Privacy Policy

Lancet Laboratories (“Lancet Laboratories”, “we”, “our” or “us”) is committed to protecting the privacy, confidentiality, integrity and security of Personal Information entrusted to us.

As a healthcare and pathology services provider, Lancet Laboratories processes Personal Information and Special Personal Information in the course of providing laboratory, diagnostic, healthcare support, digital platform, administrative and related services.

This Privacy Policy explains how Lancet Laboratories collects, processes, stores, shares, transfers, retains and protects Personal Information when individuals interact with:
• Lancet Laboratories websites
• Mobile applications
• Patient portals
• Clinician portals
• Laboratory services
• Customer support services
• Digital communication platforms
• Healthcare and pathology services and
• Other services operated by or on behalf of Lancet Laboratories.

This Privacy Policy is intended to ensure compliance with applicable legislation including:
• Protection of Personal Information Act 4 of 2013 (“POPIA”)
• Promotion of Access to Information Act 2 of 2000 (“PAIA”)
• National Health Act 61 of 2003.
• Electronic Communications and Transactions Act 25 of 2002.
• Applicable healthcare legislation.
• Applicable accreditation requirements.
• Regulatory requirements applicable to pathology laboratories and healthcare service providers.

2. DEFINITIONS
For purposes of this Policy:
2.1 Biometric Information
Means information relating to physical, physiological or behavioural characteristics capable of identifying an individual.
2.2 Child
Means a person under the age of 18 years.
2.3 Clinician
Means any registered healthcare practitioner, healthcare provider, pathologist, specialist, medical practitioner, nurse, allied healthcare professional or authorised healthcare user interacting with Lancet Laboratories systems or services.
2.4 Data Subject
Means the person to whom Personal Information relates.
2.5 Information Officer
Means the Information Officer appointed in terms of POPIA and PAIA.
2.6 Operator
Means a third party that processes Personal Information on behalf of Lancet Laboratories under mandate or agreement.
2.7 Personal Information
Means information relating to an identifiable, living natural person and where applicable an identifiable existing juristic person, including but not limited to:
• Names
• Identity numbers
• Passport numbers
• Contact details
• Addresses
• Demographic information
• Financial information
• Employment information
• Electronic identifiers
• Online identifiers
• Customer information

2.8 POPIA

Means the Protection of Personal Information Act 4 of 2013.
2.9 Processing
Means any operation concerning Personal Information including:
• Collection
• Receipt
• Recording
• Organisation
• Storage
• Updating
• Retrieval
• Use
• Dissemination
• Transmission
• Restriction
• Destruction; or
• Deletion
2.10 Special Personal Information
Means Personal Information concerning:
• Health information
• Genetic information
• Biometric information
• Race or ethnicity where legally permissible
• Information concerning children
• Other categories recognised by applicable legislation
2.11 Website
Means all websites, portals, applications, digital platforms and electronic services operated by or on behalf of Lancet Laboratories.

3. RESPONSIBLE PARTY
Lancet Laboratories acts as the Responsible Party for Personal Information processed through its websites, digital platforms, pathology services and related operations.
Information Officer: Simon Van Der Merwe
Email: [email protected]
Physical Address: 16 Napier Road, Richmond, Johannesburg 2092
All privacy-related enquiries, complaints, requests for access, correction, deletion or objection may be submitted to the Information Officer.

4. SCOPE OF APPLICATION
This Privacy Policy applies to:
Patients
Individuals receiving pathology or laboratory services.
Healthcare Professionals
Doctors, specialists, nurses, pathologists, allied healthcare professionals and authorised users of Lancet Laboratories services.
Website Users
Individuals accessing or browsing Lancet Laboratories websites.
Mobile Application Users
Users of Lancet Laboratories patient or clinician applications.
Portal Users
Users accessing patient or clinician portals.
Suppliers and Service Providers
Individuals acting on behalf of suppliers, vendors and contractors.
Prospective Employees
Applicants for employment opportunities.
Visitors
Visitors to Lancet Laboratories facilities and premises.

5. POPIA SECTION 18 COLLECTION NOTICE
In accordance with Section 18 of POPIA, Lancet Laboratories provides the following information to Data Subjects.
5.1 Collection of Personal Information
Lancet Laboratories collects Personal Information directly from Data Subjects and, where legally permitted, from third parties.
5.2 Purpose of Collection
Personal Information is collected for purposes including:
• Pathology testing
• Laboratory services
• Patient care
• Healthcare administration
• Medical aid processing
• Customer support
• Regulatory compliance
• Quality assurance
• Accreditation requirements
• Risk management
• Fraud prevention
• Legal obligations
• Website and platform management
5.3 Mandatory and Voluntary Information
Certain Personal Information is mandatory to enable Lancet Laboratories to provide healthcare services and comply with legal obligations.
Failure to provide mandatory information may result in Lancet Laboratories being unable to:
• Perform requested testing
• Verify identity
• Process medical aid claims
• Provide services
• Comply with legal obligations

Certain information may be provided voluntarily for:
• Website enquiries
• Feedback submissions
• Surveys
• Newsletters
• Communication preferences

5.4 Source of Information
Information may be collected:
• Directly from the Data Subject
• From healthcare providers
• Hospitals and clinics
• Medical schemes
• Authorised representatives
• Parents or guardians
• Employers where legally permitted
• Insurers
• Public authorities
• Publicly available sources where lawful
5.5 Recipients of Information
Personal Information may be disclosed to recipients identified in this Policy including healthcare providers, medical schemes, service providers, regulators and authorised third parties.
5.6 International Transfers
Personal Information may be transferred outside South Africa where appropriate safeguards exist and where such transfers comply with POPIA.
5.7 Rights of Data Subjects
Data Subjects have rights relating to:
• Access
• Correction
• Deletion where lawful
• Objection
• Restriction of processing
• Withdrawal of consent where applicable
• Complaints
These rights are described further in this Privacy Policy.

6. CATEGORIES OF PERSONAL INFORMATION COLLECTED
Lancet Laboratories may collect and process the following categories of Personal Information.
6.1 Identity Information
• Full names
• Identity numbers
• Passport numbers
• Date of birth
• Gender
• Nationality
6.2 Contact Information
• Residential addresses
• Postal addresses
• Email addresses
• Telephone numbers
• Mobile numbers
6.3 Healthcare Information
• Pathology requests
• Laboratory results
• Diagnostic information
• Healthcare practitioner details
• Specimen information
• Treatment-related information
• Clinical information relevant to testing
6.4 Financial Information
• Medical aid details
• Membership information
• Billing information
• Banking information
• Payment information
6.5 Technical Information
• IP addresses
• Browser information
• Device identifiers
• Operating systems
• Login activity
• Website usage information
6.6 Usage Information
• Pages viewed
• Downloads
• Portal activity
• Application usage
• Communication preferences

7. SPECIAL PERSONAL INFORMATION
As a healthcare and pathology provider, Lancet Laboratories may process Special Personal Information including:
• Pathology test results
• Histology information
• Cytology information
• Microbiology results
• Virology results
• Molecular pathology information
• HIV-related information
• Communicable disease information
• Genetic information
• DNA information
• Paternity testing information
• Kinship testing information
• Biometric information where applicable
• Information relating to children
• Occupational health information
• Disability information
• Healthcare-related information
Such information is processed only where authorised by law, necessary for healthcare services, required by regulation or otherwise permitted under POPIA.

8. CHILDREN’S INFORMATION
Lancet Laboratories may process information relating to children where:
• Authorised by a parent or legal guardian
• Required for healthcare services
• Permitted under applicable legislation
• Required for the protection of the child
Lancet Laboratories will take reasonable steps to ensure that appropriate consent and authorisation requirements are satisfied.

9. HOW INFORMATION IS COLLECTED
Personal Information may be collected through:
Direct Collection
• Registration forms
• Pathology request forms
• Websites
• Portals
• Mobile applications
• Customer service interactions
Indirect Collection
• Healthcare practitioners
• Hospitals
• Clinics
• Medical schemes
• Insurers
• Authorised representatives
Automated Collection
• Cookies
• Analytics technologies
• Security monitoring systems
• Website logs
• Application logs

10. PURPOSES AND LEGAL BASIS FOR PROCESSING
Lancet Laboratories processes Personal Information and Special Personal Information only where there is an appropriate lawful basis and legitimate business, healthcare, contractual, regulatory or legal purpose.
The lawful basis relied upon may include:
• Consent
• Performance of a contract
• Compliance with legal obligations
• Protection of vital interests
• Healthcare provision
• Legitimate business interests
• Public interest obligations
• Protection of the legitimate interests of the Data Subject

11. PROCESSING ACTIVITIES TABLE

Processing Activity Information Processed PurposeLawful Basis
Patient registrationIdentity, contact and demographic informationPatient identification and service deliveryContract, legal obligation
Pathology testingHealth information and specimen informationDiagnostic testingHealthcare provision
Result reportingTest results and patient informationReporting to authorised healthcare practitionersHealthcare provision
Medical aid processingMembership and billing informationClaims and reimbursementContract, legal obligation
Account administrationBilling and financial informationInvoicing and collectionsContract
Customer supportContact information and service recordsAssistance and complaints managementLegitimate interest
Quality assuranceLaboratory informationAccreditation and quality managementLegal obligation
Fraud preventionIdentity and transactional informationFraud detection and preventionLegitimate interest
Security monitoringTechnical informationInformation securityLegitimate interest
Website administrationTechnical and usage informationWebsite operation and improvementLegitimate interest

12. HEALTHCARE-SPECIFIC PROCESSING
As a pathology service provider, Lancet Laboratories processes health information primarily for purposes associated with healthcare delivery.
This may include:
• Pathology testing
• Laboratory diagnostics
• Specimen processing
• Result verification
• Result interpretation by authorised healthcare professionals
• Clinical consultations where applicable
• Quality assurance reviews
• Pathology consultations
• Patient care support
• Healthcare administration
Special Personal Information is processed only by appropriately authorised personnel and in accordance with applicable legal and professional requirements.

13. LABORATORY INFORMATION SYSTEMS
Personal Information may be processed through systems utilised by Lancet Laboratories including:
• Laboratory Information Systems (LIS)
• Meditech
• Elab platforms
• Clinician reporting systems
• Patient reporting systems
• Customer relationship management systems
• Billing systems
• Accreditation systems
• Document management systems
• Workflow management systems
• Access to these systems is controlled according to role-based access principles

14. PATIENT MOBILE APPLICATIONS
Lancet Laboratories may provide mobile applications and electronic platforms enabling patients to access healthcare-related services. Information processed through patient applications may include:
• Identity information
• Contact information
• Login credentials
• Authentication information
• Pathology results
• Account information
• Communication preferences
• Application activity logs
• Patients are responsible for
• Maintaining password confidentiality
• Safeguarding access devices
• Reporting unauthorised access
• Ensuring information viewed is protected from unauthorised disclosure

Lancet Laboratories may maintain activity logs relating to:
• Logins
• Report access
• Report downloads
• Profile changes
• Security events
Push notifications may be used for service-related communications.
Patients may disable certain notifications through application settings.

15. CLINICIAN PORTALS AND DOCTOR APPLICATIONS
Lancet Laboratories may provide electronic reporting platforms and mobile applications to healthcare professionals.
Information processed through these systems may include:
• Practitioner information
• HPCSA registration details
• Practice information
• Patient information
• Pathology reports
• Diagnostic information
• Portal activity logs
Healthcare practitioners are required to:
• Maintain confidentiality
• Safeguard credentials
• Implement reasonable security measures
• Access only information relevant to authorised patient care
• Comply with professional obligations
Lancet Laboratories reserves the right to monitor portal activity for security, compliance and audit purposes.

16. GENETIC TESTING, DNA TESTING AND PATERNITY TESTING
Lancet Laboratories may process Personal Information and Special Personal Information in connection with:
• DNA testing
• Genetic testing
• Paternity testing
• Maternity testing
• Kinship testing
• Relationship testing
• Forensic testing
• Inherited disease investigations

Due to the sensitive nature of genetic information, additional safeguards may be implemented.

Genetic information may only be disclosed:
• To authorised individuals
• To authorised healthcare practitioners
• Pursuant to legal requirements
• With appropriate consent
• Pursuant to valid court orders
• Where chain-of-custody procedures apply, additional identity verification and documentation requirements may be implemented.

17. CHILDREN’S TESTING
Where testing involves children:
• Parental or guardian authorisation may be required
• Legal requirements applicable to minors will be observed
• Disclosures will be managed in accordance with healthcare legislation and applicable privacy requirements

Lancet Laboratories reserves the right to request proof of authority before releasing information.

18. MEDICAL AID AND HEALTHCARE FUNDING ADMINISTRATION
Personal Information may be disclosed to:
• Medical schemes
• Healthcare funders
• Managed healthcare organisations
• Healthcare administrators
• Gap cover providers
• Authorised reimbursement service providers

The purposes of such disclosures may include:
• Benefit verification
• Authorisation processes
• Claims submission
• Reimbursement
• Account administration
• Healthcare funding audits
• Fraud investigations

Only information reasonably required for the intended purpose will be disclosed.

19. PUBLIC HEALTH REPORTING
Where required by law, Lancet Laboratories may disclose information to:
• National Institute for Communicable Diseases (NICD)
• National Department of Health
• Provincial Departments of Health
• Public health authorities
• Disease surveillance programs
• Regulatory authorities

Examples include:
• Notifiable medical conditions
• Communicable diseases
• Public health emergencies
• Disease surveillance reporting
Such disclosures occur only where authorised or required by law.

20. QUALITY ASSURANCE AND ACCREDITATION
Lancet Laboratories may process information for purposes relating to:
• Laboratory quality assurance
• Quality control programmes
• Proficiency testing
• Accreditation activities
• Sanas requirements
• ISO standards compliance
• Audit activities
• Healthcare governance

Information used for these purposes may, where appropriate, be anonymised or de-identified.

21. FRAUD PREVENTION, FORENSIC INVESTIGATIONS AND RISK MANAGEMENT
Lancet Laboratories may process Personal Information where necessary for:
• Fraud prevention
• Theft investigations
• Misconduct investigations
• Forensic audits
• Risk assessments
• Regulatory investigations
• Compliance reviews
• Litigation support

Processing under this section will be limited to information reasonably required to investigate or manage the matter.

22. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
Lancet Laboratories may utilise automated technologies, analytics platforms, machine-learning systems and artificial intelligence-assisted technologies to support:
• Operational efficiency
• Workflow management
• Customer support
• Fraud detection
• Cybersecurity monitoring
• Reporting and analytics
• Quality assurance
• Service optimisation

Artificial intelligence technologies are utilised as support tools and are not intended to replace professional healthcare judgment.
Clinical interpretation, diagnosis, treatment recommendations and patient-care decisions remain the responsibility of appropriately qualified healthcare professionals.
Lancet Laboratories does not rely solely on automated decision-making to make clinical diagnoses or treatment decisions affecting patients.

23. RESEARCH, STATISTICAL ANALYSIS AND DE-IDENTIFIED INFORMATION
Lancet Laboratories may utilise information for:
• Healthcare research
• Epidemiological studies
• Laboratory performance reviews
• Statistical analysis
• Trend analysis
• Service improvement initiatives

Where reasonably possible, information used for such purposes will be anonymised, de-identified or aggregated.
Where identifiable information is required, appropriate legal and ethical requirements will be observed.

24. DISCLOSURE OF PERSONAL INFORMATION
Lancet Laboratories may disclose Personal Information where necessary, lawful and proportionate to achieve the purpose for which the information was collected. Disclosure may occur to the following categories of recipient:
24.1 Healthcare Providers
• Referring healthcare practitioners
• Specialists
• Pathologists
• Hospitals
• Clinics
• Healthcare institutions
• Authorised healthcare professionals involved in patient care
24.2 Healthcare Funders
• Medical schemes
• Managed healthcare organisations
• Healthcare administrators
• Healthcare funding providers
• Gap cover providers
24.3 Service Providers
• Information technology service providers
• Cloud service providers
• Software vendors
• Data hosting providers
• Customer support providers
• Courier and logistics providers
• Payment processors
• Document storage providers
24.4 Professional Advisors
• Legal advisors
• Attorneys
• Advocates
• Auditors
• Insurers
• Forensic specialists
• Consultants
24.5 Regulatory and Government Authorities
• Information Regulator
• National Department of Health
• Provincial Health Departments
• National Institute for Communicable Diseases (NICD)
• South African Revenue Service
• Courts and tribunals
• Law enforcement agencies
• Other authorities where disclosure is legally required

Lancet Laboratories does not sell Personal Information.

24.6 Communication of Test Results and Personal Information
Lancet Laboratories communicates test results and other patient information using secure communication methods appropriate to the nature of the information and the recipient.
Depending on the services requested, results and related communications may be provided through one or more of the following channels:
• Secure electronic delivery to authorised healthcare practitioners.
• Secure email, where requested by the patient or authorised recipient.
• SMS notifications advising that results or other information are available (SMS messages generally do not contain detailed pathology results unless appropriate safeguards are in place.)
• The Lancet Laboratories Patient App, accessible using secure authentication.
• The Lancet Laboratories Doctor/Healthcare Practitioner Portal for authorised registered healthcare professionals.
• Printed reports collected in person or delivered through authorised courier services where applicable; and
• Any other secure communication method authorised by the patient or required by law.

Lancet Laboratories implements appropriate technical and organisational safeguards, including access controls, user authentication, encryption where appropriate, audit logging and monitoring, to protect personal information during electronic transmission and storage.
Patients are responsible for maintaining the confidentiality of their passwords, PINs, mobile devices and other authentication credentials used to access electronic services. Patients should notify Lancet Laboratories immediately if they believe their account or device has been compromised.
While Lancet Laboratories takes reasonable steps to secure electronic communications, no method of electronic transmission or electronic storage can be guaranteed to be completely secure. Patients who choose to receive information electronically acknowledge the inherent risks associated with electronic communications.

25. INTERNATIONAL TRANSFERS OF INFORMATION
Certain service providers, software vendors, hosting providers and technology platforms utilised by Lancet Laboratories may be located outside South Africa. Where Personal Information is transferred internationally, Lancet Laboratories will take reasonable steps to ensure that:
• Appropriate security safeguards are implemented.
• Adequate protection is afforded to personal information.
• Contractual protections are established where appropriate.
• Transfers comply with section 72 of POPIA.
• Recipients are subject to appropriate confidentiality obligations.
Cross-border transfers may occur in relation to:
• Cloud hosting services
• Software platforms
• Cybersecurity services
• Backup and disaster recovery systems
• Technology support services

26. COOKIES AND TRACKING TECHNOLOGIES
Lancet Laboratories websites and digital platforms may utilise cookies and similar technologies.
26.1 Categories of Cookies
Essential Cookies Required for:
• Authentication
• Website security
• Session management
• Platform functionality

Functional Cookies Used to:
• Remember preferences
• Improve usability
• Personalised experiences
Analytics Cookies Used to:
• Measure website performance
• Analyse user behaviour
• Improve services
• Generate usage statistics
Security Cookies Used to:
• Detect malicious activity
• Prevent fraud
• Protect systems
26.2 Browser Controls Users may manage cookies through browser settings.
Disabling certain cookies may affect website functionality.

27. INFORMATION SECURITY
Lancet Laboratories maintains technical and organisational security measures designed to protect Personal Information against:
• Unauthorised access
• Unauthorised disclosure
• Alteration
• Destruction
• Loss
• Misuse

Lancet Laboratories has aligned its information security policy with the ISO/IEC 27001 and ISO/IEC 27005 standards.
Security measures may include:
• Access controls
• Encryption
• Password management
• Multifactor authentication
• Network security controls
• Endpoint protection
• Security monitoring
• Vulnerability management
• Secure backup processes
• Disaster recovery procedures

No information system can be guaranteed to be completely secure. However, Lancet Laboratories continuously reviews and improves security controls to reduce risk.

28. AUDIT TRAILS AND ACCESS MONITORING
Lancet Laboratories maintains audit trails and monitoring systems to support:
• Privacy compliance
• Information security
• Fraud prevention
• Quality assurance
• Regulatory compliance
• Forensic investigations

Audit information may include:
• Login activity
• User identification
• Report access history
• Report downloads
• Modifications to records
• Administrative actions
• Security events

Audit records may be retained for periods determined by legal, operational and security requirements.

29. CCTV AND PHYSICAL SECURITY
Lancet Laboratories facilities may utilise:
• CCTV systems
• Visitor management systems
• Access control systems
• Biometric access systems
• Alarm systems
• Security monitoring technologies

Information collected through these systems may be used for:
• Protecting employees
• Protecting patients
• Protecting visitors
• Safeguarding assets
• Investigating incidents
• Fraud prevention
• Security management
• Occupational health and safety compliance

Where required, appropriate signage will be displayed.

30. RETENTION OF INFORMATION
Lancet Laboratories retains Personal Information only for as long as reasonably necessary to:
• Provide services
• Comply with legal obligations
• Comply with healthcare requirements
• Defend legal claims
• Support legitimate business purposes

Retention periods may vary according to:
• Record type
• Legal requirements
• Healthcare requirements
• Accreditation requirements

Patient records are retained on the Laboratory Information System (LIS) for a minimum period of seven (7) years. Thereafter, the records are securely archived electronically with strict role-based access controls, encryption and other appropriate security safeguards. Archived records may be retained indefinitely where permitted by applicable law and where necessary for medico-legal purposes, continuity of patient care, quality assurance, accreditation requirements, historical laboratory records or the establishment, exercise or defence of legal claims.

30.1 Examples of considerations that may influence retention periods:
• National Health Act requirements
• POPIA requirements
• PAIA requirements
• HPCSA guidance
• SANAS accreditation requirements
• Statutory prescription periods
• Litigation hold requirements
• Contractual obligations

At the end of applicable retention periods, information may be:
• Securely destroyed
• Permanently deleted
• Anonymised
• Archived where legally permissible
Deletion or destruction of Personal Information is performed using secure methods designed to prevent unauthorised recovery or reconstruction of the information, in accordance with Lancet Laboratories’ records management, information security and data destruction procedures.

31. DATA SUBJECT RIGHTS
Subject to applicable legal limitations, Data Subjects may exercise the following rights.
31.1 Right of Access: To request access to Personal Information held by Lancet Laboratories.
31.2 Right to Correction: To request correction of inaccurate or incomplete information.
31.3 Right to Deletion: To request deletion where retention is no longer legally required.
31.4 Right to Object: To object to processing where permitted by law.
31.5 Right to Restriction: To request restrictions on certain processing activities.
31.6 Right to Withdraw Consent: Where processing is based on consent, consent may be withdrawn subject to legal and operational limitations.
31.7 Right to Lodge a Complaint: To lodge a complaint with Lancet Laboratories or the Information Regulator.

32. POPIA REQUEST PROCEDURE
Requests relating to Personal Information should be directed to the Information Officer. Data Subject request forms and guidance on exercising privacy rights are available on the Lancet Laboratories website.
Requests may include:
• Access requests
• Correction requests
• Deletion requests
• Objections to processing
• Consent withdrawals

Lancet Laboratories may require:
• Proof of identity
• Proof of authority
• Supporting documentation
• Completion of prescribed forms

Lancet Laboratories reserves the right to refuse requests where permitted by applicable legislation.

32.1 Data Deletion Requests
A Data Subject who wishes to request the deletion of Personal Information may submit a written request to the Information Officer using the contact details provided in this Privacy Policy. To assist in the efficient processing of requests, Lancet Laboratories requests that Data Subjects complete and submit the prescribed POPIA Data Subject Request Form (Form 2), which is available on the Lancet Laboratories website. Requests submitted in another written format will also be considered, provided that sufficient information is supplied to enable Lancet Laboratories to verify the identity of the requester and assess the request.

The request should, where applicable, include:
• The Data Subject’s full name and surname.
• Identity or passport number, where required for identity verification.
• Sufficient information to identify the relevant records.
• Details of the information requested to be deleted.
• The reason for the request, where applicable; and
• Any supporting documentation reasonably required by Lancet Laboratories.

Upon receipt of a request, Lancet Laboratories may:
• Verify the identity and authority of the requester.
• Request additional information where reasonably necessary to process the request.
• Assess whether the requested information may lawfully be deleted in accordance with POPIA, the National Health Act, applicable healthcare legislation, accreditation requirements, contractual obligations or any other legal or regulatory retention requirements.
Where Lancet Laboratories is legally entitled or required to retain Personal Information, including health records or information subject to statutory retention periods, litigation holds, regulatory investigation or ongoing contractual obligations, the request for deletion may be refused in whole or in part. In such circumstances, the Data Subject will be informed of the reason why the information cannot be deleted, unless prohibited by law.
Where a deletion request is approved, Lancet Laboratories will, within a reasonable period, securely delete, de-identify, anonymise or otherwise dispose of the relevant Personal Information in accordance with its information governance, retention and destruction procedures and applicable legal requirements.

33. DATA BREACHES AND SECURITY INCIDENTS
Lancet Laboratories maintains incident response procedures for the management of actual or suspected security incidents. Where a security compromise involving Personal Information occurs, Lancet Laboratories may:
• Investigate the incident.
• Contain and remediate the incident.
• Assess the impact.
• Notify affected individuals where required.
• Notify regulators where required.
• Implement corrective actions.

Notifications will be issued in accordance with applicable legal requirements.

34. MARKETING COMMUNICATIONS
Lancet Laboratories may communicate with individuals regarding:
• Services
• Healthcare information
• Service updates
• Operational notices
• Educational content

Where required by law, marketing communications will only be sent with the appropriate consent. Individuals may opt out of marketing communications at any time. Operational and healthcare communications may continue where necessary for service delivery.

35. THIRD-PARTY WEBSITES AND SERVICES
Lancet Laboratories websites may contain links to third-party websites, applications or services. Lancet Laboratories does not control and is not responsible for:
• Third-party privacy practices
• Third-party security practices
• Third-party content

Users are encouraged to review the privacy notices of such third parties.

36. COMPLAINTS
Any privacy-related concern may be directed to the Information Officer. Lancet Laboratories will investigate complaints and attempt to resolve concerns promptly and fairly.

37. INFORMATION REGULATOR
Data Subjects may lodge complaints with the Information Regulator.
Information Regulator (South Africa) Physical Address: JD House 27 Stiemens Street Braamfontein Johannesburg
Website: www.inforegulator.org.za
Email: [email protected]

38. CHANGES TO THIS POLICY
Lancet Laboratories reserves the right to amend this Privacy Policy from time to time.
Updated versions will be published on the Lancet Laboratories website and will become effective upon publication unless otherwise stated.
Users are encouraged to review this Policy periodically.

39. HIGH-LEVEL POPIA SECTION 18 SUMMARY
Personal Information is collected for:
• Healthcare provision
• Pathology testing
• Customer support
• Legal compliance
• Accreditation requirements
• Quality assurance
• Fraud prevention
• Website administration

Failure to provide mandatory information may limit Lancet Laboratories’ ability to provide services. Information may be shared with authorised recipients identified in this Policy. Information may be transferred internationally where appropriate safeguards exist.

Please click the button below to view the PDF version of the Privacy Policy.