Privacy & POPIA Compliance
Caliper is fully compliant with South Africa's Protection of Personal Information Act (POPIA). This guide explains your privacy rights, data protection features, and how schools demonstrate compliance.
🎥 Video Tutorial: Complete Privacy Walkthrough
Watch this comprehensive guide showing all privacy features:
What's covered:
- Privacy Settings and consent controls
- Consent Management and history
- My Data - what information is collected
- Processing History - complete audit trail
Privacy Settings Overview
The Privacy Settings page provides complete transparency and control over your personal data
Four Core Privacy Features
Caliper provides four comprehensive tabs for managing your privacy:
- 🔒 Privacy Settings - Control your privacy preferences
- 📋 Consent Management - View and manage your consent choices
- 💾 My Data - See exactly what data is collected
- 📊 Processing History - Complete audit trail of all data processing
1. Privacy Settings Tab
Privacy Preferences You Control
✅ Allow AI Processing
- Purpose: Enable AI-powered automated marking
- Protection: Personal information is anonymized before AI processing
- Transparency: You control whether AI can mark your submissions
- Compliance: Meets POPIA's requirement for explicit consent
📊 Performance Analytics
- Purpose: Generate class and individual performance analytics
- Protection: Data is anonymized for analytics
- Benefit: Helps identify learning gaps and track progress
- Control: Can be disabled at any time
🔬 Educational Research
- Purpose: Improve teaching methods through research
- Protection: All data fully anonymized
- Voluntary: Completely optional - not required for platform use
- Ethical: Used only for educational improvement
Data Retention Preference
Choose how long your data should be retained:
- Minimum (Delete as soon as legally allowed)
- Standard (Retain for academic year + 1 year)
- Extended (Keep for educational records)
This gives you control over your digital footprint.
2. Consent Management Tab
What You'll See
- Current Consents: Active consents with dates
- Consent History: Complete timeline of all consent changes
- Consent Types:
- Essential Processing (required)
- School Data Sharing (required)
- AI Processing (optional)
- Performance Analytics (optional)
- Educational Research (optional)
Your Rights
✅ Right to Withdraw: Withdraw non-essential consents anytime ✅ Right to Know: See exactly what you've consented to ✅ Right to History: Complete audit trail of consent changes ✅ Right to Transparency: Clear explanations for each consent type
For School Leadership
POPIA Compliance Evidence:
- Timestamped consent records
- Proof of informed consent
- Audit trail for inspections
- Withdrawal tracking
This provides documented proof of POPIA compliance for school audits.
3. My Data Tab
Complete Data Transparency
See exactly what personal information Caliper stores:
Personal Information
- Name and username
- School email address
- Student/Teacher ID
- Class enrollment
- Role (Learner/Teacher)
Academic Information
- Assignment submissions
- Grades and scores
- Teacher feedback
- Rubric assessments
- Submission timestamps
Activity Information
- Login history
- Page views (anonymized)
- Submission activity
- Feature usage (anonymized)
AI Processing Data
- Anonymized submission analysis
- AI marking results (linked to your work)
- Performance patterns (anonymized)
Why This Matters
For Learners: Complete transparency builds trust For Teachers: Know what student data you can access For Schools: Demonstrate POPIA's transparency requirement For Audits: Show exactly what data is collected and why
4. Processing History Tab
Complete Audit Trail
Every data processing activity is logged:
What's Logged
- Action: What was done (submission uploaded, grade assigned, etc.)
- Timestamp: Exact date and time
- Purpose: Why the processing occurred
- Legal Basis: POPIA lawful basis (consent, legitimate interest, etc.)
- Data Categories: What types of data were processed
- Result: Outcome of the processing
Sample Processing Events
Event: Submission Uploaded
Time: 2025-06-15 14:23:45
Purpose: Assignment submission for Gr 11 CAT PAT Task 1
Legal Basis: Consent + Educational Purpose
Data: File content, metadata, timestamp
Result: Successfully stored, backup created
Event: AI Marking Requested
Time: 2025-06-16 09:12:03
Purpose: Automated marking with anonymization
Legal Basis: AI Processing Consent
Data: Anonymized submission content
Result: Grade assigned, feedback generated
Event: Teacher Viewed Submission
Time: 2025-06-16 10:45:12
Purpose: Manual review and feedback
Legal Basis: Educational Purpose + School Data Sharing Consent
Data: Submission file, student name, grade
Result: Teacher comment added
Why Processing History Matters
🛡️ For POPIA Compliance:
- Proves lawful processing
- Demonstrates purpose limitation
- Shows data minimization
- Provides accountability
📋 For School Audits:
- Complete evidence for inspections
- Answers "Who accessed what, when, and why?"
- Demonstrates responsible data handling
- Protects school from liability
🎓 For Academic Integrity:
- Tracks all grade changes
- Proves fair assessment
- Prevents disputes
- Maintains trust
POPIA Compliance Summary
How Caliper Meets POPIA Requirements
1. Accountability
✅ Designated Information Officer ✅ Data protection policies ✅ Regular compliance audits ✅ Staff training on POPIA
2. Processing Limitation
✅ Clear, specific purposes ✅ Only process necessary data ✅ No excessive data collection ✅ Purpose documented in Processing History
3. Purpose Specification
✅ Transparent purposes (education, assessment, analytics) ✅ Communicated at consent time ✅ No "mission creep" - data used only as stated ✅ Changes require new consent
4. Further Processing Limitation
✅ Data not reused for unrelated purposes ✅ New purposes require new consent ✅ All processing logged in history ✅ Compatible use only (e.g., educational research)
5. Information Quality
✅ Data kept accurate and up-to-date ✅ Students/teachers can update info ✅ Outdated data deleted per retention policy ✅ Regular data quality checks
6. Openness
✅ Privacy Policy clearly accessible ✅ "My Data" tab shows all collected data ✅ Processing History provides full transparency ✅ Contact info for privacy questions
7. Security Safeguards
✅ HTTPS encryption (TLS) ✅ Hashed passwords ✅ Access controls (role-based) ✅ Regular security audits ✅ Backup and disaster recovery
8. Data Subject Participation
✅ Access your data (My Data tab) ✅ Correct inaccuracies (update profile) ✅ Withdraw consent (Consent Management) ✅ Request deletion (contact support) ✅ Object to processing (Privacy Settings)
For School Leadership
Demonstrating POPIA Compliance to Authorities
When audited or inspected, use Caliper's privacy features to demonstrate compliance:
1. Show Consent Records
- Navigate to Consent Management tab
- Export consent logs for all students
- Show timestamped, informed consent
- Demonstrate withdrawal options
2. Prove Data Transparency
- Show My Data tab to inspector
- Demonstrate what data is collected
- Explain purpose for each data type
- Show data minimization practices
3. Provide Audit Trail
- Display Processing History
- Show lawful basis for each processing activity
- Demonstrate purpose limitation
- Prove accountability
4. Evidence of Security
- Point to HTTPS encryption in browser
- Show role-based access controls
- Demonstrate backup systems
- Explain anonymization for AI/analytics
For Teachers: Privacy Best Practices
✅ Respect Student Privacy
- Only access data needed for teaching
- Don't share student work publicly without consent
- Use AI marking responsibly
- Report privacy concerns immediately
✅ Maintain Confidentiality
- Keep grades private
- Don't discuss student data outside school
- Log out on shared devices
- Use secure passwords
✅ Support Student Rights
- Help students understand privacy settings
- Encourage students to review their data
- Respect consent withdrawals
- Answer privacy questions honestly
Frequently Asked Questions
Can I see all my data?
Yes. The My Data tab shows every piece of personal information Caliper stores about you.
Can I delete my data?
Yes. Contact your teacher or email info@restrat.co.za to request deletion after you complete your studies (subject to legal retention requirements).
Is my data shared with third parties?
Limited. Your submission content is sent to Anthropic's Claude AI for marking (anonymized). No other third-party sharing occurs without explicit consent.
What happens if I withdraw consent?
- Essential consents: Cannot withdraw (required for platform use)
- Optional consents: Withdraw anytime, takes effect immediately
- No penalties: Withdrawing optional consent doesn't affect grades or access
Who can see my submissions?
- Your teachers: Yes (with School Data Sharing consent)
- School admins: Yes (educational administration)
- AI system: Yes (anonymized, if AI Processing consent given)
- Other students: No
- Public: No
How long is my data kept?
According to your Data Retention Preference:
- Minimum: 1 year after course completion
- Standard: Academic year + 1 year
- Extended: 7 years (for academic records)
Legal requirements may override shorter retention periods.
Is Caliper POPIA certified?
Caliper is POPIA compliant as verified by legal counsel. POPIA doesn't offer "certification" but requires ongoing compliance, which Caliper demonstrates through its privacy features.
Can schools be fined for POPIA violations?
Yes. The Information Regulator can impose fines up to R10 million or 10 years imprisonment for serious violations. Caliper helps schools avoid this by ensuring compliance.
Getting Help with Privacy
For Students
- 📧 Email: info@restrat.co.za
- 👨🏫 Teacher: Ask your teacher in class
- 📖 Privacy Policy: View Full Policy
For Teachers
- 📧 Email: info@restrat.co.za
- 🏫 School Admin: Contact your school's Caliper administrator
- ⚖️ Legal Questions: Consult school's legal counsel
For School Leadership
- 📧 Compliance Support: info@restrat.co.za
- 📋 Audit Assistance: Request compliance documentation
- ⚖️ Information Regulator: https://inforegulator.org.za
Related Resources
- First-Time Login & POPIA Consent - Accept consent on first login
- Learner Quick Start - Complete learner guide
- Platform Tour - Explore all features
Caliper's privacy features ensure full compliance with the Protection of Personal Information Act, protecting students, teachers, and schools.