Subject Access Requests
The school's POPIA officer assembles a Subject Access Request export on demand, packaged for handover — without anyone needing direct database access.
Trust & POPIA
South African schools hold deeply sensitive information about minors and their families. MySentinel is built so the school's POPIA officer, IT contact, and governing body can each get a straight answer — encryption, an audit trail, and a working subject-rights console, not a promise.
Encryption at rest
Learner and visitor photos are encrypted with a per-school AES-GCM key before they ever reach storage, so one school's images can never be read with another school's key. The same posture covers the rest of the sensitive record set.
Audit trail
A badge scan, a guardian assignment, an emergency broadcast, a lockdown, a POPIA action — each writes an immutable audit entry naming the actor, the timestamp, and exactly what changed. That record is what settles a dispute between a parent and the school, and what an investigation works from.
Data residency
MySentinel runs entirely on Cloudflare — Workers, D1, R2, Queues, and Durable Objects. There is no separate reporting warehouse, no third-party advertising pixel, and no background telemetry. We collect only what is needed to record check-ins and check-outs and to notify guardians.
POPIA console
The school's designated POPIA officer works from a dedicated console. Subject Access Requests, erasure, and retention edits each require a WebAuthn passkey step-up before the change runs — so the most sensitive actions are tied to a verified person, not just a logged-in session.
The school's POPIA officer assembles a Subject Access Request export on demand, packaged for handover — without anyone needing direct database access.
A request to correct a record is logged and tracked through the console, so the school can show it was actioned.
An erasure always enters a mandatory 30-day cool-off before anything is deleted, and can be cancelled during that window. Each data store reports its own progress — completed, still scheduled, or needs attention — so the officer can see exactly where the request stands.
The POPIA officer edits per-school retention windows for movement records, so each school holds data only as long as its own policy allows.
Visitor design
The visitor register is designed to support a school's own ban and custody lists — the kind of screening a school keeps to manage who comes through the gate — while deliberately never holding a raw identity number. It matches on a one-way HMAC of the ID's last four digits, so the register can recognise a flagged person without ever storing data that would be dangerous in a breach.
Breach posture
The design assumption is that the safest data is the data you never store in the clear. Photos are encrypted per school, visitor identity is reduced to a one-way HMAC, and tenants are isolated so a single compromised school can never reach another school's records.
Because every state change is in the audit trail, a school and its POPIA officer can reconstruct exactly what was accessed and when — the record you need to meet a POPIA notification obligation, rather than a guess. As the data controller, the school directs subject-rights and erasure actions through the console; MySentinel, as processor, executes them and records the evidence.
Procurement
We'll walk your POPIA officer and IT contact through encryption, the audit trail, and the subject-rights console on a short call. Email am@binary-solutions.co.za to set it up.
Talk to us
Send us a message and we'll line up a walkthrough at a time that suits your school.