The Employee Privacy Notice: What It Must Say and When to Give It
The employee privacy notice is the single most visible POPIA document in your business — the one place where the Act’s openness condition becomes paper. Done properly it is one clear page issued with every employment contract; done badly (or not at all) it is the first gap an employee’s complaint to the Information Regulator exposes. This guide covers exactly what goes in it, the lawful-basis question that confuses everyone, and when to issue it.

- ✔The privacy notice is mandatory — POPIA’s openness condition in one document.
- ✔Issue it with the employment contract, before or as data is collected.
- ✔Legal bases: contract and legal obligation cover payroll; consent is for extras only.
- ✔Name who you share with: SARS, UIF, operators like payroll providers.
- ✔State the rights: access, correction, deletion, complaint to the Regulator.
What the employee privacy notice must contain
- ✓What you collect — identity, contact, banking, tax, medical (where relevant), performance and conduct records
- ✓Why — payroll, statutory reporting, benefits administration, performance management, safety
- ✓The legal basis for each purpose — contract, legal obligation, legitimate interest, or consent
- ✓Who you share it with — SARS, the UIF and Compensation Fund, payroll and HR operators, medical aid and retirement schemes, banks
- ✓How long you keep it — the retention periods by record type
- ✓How it is secured — in summary
- ✓The employee’s rights — access, correction, deletion where lawful, objection, and complaint to the Information Regulator
- ✓Your information officer’s contact details
Keep the language human. A notice written in legalese fails POPIA’s purpose even where it ticks the boxes — the employee must actually understand what happens to their information. Plain English, one or two pages, signed for alongside the employment contract.
The lawful basis question: why consent is usually the wrong answer
The instinct is to make employees ‘consent’ to everything. POPIA is subtler — and stricter. Payroll data goes to SARS because the law requires it; records exist because the BCEA requires them; bank details are processed because the employment contract requires payment. These lawful bases are stronger than consent, and consent is actually the *wrong* basis for them — because consent must be voluntary, and an employee who cannot realistically say no to their employer has not consented voluntarily.
| Processing | Correct lawful basis |
|---|---|
| Payroll, tax numbers, IRP5 data | Legal obligation (SARS) |
| Employment records, contracts | Legal obligation (BCEA) + contract |
| Bank details for salary | Contract necessity |
| Sick notes for leave administration | Legal obligation + contract |
| Employee photos on the website | Consent — genuinely optional |
| Marketing references or testimonials | Consent — genuinely optional |
| CCTV and monitoring | Legitimate interest + disclosure |
A contract clause ‘consenting’ to all processing of all information for all purposes impresses no regulator. Map each purpose to its proper basis, and reserve consent for the genuinely optional items — where refusal must carry no penalty.
When to issue it — and when to refresh it
Timing is part of the duty: the notice must reach the employee before or as their information is collected — which makes the employment contract pack the natural delivery vehicle, with a signed acknowledgment in the file. Existing staff who never received one get it now, with a short covering note; there is no grandfather clause for pre-POPIA employees.
Refresh the notice when reality changes: a new payroll provider (a new operator), a new benefits scheme, a new monitoring system, biometric clock-ins. An accurate notice maintained beats a perfect notice from 2021 that no longer matches practice. Keep versions with dates — your retention schedule and information officer should both reference the current one. The full framework is in the POPIA pillar guide.
Always confirm current requirements with the official source — rules and deadlines change.
- ✔Admin Boss handles registrations, filings and payroll admin
- ✔Registered tax practitioner · 20+ years experience
- ✔Fully remote — all 9 provinces
Frequently asked questions
Is an employee privacy notice legally required?
Yes — POPIA's openness condition requires responsible parties to notify data subjects what information is collected, why, on what basis, who it is shared with, and their rights. For employees, the notice is issued with the employment contract.
Do employees need to consent to payroll processing?
No — payroll processing rests on legal obligation (SARS, BCEA) and contract necessity, which are stronger lawful bases. Consent is reserved for optional extras and must be genuinely voluntary to be valid.
When must the privacy notice be given?
Before or as personal information is collected — in practice, with the employment contract at hiring. Existing employees who never received one should be issued it now; there is no exemption for long-serving staff.
Can one privacy notice cover all employees?
Yes — a standard notice works for most roles, with role-specific additions where processing differs (drivers tracked by GPS, staff on biometric systems, managers with email monitoring). The test is whether each employee's actual processing is accurately described.
Last reviewed: July 2026 · How we research our guides
EmployerGuide.online provides general information about South African employer obligations — not legal, tax or professional advice for your specific situation. Laws, rates and deadlines change; confirm current requirements with the official sources linked above, or ask Admin Boss. See our disclaimer.