LearnerLens Data Processing Agreement (DPA)

Data Processing Agreement

Between LearnerLens (Pty) Ltd (Operator) and [School Name] (Responsible Party)

1. Purpose

This Agreement forms part of the School Services Agreement (SSA) and governs the processing of Personal Information by LearnerLens on behalf of the School in accordance with POPIA. The School remains the Responsible Party and LearnerLens acts as the Operator.

2. Definitions

Terms used in this Agreement, including "Personal Information," "Processing," "Operator," "Responsible Party" and "Data Subject," have the meaning given to them in POPIA. "Security Compromise" means unauthorised access to, or acquisition, loss, damage or destruction of, Personal Information processed under this Agreement.

3. Processing Principles

  • Personal Information is processed only for agreed educational purposes.
  • LearnerLens processes information only on documented instructions from the School unless otherwise required by law.
  • The School determines the lawful basis for processing and parent/guardian communication strategy.
  • Processing is limited to what is necessary to provide the contracted services.
  • Where LearnerLens believes an instruction from the School would infringe POPIA or any other applicable law, it will notify the School before carrying out that instruction.

4. Roles and Responsibilities

The School is responsible for determining the purpose of processing, authorising access to learner reports and complying with POPIA obligations as Responsible Party. LearnerLens provides the platform, implementation services and reporting while establishing and maintaining appropriate technical and organisational safeguards consistent with the standard required of a responsible party under POPIA.

5. Aggregated and De-identified Information

LearnerLens processes identifiable learner information only where necessary to deliver the contracted services, including generating individual learner reports for authorised school personnel. Information retained by LearnerLens for benchmarking, quality assurance, service improvement, statistical reporting or research is aggregated and de-identified. These datasets exclude direct identifiers such as names, learner numbers, identity numbers, contact details and other information that could reasonably identify an individual learner. Wellbeing and related survey responses constitute Special Personal Information as defined in POPIA, and are processed with the corresponding heightened safeguards described in this Agreement.

6. Data Subject Rights Assistance

LearnerLens will provide reasonable assistance to the School to enable it to respond to requests from data subjects (or a competent person acting on a child's behalf) to access, correct, or delete their Personal Information, or to object to its processing, within the timeframes required by POPIA.

7. Security, Confidentiality and Incidents

  • Role-based access and unique user authentication.
  • Reasonable encryption and secure transmission of information.
  • Confidentiality obligations for authorised personnel.
  • Reasonable backup and business continuity arrangements.
  • Notification to the School as soon as LearnerLens becomes aware of, or has reasonable grounds to believe there has been, a Security Compromise, with further detail provided as the assessment referred to in Schedule D progresses.

8. Sub-Operators

LearnerLens may engage third-party infrastructure or service providers to support delivery of the Services. Any such sub-operator is authorised, bound by written data protection obligations equivalent to those in this Agreement, and disclosed to the School in Schedule E. LearnerLens remains responsible for each sub-operator's compliance with this Agreement.

9. Cross-Border Transfers

Personal Information is hosted within South Africa. Where any Personal Information is transferred to or accessed from outside South Africa, LearnerLens will ensure the transfer complies with section 72 of POPIA, including through the use of an equivalent level of protection or appropriate contractual safeguards.

10. Audit and Inspection

On reasonable written notice, and no more than once per year unless following a Security Compromise, LearnerLens will provide the School with reasonable evidence of its compliance with this Agreement, which may include security documentation, policies, or a summary audit report. Any information provided under this clause is Confidential Information.

11. Retention, Return and Deletion

LearnerLens will not retain identifiable learner information beyond the agreed retention period unless required by law or expressly instructed by the School. Following completion of the agreed retention period, identifiable learner information will be securely deleted or returned to the School. LearnerLens may retain only aggregated and de-identified statistical information that cannot reasonably be linked to an identifiable learner, school staff member, or other data subject. Such information may be used solely for quality assurance, service improvement, benchmarking, research, and product development.

12. Term and Survival

This Agreement remains in force for as long as LearnerLens processes Personal Information on behalf of the School under the SSA. Clauses 6 (Data Subject Rights Assistance), 7 (Security, Confidentiality and Incidents), 9 (Cross-Border Transfers) and 11 (Retention, Return and Deletion) survive termination of the SSA to the extent necessary to give effect to their terms.

13. General

  • This Agreement is governed by South African law.
  • The DPA prevails where processing obligations conflict with the SSA.
  • Changes must be agreed in writing.

Schedule A — Categories of Personal Information

CategoryExamplesPurpose
School InformationSchool name, grades, classesPlatform configuration
Learner IdentifiersName, learner ID/classAuthorised learner reporting
Survey ResponsesWellbeing responses (Special Personal Information under POPIA)Generate reports
Authorised UsersStaff names, emailsSystem access & support

Schedule B — Technical & Organisational Security Measures

  • Role-based permissions.
  • Strong authentication for authorised users.
  • Encryption during transmission and protection of stored data.
  • Confidentiality agreements for authorised personnel.
  • Audit logging where applicable.
  • Regular backups and controlled access.

Schedule C — Data Retention Schedule

InformationRetentionAction
Identifiable learner dataAs agreed with School / contractual periodSecurely deleted or returned to the School on completion of the retention period
School reportsAs agreed with SchoolAvailable to authorised users
Aggregated de-identified datasetsRetained only while it cannot reasonably be linked to an identifiable individualUsed only for quality assurance, service improvement, benchmarking, research and product development

Schedule D — Incident Notification Procedure

  1. Identify and contain the incident.
  2. Assess the scope and potential impact.
  3. Notify the School's nominated contact as soon as LearnerLens becomes aware of, or has reasonable grounds to believe there has been, a Security Compromise.
  4. Provide updates on investigation and remediation.
  5. Support the School in meeting any applicable POPIA notification obligations.
  6. Record corrective actions and review lessons learnt.

Schedule E — Authorised Sub-Operators

[To be completed by LearnerLens prior to execution, listing each authorised sub-operator, the service it provides, and the location where Personal Information is hosted or processed.]