Privacy Policy

Last updated: 13 March 2026

1. Introduction

The National Rifle and Pistol Association of South Africa ("NRAPA", "we", "us", "our") is committed to protecting your privacy and personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and other applicable South African legislation.

This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the NRAPA members portal ("Portal") and our related services.

By using the Portal or providing us with your personal information, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal information as described herein.

2. Responsible Party

For purposes of POPIA, the responsible party is:

  • Organisation: National Rifle and Pistol Association of South Africa (NRAPA)
  • Address: 241 Jean Avenue, Centurion, Gauteng, South Africa
  • Email: info@nrapa.co.za
  • FAR Numbers: 1300122 (Sport) & 1300127 (Hunting)

3. Personal Information We Collect

We collect and process the following categories of personal information:

3.1 Information You Provide

  • Identity information: Full name, surname, title, South African ID number or passport number, date of birth, gender.
  • Contact information: Email address, mobile phone number, physical address, postal address.
  • Membership information: Membership type, membership number, application date, renewal history, membership status.
  • Financial information: Payment records, proof of payment, transaction history (we do not store credit card numbers).
  • Firearm information: Firearm make, model, calibre, serial number, licence number, licence expiry dates (as recorded in your Virtual Safe).
  • Activity records: Shooting activity logs, hunting activity records, scores, range session details, competition participation.
  • Endorsement information: Endorsement applications, supporting motivation, firearm details for endorsement requests.
  • Supporting documents: ID copies, proof of residence, competency certificates, photographs, and other documents uploaded to the Portal.

3.2 Information Collected Automatically

  • Technical data: IP address, browser type, device type, operating system.
  • Usage data: Pages visited, features used, timestamps, session duration.
  • Cookies: Session cookies to maintain your logged-in state and security tokens. See Section 11 for our Cookie Policy.

4. Purpose of Processing

We process your personal information for the following lawful purposes:

Purpose Legal Basis (POPIA)
Processing membership applications and renewals Contract / Consent
Issuing membership certificates and endorsement letters Contract / Legal obligation
Administering Dedicated Hunter and Sport Shooter status Legal obligation (FCA)
Maintaining activity records for compliance Legal obligation (FCA)
Communicating with you about your membership Contract / Legitimate interest
Sending renewal reminders and important notices Legitimate interest
Reporting to SAPS as required by the FCA Legal obligation
Processing endorsement applications Contract
Generating QR-verifiable certificates Contract / Legitimate interest
Maintaining the Virtual Safe and Loading Bench features Consent
Preventing fraud and ensuring Portal security Legitimate interest
Complying with legal and regulatory requirements Legal obligation

5. Sharing of Personal Information

We may share your personal information with the following parties, only to the extent necessary:

5.1 South African Police Service (SAPS)

We are legally required under the FCA to share certain information with SAPS, including:

  • Confirmation of membership status.
  • Dedicated Status records and compliance.
  • Endorsement letters supporting licence applications.
  • Notification when a member's Dedicated Status is revoked or membership is terminated.

5.2 QR Certificate Verification

When a third party (such as a SAPS official, DFO, or range officer) scans a QR code on your certificate, they will be able to see limited verification information including your name, membership number, membership status, and the validity of the certificate. This is necessary for the legitimate purpose of certificate verification.

5.3 Service Providers

We engage trusted third-party service providers to assist in operating the Portal. These may include:

  • Hosting providers for server infrastructure.
  • Email service providers for transactional and notification emails.
  • Cloud storage providers for secure document storage.
  • Payment processors for handling membership fee payments.

All service providers are contractually bound to process your data in accordance with POPIA and only for the purposes we specify.

5.4 We Do Not

  • Sell your personal information to any third party.
  • Share your information with marketing companies.
  • Transfer your personal information outside South Africa without appropriate safeguards as required by POPIA.

6. Retention of Personal Information

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

  • Active membership records: For the duration of your membership plus 5 years after termination or expiry.
  • Dedicated Status records: As required by the FCA, records relating to Dedicated Status are retained indefinitely or as prescribed by SAPS regulations.
  • Financial records: 5 years as required by the Tax Administration Act and other fiscal legislation.
  • Activity records: For the duration of your membership and 3 years thereafter.
  • Endorsement records: 5 years from date of issue.
  • Technical/usage data: 12 months.

After the retention period, personal information will be securely destroyed or de-identified in accordance with POPIA.

7. Security Measures

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, destruction, or damage, including:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Secure authentication with password hashing and optional two-factor authentication.
  • Role-based access controls limiting who can access your information.
  • Regular security reviews and updates.
  • Secure cloud infrastructure with access logging.
  • Automated backups with encrypted storage.

While we take all reasonable steps to protect your personal information, no system is completely secure. We cannot guarantee absolute security of your data.

8. Your Rights Under POPIA

As a data subject under POPIA, you have the right to:

  • Access: Request confirmation of whether we hold personal information about you and request access to that information.
  • Correction: Request the correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • Deletion: Request the destruction of your personal information, subject to our legal retention obligations.
  • Object: Object to the processing of your personal information on reasonable grounds.
  • Withdraw consent: Withdraw your consent to processing where consent was the legal basis, subject to any legal or contractual obligations.
  • Complain: Lodge a complaint with the Information Regulator if you believe your rights have been infringed.

To exercise any of these rights, please contact us at info@nrapa.co.za. We will respond to your request within a reasonable time, and no later than 30 days.

Important Note on Deletion Requests

Please note that we may not be able to delete certain information where we have a legal obligation to retain it, particularly records related to Dedicated Status, endorsements, and SAPS reporting requirements under the FCA. In such cases, we will inform you of the reason and the applicable retention period.

9. Special Personal Information

We are aware that certain information we process, such as your ID number, may constitute "special personal information" under POPIA. We process this information only because it is necessary for:

  • Compliance with the FCA, which requires positive identification of members.
  • The establishment, exercise, or defence of a right or obligation in law.
  • The performance of the membership contract.

10. Children's Information

Junior membership is available to persons under 18 years of age. We process personal information of children (under 18) only with the consent of a parent or legal guardian. We collect only the minimum information necessary for membership administration and comply with all POPIA requirements regarding the processing of children's personal information.

11. Cookies

The Portal uses the following types of cookies:

  • Essential cookies: Required for the Portal to function, including session management and CSRF protection tokens. These cannot be disabled.
  • Functional cookies: Remember your preferences (such as theme settings) to improve your experience.

We do not use advertising or tracking cookies. We do not use third-party analytics services that track individual users.

12. Direct Marketing

We may send you communications related to your membership, including renewal reminders, important notices, and updates about NRAPA services. These are transactional communications necessary for the administration of your membership.

We will not send you unsolicited direct marketing without your prior opt-in consent. You may opt out of marketing communications at any time by contacting us or using the unsubscribe mechanism provided in such communications.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. When significant changes are made, we will notify members via email or through the Portal. The "Last updated" date at the top of this page indicates when the policy was last revised.

14. Information Regulator

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the South African Information Regulator:

15. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal information, please contact:

  • Organisation: National Rifle and Pistol Association of South Africa (NRAPA)
  • Address: 241 Jean Avenue, Centurion, Gauteng, South Africa
  • Email: info@nrapa.co.za
  • Website: nrapa.co.za