NewRevised White Paper on immigration: what is policy and what is already law.

Read the guide
A row of blue and orange lever-arch binders with handwritten spine labels standing on a records-room shelf, side light raking across them. Landscape, 1600x1067.
Pexels (free licence)
Compliance

POPIA Documents Are Not the Same as POPIA Compliance

Privacy policies are useful, but real compliance also requires data mapping, access controls, retention, incident response and staff behaviour.

Buying a privacy policy, an operator agreement and a data subject request form is a sensible first step. It is not compliance. The Protection of Personal Information Act 4 of 2013 does not ask whether you own the documents. It asks what your organisation does with personal information, who is accountable for it, whether your safeguards work, and whether you can answer a request or report a breach when one arrives.

That distinction is not academic, and the way POPIA is enforced shows why. The Information Regulator does not ordinarily fine a first contravention. Section 95 allows it to serve an enforcement notice requiring specified steps within a stated period. Failing to comply with that notice is itself an offence under section 103, and section 109 then allows an infringement notice carrying a fine of up to R10 million. The POPIA fines reported so far have followed that route: the penalty attached to ignoring the notice, not to the original mistake.

Lancet Laboratories is the clearest example for a private business. After an assessment into repeated security compromises, the Regulator issued an enforcement notice in September 2024 on the basis that the laboratory group had not notified it or the affected data subjects as section 22 requires, and ordered it to put adequate safeguards and breach notification processes in place. When the notice was not complied with, an infringement notice followed with a R100,000 fine, since paid. Comparable notices have gone to FT Rams Consulting over direct marketing under section 69, to Blouberg Local Municipality over an employee's details left exposed online, and to the Department of Justice and Constitutional Development over sections 19 and 22 after an antivirus and intrusion detection licence was allowed to expire, that R5 million notice being contested in court. No template would have changed those findings.

The eight conditions are operating requirements, not clauses

Chapter 3 of POPIA sets out eight conditions for lawful processing across sections 8 to 25. Each describes something the organisation must do, not something a document says:

  1. Accountability (section 8). The responsible party must ensure the conditions are complied with. This cannot be outsourced to a supplier or a template vendor.
  2. Processing limitation (sections 9 to 12). Processing must be lawful and minimal, must rest on consent or another listed justification, and information must generally come directly from the data subject.
  3. Purpose specification (sections 13 and 14). Collection must be for a specific, explicitly defined and lawful purpose, and records must not be kept longer than necessary.
  4. Further processing limitation (section 15). Using data for a new purpose must be compatible with the original purpose.
  5. Information quality (section 16). Reasonable steps to keep information complete, accurate and up to date.
  6. Openness (sections 17 and 18). Documented processing operations, plus notification to the data subject at collection.
  7. Security safeguards (sections 19 to 22). Technical and organisational security, operator control and breach notification.
  8. Data subject participation (sections 23 to 25). Access, correction and deletion rights.

A privacy notice is the visible output of condition 6 alone. Section 18 requires that the data subject is made aware of what is collected and its source, the name and address of the responsible party, the purpose, whether supply is voluntary or mandatory, the consequences of not supplying it, any law requiring collection, any transfer to a third country and the protection there, plus the rights to object and to complain to the Information Regulator. If your notice says all that but your booking form quietly collects an ID number nobody uses, the notice is inaccurate and the condition is not met.

The Information Officer is a person with statutory duties

Under POPIA the head of a private body is the Information Officer by default. Section 55(1) makes that person responsible for encouraging compliance with the conditions, dealing with requests, working with the Regulator during investigations, and otherwise ensuring compliance. Section 56 allows deputies to be designated, but delegation moves the work, not the accountability.

Regulation 4 of the POPIA Regulations adds concrete duties. The Information Officer must ensure that a compliance framework is developed, implemented, monitored and maintained, that a personal information impact assessment is done, that a PAIA manual is made available, that systems for processing requests exist, and that internal staff awareness sessions are conducted.

Section 55(2) is the part that catches small businesses: an Information Officer must take up their duties only after being registered with the Regulator. Registration is done on the eServices portal at eservices.inforegulator.org.za, where deputies are recorded too. The same portal handles PAIA annual reports and, since 1 April 2025, security compromise reporting. The Regulator publishes no fee for registration, so treat any third party charging a large sum purely to submit the form with scepticism.

Section 19 is where document packs fail hardest

Section 19(1) requires appropriate, reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction, and unlawful access or processing. Section 19(2) spells out four ongoing actions: identify all reasonably foreseeable internal and external risks, establish and maintain appropriate safeguards against them, regularly verify that the safeguards are effectively implemented, and ensure they are continually updated in response to new risks or deficiencies. Section 19(3) requires due regard to generally accepted information security practices, including any that apply to your industry.

Read that as a maintenance schedule. A licence that lapses, a former employee whose access was never revoked, a shared WhatsApp group holding client ID copies, an unencrypted laptop, a spreadsheet of customer data emailed to a personal address: no document fixes any of these.

Section 21 extends the same duty to suppliers. Where an operator processes personal information on your behalf, a written contract must ensure it establishes and maintains the section 19 measures, and the operator must notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Signing an operator agreement with your bookkeeper, payroll bureau or cloud provider is the paperwork half. Knowing which suppliers hold your data, and confirming they can meet the clause, is the other half.

If your systems sit outside South Africa, section 72 also applies: a transfer to a third party in a foreign country needs one of the listed grounds, most commonly that the recipient is bound by a law, binding corporate rules or an agreement providing adequate protection, or that the transfer is necessary to perform a contract with the data subject.

Requests and breaches run on clocks

Section 23 lets a data subject confirm, free of charge, whether you hold personal information about them, and be given the record or a description within a reasonable time, at a prescribed fee if any. Where a fee applies you must give a written estimate first, and when you supply the information you must advise the person of the section 24 right to request correction. Corrections and deletions are requested on Form 2 under the POPIA Regulations, objections to processing on Form 1.

Access requests themselves are made under PAIA. For a private body, section 56(1) requires a decision and notification to the requester as soon as reasonably possible and in any event within 30 days of receiving the request, with a single extension of up to a further 30 days under section 57. The prescribed form is Form 2 under the PAIA Regulations gazetted on 27 August 2021, replacing older forms some businesses still publish. A business with no monitored inbox for these requests, and no named person who opens them, will miss that window whatever its request procedure document says.

Breaches run faster. Section 22 requires notification to the Regulator and to affected data subjects where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, as soon as reasonably possible after discovery. Section 22(5) sets out what the notice to data subjects must contain: the possible consequences, the measures you intend to take or have taken, a recommendation on what the data subject can do to protect themselves, and the identity of the unauthorised person if known. Since 1 April 2025 reporting to the Regulator must go through the eServices portal, and its fact sheet of 19 August 2025 states that POPIA has no reporting threshold, that all security compromises must be reported whatever the assessed level of risk, and that an investigation need not be completed first.

PAIA is a separate obligation, and it is now universal

The ministerial exemption that spared certain private bodies from preparing a section 51 PAIA manual expired on 31 December 2021. From 1 January 2022 every private body needs one, published on its website if it has one and kept at its principal place of business. It is not filed with the Regulator unless requested. Separately, the Regulator runs a PAIA annual reporting cycle covering 1 April to 31 March, with submissions made through the eServices portal between 1 April and 30 June. You cannot submit the report unless your Information Officer is registered on the portal first.

What to do next, in order

  1. List your data. For each system, form and inbox: what information, whose, why, where it lives, who can see it, how long it is kept.
  2. Fix access and retention first. Remove ex-staff accounts, close shared logins, delete what you no longer need, turn on multi-factor authentication.
  3. Name and register the Information Officer on the eServices portal, recording deputies if the workload needs them.
  4. Map your operators and put written contracts in place carrying the section 19 duty and the immediate notification duty.
  5. Make the notices true. Only then update the privacy notice and website policy to match what you do.
  6. Build two workflows: a monitored channel and named owner for requests against the 30-day PAIA clock, and a breach playbook that ends at the eServices portal.
  7. Publish the PAIA manual and diarise the reporting window.
  8. Train staff and review. Section 19(2)(c) and (d) make verification and updating continuing duties.

The gap the Regulator keeps finding sits between step 5 and everything around it. If you want documents that can be implemented, the POPIA Starter Pack starts at R299 for a standalone website privacy policy, with the six-template starter bundle and implementation checklist at R699. If you already have documents and need to know whether practice matches them, the POPIA Readiness Assessment is R2,990 and delivers a data flow and risk summary, a document gap list, a priority action plan and an implementation call. For registration and access-to-information work, PAIA & Information Officer Support is R990 and PAIA Manual Support starts from R890. Legalyze provides administrative support rather than legal representation, and issues needing a legal opinion or a cybersecurity specialist are flagged and referred.

This is general information about POPIA and PAIA obligations, not advice on your organisation's circumstances.

Important: This resource is general information, not personalised legal advice. Check current official instruments and the facts of your matter before acting.