Document Code: NeftalyP384
Approved By: Neftaly Malatjie, Chief Executive Officer
Last Reviewed: 21 November 2025
Next Review Date: 21 May 2026
Policy Owner: Neftaly Chief Human Capital Officer (NeftalyCHCR)
NeftalyP384-1: CEO Statement on the Launch of the Policy
To the Neftaly Chairperson, Neftaly Board, Neftaly Royal Chiefs, and the entire Neftaly Human Capital Community,
I am honoured to launch the Neftaly Human Capital Protection Management Policy (NeftalyP384).
Protection is a cornerstone of Neftaly’s Human Capital governance. This policy establishes clear standards, procedures, and responsibilities for safeguarding the safety, wellbeing, rights, and assets of our people, information, and operational environments. Adhering to this policy ensures that every member of Neftaly is supported, risks are mitigated, and our organisational integrity is preserved.
My message shall end here.
Signed:
Neftaly Malatjie
Chief Executive Officer
Neftaly
NeftalyP384-2: Scope
NeftalyP384-2-1: This policy applies to:
- NeftalyP384-2-1-1 All Neftaly Human Capital staff, representatives, and contractors.
- NeftalyP384-2-1-2 Physical, digital, and intellectual assets of Neftaly.
- NeftalyP384-2-1-3 Employee safety, wellbeing, and rights protection.
- NeftalyP384-2-1-4 Sensitive data and information management.
- NeftalyP384-2-1-5 Incident prevention, mitigation, and reporting protocols.
NeftalyP384-3: Definitions
| Term | Definition |
|---|---|
| Protection | Measures and practices to ensure safety, security, rights, and wellbeing of people and assets. |
| Human Capital Protection Officer | Staff member responsible for implementation and monitoring of protection measures. |
| Risk Assessment | Process of identifying, evaluating, and mitigating potential threats or hazards. |
| Incident | Any event that threatens safety, security, or integrity of personnel, property, or information. |
| Mitigation | Actions taken to reduce the impact or likelihood of risks. |
NeftalyP384-4: Objectives
- NeftalyP384-4-1 Safeguard employees, stakeholders, and Neftaly assets.
- NeftalyP384-4-2 Minimise risks, incidents, and operational disruptions.
- NeftalyP384-4-3 Establish clear procedures for prevention, response, and mitigation of threats.
- NeftalyP384-4-4 Ensure compliance with labour, safety, and legal standards.
- NeftalyP384-4-5 Promote a culture of vigilance, accountability, and resilience.
NeftalyP384-5: Roles and Responsibilities
NeftalyP384-5-1 Neftaly Chief Executive Officer (NeftalyCER)
- NeftalyP384-5-1-1 Approves major protection initiatives and organisational security strategies.
NeftalyP384-5-2 Neftaly Chief Human Capital Officer (NeftalyCHCR)
- NeftalyP384-5-2-1 Oversees implementation and compliance of protection policies.
- NeftalyP384-5-2-2 Reviews protection risk assessments and mitigation plans.
NeftalyP384-5-3 Human Capital Protection Unit
- NeftalyP384-5-3-1 Conducts risk assessments and audits.
- NeftalyP384-5-3-2 Coordinates emergency response, health, and safety programs.
- NeftalyP384-5-3-3 Monitors protection compliance across all units.
NeftalyP384-5-4 Supervisors / Officers
- NeftalyP384-5-4-1 Ensure staff adhere to protection procedures.
- NeftalyP384-5-4-2 Report incidents and risks promptly.
- NeftalyP384-5-4-3 Facilitate training and awareness initiatives.
NeftalyP384-5-5 All Employees
- NeftalyP384-5-5-1 Follow protection policies and procedures.
- NeftalyP384-5-5-2 Report hazards, risks, or breaches immediately.
- NeftalyP384-5-5-3 Participate in safety and protection training.
NeftalyP384-6: Procedures
NeftalyP384-6-1 Risk Assessment and Planning
- NeftalyP384-6-1-1 Conduct regular risk assessments using NeftalyT384-01 Protection Risk Assessment Form.
- NeftalyP384-6-1-2 Identify threats to people, property, information, and operations.
- NeftalyP384-6-1-3 Develop and implement mitigation plans.
NeftalyP384-6-2 Safety and Security Measures
- NeftalyP384-6-2-1 Implement access control, surveillance, and safety protocols.
- NeftalyP384-6-2-2 Ensure proper training in emergency response, fire safety, and health protocols.
- NeftalyP384-6-2-3 Maintain PPE (Personal Protective Equipment) and safety infrastructure.
NeftalyP384-6-3 Data and Information Protection
- NeftalyP384-6-3-1 Classify, secure, and monitor sensitive data.
- NeftalyP384-6-3-2 Use NeftalyT384-02 Data Protection Checklist.
- NeftalyP384-6-3-3 Comply with POPIA, GDPR, and internal data security standards.
NeftalyP384-6-4 Incident Reporting and Response
- NeftalyP384-6-4-1 Use NeftalyT384-03 Incident Report Form to document events.
- NeftalyP384-6-4-2 Activate response protocols including mitigation, investigation, and recovery.
- NeftalyP384-6-4-3 Conduct post-incident analysis and improvement planning.
NeftalyP384-6-5 Training and Awareness
- NeftalyP384-6-5-1 Conduct regular protection awareness and safety training.
- NeftalyP384-6-5-2 Use digital, in-person, and instructional resources.
- NeftalyP384-6-5-3 Track participation using NeftalyT384-04 Training Log.
NeftalyP384-6-6 Monitoring and Review
- NeftalyP384-6-6-1 Monitor protection compliance through audits and inspections.
- NeftalyP384-6-6-2 Provide monthly reports to NeftalyCHCR.
- NeftalyP384-6-6-3 Conduct annual review and update of protection measures.
NeftalyP384-7: Templates, Documents and Forms
NeftalyP384-7-1: Core Templates
- NeftalyP384-7-1-1 NeftalyT384-01: Protection Risk Assessment Form
- NeftalyP384-7-1-2 NeftalyT384-02: Data Protection Checklist
- NeftalyP384-7-1-3 NeftalyT384-03: Incident Report Form
- NeftalyP384-7-1-4 NeftalyT384-04: Protection Training Log
- NeftalyP384-7-1-5 NeftalyT384-05: Safety Inspection Checklist
- NeftalyP384-7-1-6 NeftalyT384-06: Emergency Response Plan Template
- NeftalyP384-7-1-7 NeftalyT384-07: Mitigation Action Plan
NeftalyP384-7-2: Extended List (2000+ Templates)
NeftalyP384-7-2-1 Includes: security audit forms, health and safety SOPs, disaster recovery plans, protection awareness campaign kits, emergency drill trackers, and compliance checklists.
NeftalyP384-8: Compliance
NeftalyP384-8-1 All protection management must comply with:
- NeftalyP384-8-1-1 Neftaly Governance Manual
- NeftalyP384-8-1-2 Occupational Health & Safety Standards
- NeftalyP384-8-1-3 Labour, safety, and data protection legislation
NeftalyP384-8-4 Non-compliance may result in corrective, administrative, or disciplinary action.
NeftalyP384-9: Frequently Asked Questions (Preview)
- Who is responsible for protection compliance?
- How often are risk assessments conducted?
- What procedures exist for reporting incidents?
- How is sensitive data protected?
- What training is required for employees?
- How are emergency situations handled?
- Who approves protection mitigation plans?
- How are incidents reviewed and lessons implemented?
- What records must be maintained?
- How often is the protection policy updated?
