer "certification" but requires ongoing compliance, which Caliper demonstrates through its privacy features.

Can schools be fined for POPIA violations?

Yes. The Information Regulator can impose fines up to R10 million or 10 years imprisonment for serious violations. Caliper helps schools avoid this by ensuring compliance.


Getting Help with Privacy

For Students

For Teachers

  • 📧 Email: info@restrat.co.za
  • 🏫 School Admin: Contact your school's Caliper administrator
  • ⚖️ Legal Questions: Consult school's legal counsel

For School Leadership



POPIA Compliant ✅

Caliper's privacy features ensure full compliance with the Protection of Personal Information Act, protecting students, teachers, and schools.