POPIA has been fully in force since July 2021 and most South African businesses have done the visible work: a privacy notice on the website, a consent checkbox on a form, an information officer registered. The systems layer gets less attention, and that is where the practical obligations sit.
Operator agreements are not optional
When a software vendor processes personal information on your behalf, they are an operator in the terms of the Act and you are the responsible party. Section 21 requires a written contract obliging the operator to establish and maintain the security measures the Act requires, and to notify you of a compromise.
Most reputable vendors publish a data processing addendum that serves this purpose. Ask for it by name. If a vendor cannot produce one, that is a straightforward answer to whether you should buy from them.
Cross border transfer
Section 72 restricts sending personal information outside South Africa. It is permitted where the receiving jurisdiction has substantially similar protection, or where the operator agreement binds the recipient to equivalent standards, or with the data subject's consent.
In practice, most cloud software you buy hosts data outside South Africa, and the route through section 72 is the operator agreement. This is workable and it is not automatic. Your information officer should read the agreement rather than assume the vendor's compliance page covers it.
Where data residency genuinely matters, SimplePay, PaySpace, LabourNet and HR Companion host in South Africa, and on premises deployments of Sage Pastel, Sage 200 Evolution and SYSPRO keep the data in your building.
Special personal information
Section 26 sets a higher bar for certain categories, including health, biometrics, religious belief, trade union membership and criminal behaviour. An HR system routinely holds several of these: medical aid details, disciplinary records, union membership.
The practical requirement is that access is restricted to people who need it for a lawful purpose. A permission model that only works at module level fails this, because a line manager approving leave should not thereby be able to read a disciplinary record. Ask to see field level or record level restriction demonstrated.
The four questions worth asking every vendor
- Can you produce a signed operator agreement that references POPIA, not only GDPR?
- Where is the data hosted, and what happens to it if we terminate?
- Can I find and permanently delete one individual's record across the whole system, and can you show me?
- What is your breach notification commitment, in hours, and to whom?
Retention is the part everyone skips
Section 14 says you may not keep personal information longer than necessary for the purpose it was collected for, unless another law requires it. Other laws frequently do: tax records for five years, employment records under the BCEA, and so on.
The practical implication is that you need a retention schedule and a system that can act on it. Very few businesses have either. Where your software supports configurable retention rules, use them. Where it does not, at minimum document the schedule so the decision is deliberate rather than accidental.
The marketing consent trap
Section 69 governs direct marketing by electronic means. For people who are not existing customers, you need consent, and you may only ask once. An existing customer may be marketed to for similar products, provided you gave them an opportunity to object at collection and in every message.
If your CRM cannot record the basis on which each contact is being marketed to, and the date and source of consent where consent applies, you cannot demonstrate compliance if you are asked. That capability is worth checking in a CRM trial.
