PAIA and POPIA Manual

Downtown Music Publish Africa Asset 1353

Download the supplied manual (PDF)

Downtown Music Publishing Africa Group

Prepared in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000, as amended (“PAIA”), and the Protection of Personal Information Act 4 of 2013 (“POPIA”).

On narrow screens, swipe horizontally to view all columns in this table.

Private bodies covered by this manual and their contact details
Entity Registration number Website (if any) Registered & postal address General email address Telephone number
Sheer Publishing (Pty) Ltd t/a Downtown Music Publishing Africa 2000/014175/04 https://downtownmusic.africa/ 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa; P.O. Box 3128, Parklands 2121, South Africa info@downtownmusic.africa +27 11 438 7000
Downtown SA Holdings (Pty) Ltd 2019/452288/07 No website 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa; P.O. Box 3128, Parklands 2121, South Africa info@downtownmusic.africa +27 11 438 7000
Super 5 Productions (Pty) Ltd 2013/070283/07 No website 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa; P.O. Box 3128, Parklands 2121, South Africa info@downtownmusic.africa +27 11 438 7000
Phatmonk Music Publishing SA (Pty) Ltd 2006/015995/07 No website 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa; P.O. Box 3128, Parklands 2121, South Africa info@downtownmusic.africa +27 11 438 7000
Skumba Music (Pty) Ltd 2012/025791/07 https://library.skumba.com/ 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa; P.O. Box 3128, Parklands 2121, South Africa info@downtownmusic.africa +27 11 438 7000

INTRODUCTION

Downtown Music Publishing Africa is a South African music publishing business.

The Company’s activities may include:

  • acquiring, administering and licensing musical works;
  • entering into publishing, administration, sub-publishing and representation agreements;
  • registering musical works and ownership interests;
  • administering copyright and contractual rights;
  • issuing mechanical, performance, synchronisation, print, digital and other licences;
  • receiving, processing, allocating and distributing royalties;
  • maintaining songwriter, composer, producer, catalogue and repertoire information;
  • working with collective management organisations, performing-right organisations and mechanical-right organisations;
  • managing sub-publishers, licensees, digital platforms, broadcasters, record labels, production companies and other commercial partners;
  • monitoring the use of musical works;
  • handling copyright claims, disputes and infringement matters; and
  • providing related rights-management and administrative services.

This Manual explains:

  1. what records the Company holds;
  2. how a person may request access to those records under PAIA;
  3. how the Company processes personal information under POPIA;
  4. the categories of data subjects whose information may be processed;
  5. the purposes for which personal information is processed;
  6. the persons to whom personal information may be disclosed;
  7. whether personal information may be transferred outside South Africa; and
  8. the security measures used to protect personal information.

DEFINITIONS

In this Manual:

“Company” means Sheer Publishing (Pty) Ltd t/a Downtown Music Publishing Africa ; Downtown SA Holding (Pty Ltd ;Super 5 Productions (Pty) Ltd; Phat Monk Music Publishing SA (Pty) Ltd; and Skumba Music (Pty) Ltd.

“Data subject” means the person to whom personal information relates.

“Information Officer” means the person responsible for ensuring the Company’s compliance with PAIA and POPIA.

“Musical work” includes music, lyrics, compositions and related copyright-protected material administered or represented by the Company.

“PAIA” means the Promotion of Access to Information Act 2 of 2000, as amended.

“Personal information” has the meaning assigned to it in POPIA and includes information relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person.

“POPIA” means the Protection of Personal Information Act 4 of 2013.

“Processing” includes collecting, recording, organising, storing, updating, using, sharing, transferring, restricting, deleting or destroying personal information.

“Record” means recorded information, regardless of its form or medium, that is in the possession or under the control of the Company.

“Requester” means a person who requests access to a record under PAIA.

“Royalty data” includes royalty statements, usage data, ownership shares, earnings, payment information, deductions, commissions, reserves and distribution calculations.

“Songwriter” includes a composer, lyricist, author, arranger or other creator or rights holder represented by or associated with the Company.

COMPANY AND INFORMATION OFFICER DETAILS

Company details

See above for a list of Downtown Music Publishing Africa group of companies.

Information Officer

Name: Thando Makhunga

Position: Managing Director

Telephone: +27 11 438 7000

Email: thandom@downtownmusic.com

Physical address: 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa

The Company’s Information Officer is the statutory officer appointed in accordance with POPIA and PAIA. The Information Officer is supported by the Company’s Global Privacy Office and Data Protection Officer in the implementation of the Company’s privacy and data protection programme.

Deputy Information Officer

Name: Privacy Office

General PAIA & POPIA enquiries can be directed to privacy@downtown.africa.

The Information Officer or the Company’s Global Privacy Office may be contacted for:

  • PAIA access requests;
  • requests to access or correct personal data;
  • objections to processing;
  • privacy complaints;
  • questions about this Manual; and
  • reports of suspected personal-information security compromises.

PURPOSE OF THIS MANUAL

The purpose of this Manual is to enable members of the public to:

  • identify the records held by the Company;
  • determine which records may be available without a formal PAIA request;
  • understand how to submit a request for access to a record;
  • obtain the Information Officer’s contact details;
  • understand the grounds on which access may be refused;
  • understand how the Company processes personal information;
  • identify the categories of data subjects and personal information processed;
  • understand how personal information may be shared or transferred;
  • understand the Company’s security safeguards; and
  • exercise rights under PAIA and POPIA.

GUIDE ON HOW TO USE PAIA

The Information Regulator has prepared a guide explaining how PAIA may be used.

The guide includes information about:

  • the purpose of PAIA;
  • how to make an access request;
  • the forms and potential fees applicable to requests;
  • remedies available where access is refused;
  • the role of the Information Regulator; and
  • how data subjects may exercise certain rights under POPIA.

The guide and prescribed PAIA forms are available from the Information Regulator.

Information Regulator contact details:

Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191

Telephone: 010 023 5200

Toll-free number: 0800 017 160

Email: enquiries@inforegulator.org.za

Website: www.inforegulator.org.za

The Company will assist a requester to identify the appropriate form where reasonably possible.

RECORDS AVAILABLE WITHOUT A FORMAL PAIA REQUEST

The following records may be available without a formal PAIA request, subject to confidentiality, copyright, contractual restrictions and applicable law:

  • this PAIA and POPIA Manual;
  • the Company’s privacy notice;
  • published company information;
  • public website content;
  • publicly announced management information;
  • press releases;
  • published catalogues or repertoire information;
  • publicly available songwriter or artist profiles;
  • publicly announced licensing information;
  • standard contact information;
  • standard terms and conditions;
  • marketing and promotional materials;
  • job advertisements;
  • publicly available regulatory filings;
  • public corporate information available through the Companies and Intellectual Property Commission; and
  • other records which the Company has expressly made publicly available.

The fact that a category is listed above does not mean that every record within that category is automatically available.

Confidential catalogue data, royalty information, contractual terms, ownership disputes, banking information and non-public commercial information are not ordinarily available without assessment under PAIA.

RECORDS HELD BY THE COMPANY

The Company may hold the following categories of records.

Corporate and governance records

  • incorporation and registration documents;
  • memorandum of incorporation;
  • shareholder records;
  • share registers;
  • beneficial-ownership records;
  • board and shareholder resolutions;
  • minutes of meetings;
  • powers of attorney;
  • organisational charts;
  • governance policies;
  • statutory registers;
  • regulatory registrations;
  • annual returns;
  • insurance records;
  • business-continuity plans;
  • Standard operating policy documents;
  • risk registers; and
  • internal delegations of authority.

Music publishing and catalogue records

  • publishing agreements;
  • administration agreements;
  • co-publishing agreements;
  • sub-publishing agreements;
  • songwriter and composer agreements;
  • catalogue acquisition agreements;
  • assignment and transfer agreements;
  • deeds of assignment;
  • commission agreements;
  • work-for-hire agreements;
  • producer, arranger and adaptation agreements;
  • letters of direction;
  • mandates and authorities;
  • work registrations;
  • song titles and alternate titles;
  • International Standard Musical Work Codes;
  • International Standard Recording Codes;
  • interested-party information;
  • writer and publisher identifiers;
  • ownership and copyright shares;
  • controlled and non-controlled shares;
  • territory information;
  • term and rights-reversion information;
  • chain-of-title documents;
  • copyright ownership documentation;
  • split sheets;
  • cue sheets;
  • metadata;
  • lyrics;
  • musical scores;
  • compositions and demo recordings;
  • copyright notices;
  • catalogue schedules;
  • repertoire databases;
  • duplicate-work and conflict records;
  • sample-clearance records;
  • adaptation and translation approvals;
  • claims, counterclaims and ownership disputes; and
  • historical catalogue records.

Licensing records

  • synchronisation licences;
  • mechanical licences;
  • performance licences;
  • digital and online licences;
  • print licences;
  • lyric-display licences;
  • blanket licences;
  • direct licences;
  • production-music licences;
  • commissioned-work licences;
  • sample licences;
  • adaptation and arrangement permissions;
  • quotations and licence proposals;
  • licence applications;
  • licence agreements;
  • rights-clearance correspondence;
  • usage approvals;
  • restrictions and reserved rights;
  • licence fees;
  • most-favoured-nations terms;
  • cue sheets;
  • audiovisual-production information;
  • advertising and campaign information;
  • broadcaster and platform information;
  • licence invoices;
  • licence reports; and
  • licence compliance records.

Royalty and usage records

  • royalty statements;
  • royalty calculations;
  • royalty-distribution schedules;
  • digital usage reports;
  • streaming and download reports;
  • broadcast logs;
  • performance reports;
  • mechanical-usage reports;
  • synchronisation income;
  • print income;
  • neighbouring-rights information, where applicable;
  • collective-management-organisation statements;
  • performing-right-organisation statements;
  • mechanical-right-organisation statements;
  • society distribution files;
  • unmatched and suspense royalties;
  • black-box or unidentified royalty records;
  • reserves and adjustments;
  • recoupment information;
  • commissions and administration fees;
  • withholding-tax records;
  • currency-conversion information;
  • payment schedules;
  • remittance advice;
  • bank-account details;
  • tax-residency information;
  • tax forms and certificates;
  • audit reports;
  • royalty queries;
  • royalty disputes;
  • royalty audit requests; and
  • historical royalty records.

Collective-management and rights-organisation records

  • membership and affiliation records;
  • mandates;
  • registrations submitted to rights organisations;
  • work-registration files;
  • publisher and writer identifiers;
  • society claims;
  • counterclaims;
  • distribution statements;
  • correspondence;
  • reciprocal-representation information;
  • audit and reconciliation records; and
  • records relating to organisations such as SAMRO, CAPASSO, SAMPRA or equivalent foreign organisations, where applicable.

Client, songwriter and rights-holder records

  • names and contact details;
  • identity and passport information;
  • dates of birth;
  • nationality and residence information;
  • professional names, aliases and stage names;
  • biographies;
  • signatures;
  • photographs;
  • tax numbers;
  • VAT information;
  • bank details;
  • payment instructions;
  • contract information;
  • ownership interests;
  • work and catalogue information;
  • society affiliations;
  • membership numbers;
  • writer or publisher identifiers;
  • correspondence;
  • meeting notes;
  • instructions;
  • complaints;
  • dispute information;
  • family, estate, heir or beneficiary information;
  • guardian information for minors;
  • legal-representative details;
  • management and agent details; and
  • due-diligence and compliance information.

Customer, licensee and commercial-partner records

  • names and contact information;
  • company registration information;
  • billing information;
  • tax information;
  • authorised-representative information;
  • contractual records;
  • correspondence;
  • licence history;
  • payment history;
  • usage information;
  • due-diligence documentation;
  • sanctions-screening information;
  • supplier and vendor records;
  • platform and distribution records;
  • broadcaster records;
  • record-label records;
  • production-company records;
  • advertising-agency records; and
  • audit and compliance information.

Financial and tax records

  • annual financial statements;
  • management accounts;
  • general ledgers;
  • invoices;
  • credit notes;
  • bank statements;
  • payment records;
  • accounts payable and receivable;
  • tax returns;
  • VAT records;
  • payroll records;
  • audit records;
  • budget and forecast records;
  • expense claims;
  • procurement records;
  • exchange-control records;
  • withholding-tax records;
  • royalty accruals;
  • debtor and creditor records; and
  • financial-control documentation.

Employment and contractor records

  • job applications;
  • curricula vitae;
  • interview records;
  • identity and contact information;
  • employment agreements;
  • contractor agreements;
  • background checks, where lawful;
  • qualification records;
  • remuneration information;
  • payroll records;
  • bank details;
  • tax information;
  • leave records;
  • attendance records;
  • performance records;
  • disciplinary and grievance records;
  • training records;
  • health and safety records;
  • emergency contacts;
  • benefit records;
  • termination records; and
  • access-control and system-usage records.

Legal, regulatory and compliance records

  • legal opinions;
  • litigation and arbitration records;
  • copyright claims;
  • infringement notices;
  • takedown notices;
  • cease-and-desist correspondence;
  • settlement agreements;
  • mediation records;
  • court and tribunal records;
  • legal privilege records;
  • complaints;
  • regulatory correspondence;
  • PAIA requests;
  • POPIA requests;
  • information-security incidents;
  • breach-response records;
  • data-processing assessments;
  • contracts with operators;
  • information-security policies;
  • compliance registers;
  • anti-bribery and corruption records;
  • sanctions and fraud-prevention records; and
  • records relating to investigations.

Information technology records

  • hardware and software inventories;
  • system configurations;
  • user accounts;
  • access logs;
  • audit logs;
  • security logs;
  • backups;
  • email records;
  • cloud-service records;
  • database records;
  • website logs;
  • cookie records;
  • incident-response records;
  • cybersecurity assessments;
  • vendor-security assessments;
  • disaster-recovery records; and
  • system-development documentation.

Marketing and communications records

  • mailing lists;
  • newsletter subscriptions;
  • marketing preferences;
  • event invitations;
  • event attendance;
  • campaign records;
  • website enquiries;
  • social-media interactions;
  • photography and audiovisual materials;
  • promotional agreements;
  • media enquiries;
  • publicity records; and
  • consent records.

RECORDS HELD UNDER OTHER LEGISLATION

Where applicable, the Company may hold records in accordance with legislation including:

  • the Companies Act 71 of 2008;
  • the Copyright Act 98 of 1978;
  • the Performers’ Protection Act 11 of 1967;
  • the Income Tax Act 58 of 1962;
  • the Value-Added Tax Act 89 of 1991;
  • the Tax Administration Act 28 of 2011;
  • the Basic Conditions of Employment Act 75 of 1997;
  • the Labour Relations Act 66 of 1995;
  • the Employment Equity Act 55 of 1998;
  • the Occupational Health and Safety Act 85 of 1993;
  • the Unemployment Insurance Act 63 of 2001;
  • the Compensation for Occupational Injuries and Diseases Act 130 of 1993;
  • the Electronic Communications and Transactions Act 25 of 2002;
  • the Consumer Protection Act 68 of 2008;
  • the National Archives and Records Service of South Africa Act 43 of 1996, where applicable;
  • PAIA;
  • POPIA; and
  • other legislation applicable to the Company’s activities.

Listing legislation does not mean that records will automatically be disclosed. Access remains subject to PAIA and other applicable laws.

HOW TO REQUEST ACCESS UNDER PAIA

Form of request

Requests for access to records may be submitted using the Company’s PAIA Request Form, which corresponds substantially with Form 2 prescribed under the PAIA Regulations. The prescribed Form 2 is also available from the Information Regulator’s website.

The request should contain enough information to enable the Company to:

  • identify the requester;
  • identify the record requested;
  • locate the record;
  • understand the form in which access is required;
  • identify the right the requester seeks to exercise or protect;
  • understand why the requested record is required to exercise or protect that right; and
  • communicate with the requester.

Where a request is made on behalf of another person, proof of authority must be supplied.

Submission details

Requests must be submitted either:

  1. By completing a PAIA Request Form; or
  2. By emailing the Company’s Privacy Office at privacy@downtown.africa; or
  3. By sending a letter to the Company’s physical address at 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa or postal address: P.O. Box 3128, Parklands 2121, South Africa.

Assistance to requesters

The Company may ask the requester to clarify a request that is vague, excessively broad or does not sufficiently identify the requested records.

The Information Officer will provide reasonable assistance where required by law.

Fees

The fees payable in respect of requests for access to records are those prescribed under PAIA and the applicable Regulations, as amended from time to time. These may include a request fee (where applicable), an access fee, reproduction fees, search and preparation fees, and, where permitted by PAIA, a deposit. The requester will be notified in writing if a fee is payable.

Decision period

The Company will, as soon as reasonably possible, and in any event within 30 days of receiving a valid request (or any additional information required to process the request), notify the requester of its decision. Where permitted by PAIA, this period may be extended by a further period of up to 30 days, in which case the requester will be notified of the extension and the reasons for it.

The requester will be informed whether:

  • access is granted;
  • access is granted in part;
  • access is refused;
  • the requested record cannot be found or does not exist;
  • a fee is payable; or
  • additional information is required.

Form of access

Access may be provided by:

  • inspection;
  • printed copy;
  • electronic copy;
  • transcription;
  • audio copy;
  • secure electronic transfer; or
  • another reasonably available format.

Access may be subject to reasonable security, copyright, confidentiality and system-protection measures.

GROUNDS FOR REFUSING ACCESS

The Company will assess each request for access to records on its own merits in accordance with PAIA. Access may be refused where PAIA requires or permits refusal, including where disclosure would unreasonably infringe the privacy of a third party, reveal confidential or commercially sensitive information, disclose legally privileged communications, or otherwise fall within one of the grounds for refusal set out in Chapter 4 of PAIA. Where access is refused, the Company will provide written reasons for the decision in accordance with PAIA.

This may include records involving:

  • unreasonable disclosure of a third party’s personal information;
  • confidential commercial information of the Company or a third party;
  • trade secrets;
  • confidential contractual terms;
  • royalty rates and royalty statements;
  • non-public catalogue valuations;
  • confidential acquisition terms;
  • financial, scientific or technical information;
  • information supplied in confidence;
  • legal professional privilege;
  • litigation privilege;
  • research information;
  • copyright restrictions;
  • safety and security risks;
  • computer, network or information-security risks;
  • information whose disclosure could prejudice negotiations;
  • information whose disclosure could prejudice the Company in commercial competition;
  • records whose disclosure is prohibited by law; or
  • records not required for the exercise or protection of the right identified by the requester.

A request will not be refused merely because a document contains some protected data. Where reasonably possible, the protected portion will be redacted and access will be given to the remainder.

THIRD-PARTY DATA

Where requested records contain data concerning another person, songwriter, employee, licensee, client, supplier, business partner or rights holder, the Company may be required to notify that third party.

The third party may be invited to consent to or oppose disclosure.

The Company will determine the request in accordance with PAIA and will not treat third-party consent or objection as the sole determining factor where the law requires a different outcome.

Personal data will not automatically be disclosed merely because it appears in a record requested under PAIA.

POPIA: CATEGORIES OF DATA SUBJECTS

The Company may process personal data relating to:

  • employees, directors and officers;
  • job applicants;
  • contractors, consultants and temporary workers;
  • clients and customers;
  • songwriters, composers, lyricists, rights holders and other creators represented by or contracting with the Company;
  • suppliers, vendors and service providers;
  • business partners, licensees and licensors;
  • website users and individuals who contact the Company or subscribe to its communications; and
  • any other individuals whose personal data the Company processes in the ordinary course of its business.

CATEGORIES OF PERSONAL DATA

The types of personal data the Company collects and processes include:

  • Identification and contact information, such as a data subject’s name, telephone number, postal and email address, and country;
  • Personal characteristics, such as photo, age and gender;
  • Financial information such as income and tax-related information, and any payment details that the data subject may provide to the Company;
  • Other information the data subject chooses to provide to the Company (see below).

Personal data that the data subject provides directly to the Company will be apparent from the context in which the data subject provides it, for example:

  • If they register for an account with the Company;
  • If they fill out a form on the Company’s Site, such as the “Contact Us” form;
  • If they complete the Company’s online surveys;
  • If they enter into transactions with the Company;
  • If they provide the Company with feedback about the Site or the Company’s Services;
  • If they apply for a position with the Company;
  • If they correspond with the Company by phone, email or otherwise; or
  • If they sign up to receive electronic marketing communications from the Company.

The Company may also obtain this information from a third party representative acting on the data subject’s behalf.

Each form on the Company’s Site varies in the information required and collected. In most cases, an asterisk (*) indicates the required information on a form. The data subject may choose to provide additional information within fields that are not required.

While the personal data the data subject chooses to provide is voluntary, certain personal data may be necessary to provide the data subject with the relevant product or service. If the data subject chooses not to provide certain information, this may affect the Company’s ability to provide the data subject with certain products or services.

PURPOSES FOR PROCESSING PERSONAL DATA

The Company uses the personal data the data subjects provided on the Company’s Site for the following legitimate business purposes:

  • To set up an account for the data subject, including to verify their identity in connection to setting up their account;
  • To respond to any enquiry the data subject should make, or contact them if necessary;
  • To perform market research and customer surveys, and determine the effectiveness of the Company’s advertising and marketing;
  • To comply with the Company’s legal and regulatory obligations such as for anti-money laundering, financial and credit checks, audit requirements, conduct fraud monitoring, prevention and detection activities and ID verification activities. This may include automated checks of personal data that the data subject provides about their identity against relevant databases, contacting the data subject to confirm their identity, or making records of the Company’s communications with the data subject for compliance purposes;
  • To operate, evaluate, and improve our Services and business (including administering the Site; developing new products and services; enhancing, improving and analysing the Company’s products and services; managing the Company’s communications; analyzing the Company’s customer base and Site; performing data analytics; and performing accounting, auditing and other internal functions);
  • To protect the security of and managing access to the Company’s premises, IT and communication systems, online platforms, websites and other systems, preventing and detecting security threats or other malicious activities;
  • To notify the data subject about any changes to the Services;
  • To send the data subject promotional correspondence from the Company, to enable them to participate in contests or receive special offers;
  • To provide the data subject with information about other products and services the Company or their subsidiaries or affiliates offer; and
  • To exercise the Company’s rights and remedies and defend against legal claims, protect against, identify and prevent fraud and other criminal activity, claims and other liabilities, and comply with and enforce applicable legal requirements, relevant industry standards and or policies.

LAWFUL BASIS FOR PROCESSING

The Company will process personal data in accordance with POPIA and only for a specific, explicitly defined and lawful purpose, where an appropriate lawful basis for the processing exists.

Depending on the circumstances, processing may be necessary:

  • with the data subject’s consent;
  • to perform or conclude a contract;
  • to comply with a legal obligation;
  • to protect a legitimate interest of the data subject;
  • to pursue the Company’s legitimate interests or those of a third party, subject to the data subject’s rights;
  • for the proper performance of a public-law duty by a public body; or
  • under another lawful justification recognised by POPIA.

Consent will not be relied upon where another lawful justification is more appropriate.

MUSIC-INDUSTRY DATA SOURCES

Personal data may be collected:

  • directly from the data subject;
  • from a songwriter, artist, manager, agent or representative;
  • from a co-writer or co-publisher;
  • from a rights owner or predecessor-in-title;
  • from a record label;
  • from a collective management organisation;
  • from a performing-right or mechanical-right organisation;
  • from an industry database;
  • from a digital service provider;
  • from a broadcaster;
  • from a production company;
  • from a licensee;
  • from cue sheets;
  • from royalty and usage reports;
  • from copyright registrations;
  • from public records;
  • from a regulator or government authority;
  • from a legal or professional adviser;
  • from the Company’s systems and websites; or
  • from another lawful source.

Where personal data is not collected directly from the data subject, the Company will comply with applicable notification and lawful-processing requirements.

RECIPIENTS OF PERSONAL DATA

Personal data may be supplied to:

  • members of the Company’s group, including affiliates and subsidiaries of the Company’s group;
  • the Company’s trusted third party service providers that perform services on the Company’s behalf and the Company’s business partners (or allow access to or collection of personal data by such third parties), in particular marketing service providers, adtech services, analytics providers, IT and data hosting providers, customer service and order delivery services, providers of fraud prevention services and ID verification services, and credit card processing or payment service providers;
  • accountants, attorneys, and consultants who need the information in order to provide services in connection with the delivery of the Company’s Services, Downtown Music’s management, administration, or legal and tax responsibilities;
  • In addition, we may disclose personal data about data subjects (a) if the Company is required or permitted to do so by law or legal process, for example due to a court order or a request from a law enforcement agency, (b) when the Company believes disclosure is necessary or appropriate to prevent physical harm or financial loss, (c) in connection with an investigation of suspected or actual fraudulent or other illegal activity, and (d) in the event the Company sell or transfer all or a portion of the Company’s business or assets, including in the event of a reorganization, dissolution, or liquidation;
  • With the consent of the data subject, the Company also may share information with third parties whose products and services the Company thinks may interest them or in connection with co-promotions, sweepstakes or contests in the Site.

The Company will disclose only the information reasonably required for the relevant purpose.

OPERATORS AND SERVICE PROVIDERS

Where a service provider processes personal data on the Company’s behalf, the Company will take reasonable steps to ensure that the service provider:

  • processes the information only with the Company’s knowledge or authorisation;
  • maintains confidentiality;
  • implements appropriate security safeguards;
  • notifies the Company of suspected security compromises;
  • does not retain information longer than authorised; and
  • complies with applicable contractual and legal requirements.

Relevant service providers may include:

  • royalty-accounting platforms;
  • music-rights databases;
  • cloud-hosting providers;
  • customer-relationship-management systems;
  • accounting systems;
  • payment processors;
  • payroll providers;
  • email and communication platforms;
  • document-management providers;
  • data analytics providers;
  • cybersecurity providers; and
  • professional advisers.

CROSS-BORDER TRANSFERS

Because music publishing is an international industry, the Company may transfer personal data outside South Africa.

International recipients may include:

  • foreign sub-publishers;
  • affiliated companies;
  • foreign collective management organisations;
  • performing-right and mechanical-right organisations;
  • global licensees;
  • digital service providers;
  • international royalty-processing platforms;
  • cloud-service providers;
  • financial institutions;
  • foreign tax authorities; and
  • professional advisers.

Cross-border transfers may take place where:

  • the recipient is subject to a law, binding corporate rule or agreement providing an adequate level of protection;
  • the data subject consents;
  • the transfer is necessary for the performance of a contract;
  • the transfer is necessary to implement pre-contractual measures requested by the data subject;
  • the transfer is necessary for the conclusion or performance of a contract in the interests of the data subject; or
  • another lawful basis applies.

The Company will use reasonable contractual, organisational and technical safeguards for international transfers.

SPECIAL PERSONAL DATA AND CHILDREN’S DATA

The Company will process special personal data and children’s personal data only where such processing is authorised under POPIA and is necessary for a lawful purpose.

Where the Company enters into agreements involving a minor songwriter, composer, artist or beneficiary, the Company may process:

  • age and date-of-birth information;
  • guardian or competent-person details;
  • contractual approvals;
  • payment and trust information;
  • educational or availability information where relevant; and
  • other information needed to administer the minor’s rights.

Appropriate consent, authority or another lawful justification must be obtained.

Access to such data will be restricted.

DATA QUALITY

The Company will take reasonably practicable steps to ensure that personal data is:

  • complete;
  • accurate;
  • not misleading;
  • updated where necessary; and
  • appropriate for the purpose for which it is processed.

Songwriters, rights holders and commercial partners should promptly notify the Company of changes to:

  • contact details;
  • banking details;
  • tax information;
  • society affiliations;
  • ownership information;
  • representatives;
  • authority to act;
  • catalogue information; or
  • royalty-payment instructions.

Changes to bank details or payment instructions may be subject to verification procedures.

RETENTION AND DESTRUCTION

Personal data and business records will be retained only for as long as:

  • required by law;
  • necessary for a contractual or business purpose;
  • reasonably required for copyright, ownership, royalty or licensing administration;
  • required to establish, exercise or defend legal claims;
  • required to resolve disputes;
  • required for historical royalty reconciliation;
  • authorised by the data subject; or
  • otherwise permitted under POPIA.

Music-publishing records may need to be retained for extended periods because:

  • copyright interests may continue for many years;
  • contractual rights may survive termination;
  • royalty reports may be received long after the underlying use;
  • ownership disputes may arise after a work is registered;
  • historic chain-of-title evidence may remain relevant;
  • unmatched royalties may later be identified; and
  • licences and audit rights may continue after expiry.

When records are no longer required, they will be securely deleted, destroyed or de-identified, subject to lawful retention requirements and legitimate archival needs.

SECURITY SAFEGUARDS

The Company uses reasonable technical and organisational measures appropriate to the nature of the data processed.

Measures may include:

  • access controls;
  • role-based permissions;
  • unique user accounts;
  • strong passwords;
  • multi-factor authentication;
  • encryption;
  • secure file-transfer systems;
  • secure cloud storage;
  • network and endpoint protection;
  • malware protection;
  • patch management;
  • backup and recovery procedures;
  • logging and monitoring;
  • confidentiality undertakings;
  • staff training;
  • clean-desk and secure-disposal procedures;
  • physical access controls;
  • incident-response procedures;
  • vendor due diligence;
  • contractual security obligations;
  • periodic access reviews;
  • segregation of financial duties;
  • bank-detail verification;
  • secure royalty portals;
  • data-minimisation measures; and
  • regular review of security risks.

No system can be guaranteed to be completely secure. The Company will continually assess and improve safeguards where reasonably appropriate.

SECURITY COMPROMISES

A suspected loss, unauthorised access, disclosure, alteration or destruction of personal data must be reported immediately to privacy@downtown.africa.

The Company will investigate the incident and, where required by POPIA, notify:

  • the Information Regulator; and
  • affected data subjects.

Notifications may be delayed where a competent authority determines that notification would impede a criminal investigation.

The Company will maintain incident and response records.

DATA-SUBJECT RIGHTS

Subject to applicable law, a data subject may request:

  • confirmation that the Company holds personal data about them;
  • access to their personal data;
  • correction of inaccurate or incomplete data;
  • deletion or destruction of data that the Company is no longer authorised to retain;
  • objection to certain processing;
  • restriction of processing where appropriate;
  • information about the source of their data;
  • information about recipients or categories of recipients;
  • review of certain automated decisions; and
  • assistance with a privacy complaint.

Rights may be limited where the Company is legally entitled or required to retain or withhold information.

For example, the Company may need to retain royalty, contractual, ownership, tax, legal or dispute records even after a deletion request.

REQUESTS TO ACCESS OR CORRECT PERSONAL DATA

Requests must be submitted either:

  1. By completing a POPIA (Data Subject) Request Form; or
  2. By emailing the Company’s Privacy Office at privacy@downtown.africa; or
  3. By sending a letter to the Company’s physical address at 5th Floor, 165 West Street, 2 Sandown Valley Crescent, Sandton 2196, South Africa or postal address: P.O. Box 3128, Parklands 2121, South Africa.

The requester should provide:

  • their full name;
  • proof of identity;
  • sufficient details to identify the relevant data;
  • the requested action;
  • the reason for the correction, deletion or objection, where applicable; and
  • proof of authority if acting for another person.

The Company may require additional verification before disclosing or changing:

  • bank details;
  • royalty-payment instructions;
  • identity information;
  • ownership information;
  • contract information; or
  • account credentials.

Objections to processing or requests to correct or destroy personal data should be made via the Information Regulator’s official forms or in a format providing equivalent details, as authorised by the POPIA Regulations.

DIRECT MARKETING

The Company may send industry news, catalogue updates, event invitations, licensing information or other marketing communications where permitted by law.

Recipients may opt out using the unsubscribe method in the communication or by contacting:

Communications@downtownmusic.africa

An opt-out will not prevent the Company from sending:

  • contractual communications;
  • royalty statements;
  • payment notifications;
  • security notices;
  • licence-administration communications;
  • rights-conflict notices; or
  • legally required communications.

COOKIES AND ONLINE SERVICES

The Company’s websites or online portals may use cookies and similar technologies for:

  • authentication;
  • security;
  • user preferences;
  • website functionality;
  • analytics;
  • performance measurement; and
  • lawful marketing.

Further information is set out in the Company’s cookie notice or online privacy notice.

Portal users are responsible for maintaining the confidentiality of their login credentials.

AUTOMATED DECISION-MAKING

The Company does not ordinarily make decisions producing legal or similarly significant effects solely through automated processing.

Automated tools may, however, assist with:

  • matching musical works;
  • identifying duplicate registrations;
  • allocating usage records;
  • identifying potential ownership conflicts;
  • calculating royalties;
  • fraud detection;
  • payment verification; and
  • catalogue analytics.

Material decisions will be subject to appropriate human oversight where required.

COMPLAINTS

Privacy or PAIA complaints may first be submitted to:

Information Officer: Thando Makhunga

Email: privacy@downtown.africa

Telephone: +27 11 438 7000

A person may also submit a complaint to the Information Regulator.

Information Regulator:

Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191

Telephone: 010 023 5200

Toll-free number: 0800 017 160

Email: enquiries@inforegulator.org.za

Website: www.inforegulator.org.za

AVAILABILITY OF THIS MANUAL

This Manual is available free of charge on the Company’s websites at https://downtownmusic.africa/ and https://library.skumba.com/#/home. A copy may also be obtained by contacting the Privacy Office or by inspecting the Manual at the Company’s principal place of business during normal business hours by prior arrangement.

REVIEW

This Manual was last updated on 18 September 2026.

Quick Answers

A white graphic consisting of concentric semicircular arches arranged horizontally.
M

Close

Our Rhythm

AFRICA We Are Down

We’re down with the culture of music — and the creators behind it. Downtown Music Publishing Africa protects the rights, handles the business, and amplifies the voices shaping Africa’s sound, from local legends to global stages.
Other Links
General Links
&

Home Base

&

Behind the Beat

&

On the Feed

&

Get in Touch

©2026 Downtown Music Publishing Africa | a Virgin Music Group company