POPIA
Employee data protection, Information Officers and POPIA compliance for employers.
-
The Salary Spreadsheet Just Went to the Whole Company: Data Breach Steps
⚡ Quick answer A salary spreadsheet sent to the wrong list is a data breach under POPIA — salaries are personal information, and unauthorised disclosure triggers the Act’s response duties. Contain it, assess it, notify the Information Regulator and affected staff where required, and fix the process that allowed it. It happens in one click: the payroll spreadsheet goes to ‘All Staff’ instead of the bookkeeper, or a laptop with unencrypted salary data disappears from a car. Under POPIA that is a data breach — a security compromise of personal information — and it comes with defined duties: contain, assess, notify, document, prevent. The employers who survive these incidents are…
-
CV Retention Rules: How Long May You Keep Job Applications?
⚡ Quick answer CV retention under POPIA comes down to purpose: keep an unsuccessful applicant’s CV only as long as the recruitment purpose justifies — typically three to twelve months with consent for a talent pool — keep hired employees’ records for the statutory employment periods, and securely destroy everything past its purpose. Every hiring round leaves a trail of CVs — in the inbox, in a shared drive, in a physical folder from the interviews. Under POPIA, CV retention is not an administrative afterthought: a CV is personal information, and keeping it ‘just in case’ is exactly what the Act’s purpose-limitation principle prohibits. The rules are simple once separated…
-
You Are the Information Officer by Default — Now What?
⚡ Quick answer Under POPIA, every organisation’s head is its information officer automatically — in a small company, that is you, the owner. You did not appoint yourself; the Act did. Your job is to register with the Information Regulator, take charge of compliance, and answer for it when things go wrong. Here is a job you already hold, whether or not anyone told you: if you run a South African company, you are its information officer under POPIA. The Act assigns the role to the head of the organisation automatically — no board resolution, no opt-out. For most small-business owners the discovery comes late, usually when a tender or…
-
POPIA Compliance for Small Business: The Eight-Point Checklist
⚡ Quick answer POPIA compliance for a small business comes down to eight moves: register your information officer, publish privacy notices, sign operator agreements, lock down security, set retention periods, prepare for access requests, plan for breaches, and train your staff. None of it requires lawyers on retainer — it requires doing the basics on paper. POPIA has no small-business exemption: if you hold an employee’s ID number, a customer’s email address or a CV in your inbox, the Act applies to you in full. The good news is that POPIA compliance for a small business is a finite, mostly free checklist rather than an enterprise programme. These are the…