POPIA Compliance Pack

All documents are pre-filled. Review, customise, and download.

1. Privacy Policy

How your business collects, uses, stores, and shares personal information. Required under POPIA Section 14.

Print / Save PDF

1. Introduction

[Your Company Name] ("we", "us", "our") is committed to protecting the privacy and personal information of all individuals ("data subjects") whose information we collect, use, and store in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA").

2. Information We Collect

We collect the following categories of personal information:

  • Identity information: Full name, surname, ID number, date of birth, gender
  • Contact information: Email address, phone number, physical address
  • Financial information: Bank account details, payment information, tax numbers
  • Employment information: Job title, employer, employment history
  • Technical information: IP address, browser type, device information, cookies
  • Usage information: How you interact with our services, preferences, feedback

3. Purpose of Processing

We process personal information for the following purposes:

  • Providing our services and fulfilling contractual obligations
  • Communicating with you about our services
  • Complying with legal and regulatory obligations
  • Improving our services and customer experience
  • Marketing and promotional activities (with your consent)
  • Protecting our legitimate business interests

4. Lawful Basis for Processing

We process personal information based on:

  • Consent: You have given clear consent for processing
  • Contract: Processing is necessary for a contract with you
  • Legal obligation: Processing is necessary to comply with the law
  • Legitimate interest: Processing is necessary for our legitimate interests

5. Sharing of Information

We may share your information with:

  • Service providers who assist in delivering our services
  • Professional advisors (accountants, lawyers, auditors)
  • Regulatory authorities when required by law
  • Only with your consent for any other third parties

6. Data Security

We implement appropriate technical and organisational measures to protect personal information against unauthorised access, loss, destruction, or damage. These measures include encryption, access controls, firewalls, and regular security assessments.

7. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are set out in our Data Retention Schedule.

8. Your Rights

You have the right to:

  • Request access to your personal information
  • Request correction of inaccurate information
  • Request deletion of your information
  • Object to processing of your information
  • Withdraw consent at any time
  • Lodge a complaint with the Information Regulator

9. Contact Details

For any queries regarding this policy or your personal information, contact our Information Officer:

  • Information Officer: [Name]
  • Email: [Email]
  • Phone: [Phone]
  • Address: [Physical Address]

10. Updates to This Policy

We may update this policy from time to time. Any material changes will be communicated to you via email or notice on our website. Last updated: [Date]

2. PAIA Manual

Promotion of Access to Information Act manual. Required for public bodies, recommended for private companies.

Print / Save PDF

1. Introduction

This Manual is published in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000 ("PAIA") to assist persons who wish to request information from [Your Company Name].

2. Contact Details

  • Company: [Your Company Name]
  • Registration Number: [Number]
  • Physical Address: [Address]
  • Postal Address: [Address]
  • Telephone: [Phone]
  • Email: [Email]
  • Information Officer: [Name]

3. Records Available

The following categories of records are held:

  • Company documents: Registration documents, memorandum of incorporation, annual returns
  • Financial records: Annual financial statements, tax returns, budgets
  • Personnel records: Employment contracts, policies, disciplinary records
  • Operational records: Contracts, correspondence, client records
  • Statutory records: Licences, permits, registrations

4. Request Procedure

To request information, complete Form A (attached) and submit it to the Information Officer. A fee of R35 may apply. Requests will be processed within 30 days.

5. Grounds for Refusal

Requests may be refused on the following grounds:

  • Protection of personal information of third parties
  • Protection of commercially sensitive information
  • Legal professional privilege
  • Public interest considerations

6. Appeal Process

If a request is refused, the applicant may lodge an internal appeal within 60 days. If still dissatisfied, a court application may be made.

4. Data Subject Request Forms

Forms for access, correction, deletion, and objection requests under POPIA Sections 23-25.

Print / Save PDF

Form 4A: Access Request (Section 23)

To: Information Officer, [Company Name]

From: [Data Subject Name]

ID Number: [ID Number]

I hereby request access to all personal information held about me by [Company Name], including:

  • All personal information held
  • Purposes of processing
  • Categories of information
  • Recipients to whom information has been/will be disclosed
  • Retention periods
  • Source of information (if not collected from me)

Signature: _________________

Date: _________________

Form 4B: Correction Request (Section 24)

I, [Data Subject Name], request the correction of the following personal information held by [Company Name]:

  • Incorrect information: [Describe]
  • Correct information: [Provide correct details]
  • Supporting evidence: [Attach proof]

Signature: _________________

Date: _________________

Form 4C: Deletion Request (Section 24)

I, [Data Subject Name], request the deletion of all personal information held about me by [Company Name].

Reason for request: _________________

I understand that deletion may not be possible where retention is required by law.

Signature: _________________

Date: _________________

Form 4D: Objection Request (Section 25)

I, [Data Subject Name], object to the processing of my personal information for the following purpose(s):

  • Purpose objected to: [Describe]
  • Reason for objection: [Explain]

Signature: _________________

Date: _________________

5. Information Security Policy

Technical and organisational safeguards to protect personal information. POPIA Section 19.

Print / Save PDF

1. Purpose

This policy sets out the technical and organisational measures [Company Name] implements to protect personal information against unauthorised access, loss, destruction, or damage.

2. Technical Safeguards

  • Encryption: All personal information encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access controls: Role-based access, multi-factor authentication, password policies
  • Network security: Firewalls, intrusion detection, VPN for remote access
  • Data backup: Daily encrypted backups, tested quarterly, stored off-site
  • Endpoint security: Antivirus, device encryption, remote wipe capability
  • Monitoring: 24/7 system monitoring, audit logging, anomaly detection

3. Organisational Safeguards

  • Staff training: Annual POPIA training for all employees
  • Confidentiality agreements: All staff sign NDAs
  • Incident response: Documented breach response procedure
  • Vendor management: Data processing agreements with all operators
  • Physical security: Locked offices, restricted access areas
  • Clear desk policy: No sensitive information left unattended

4. Data Minimisation

We collect only the minimum personal information necessary for the stated purpose. Data is anonymised where possible and deleted when no longer required.

5. Incident Response

In the event of a data breach, we will:

  • Contain the breach within 1 hour
  • Assess the scope and impact within 24 hours
  • Notify the Information Regulator within 72 hours if required
  • Notify affected data subjects without undue delay
  • Investigate root cause and implement remediation

6. Policy Review

This policy is reviewed annually by the Information Officer and updated as necessary. Last reviewed: [Date]

6. Breach Notification Procedure

Step-by-step guide for reporting data breaches to the Information Regulator and affected data subjects.

Print / Save PDF

1. What Constitutes a Breach

A data breach includes any unauthorised access to, or acquisition, disclosure, or destruction of, personal information. This includes:

  • Hacking or cyberattack
  • Theft or loss of devices containing data
  • Accidental disclosure to unauthorised parties
  • Unauthorised access by employees
  • Physical theft of paper records

2. Immediate Actions (First Hour)

  • 1. Contain the breach — disconnect affected systems, revoke access
  • 2. Notify the Information Officer immediately
  • 3. Preserve evidence — do not delete logs or files
  • 4. Document the time and nature of discovery
  • 5. Activate the incident response team

3. Assessment (Within 24 Hours)

  • Determine the scope — what data, how many records
  • Identify affected data subjects
  • Assess the risk to individuals (financial, reputational, physical)
  • Determine if notification is required (reasonable risk of harm)
  • Engage legal counsel if necessary

4. Notification to Information Regulator

If there is a reasonable risk of harm to data subjects, notify the Information Regulator "as soon as reasonably possible" using the prescribed form. Include:

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Name and contact details of Information Officer
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

5. Notification to Data Subjects

If notification is required, communicate to affected individuals "without undue delay" via email, letter, or public notice. Include:

  • Description of the breach in clear language
  • Information about the data involved
  • Recommended steps for individuals to protect themselves
  • Contact details for further information

6. Post-Incident Review

Within 30 days, conduct a full review: root cause analysis, lessons learned, policy updates, and staff retraining.

7. Operator Agreement Template

Data processing agreement for third-party vendors and service providers. POPIA Section 21.

Print / Save PDF

1. Parties

This Agreement is between [Company Name] ("Responsible Party") and [Operator Name] ("Operator").

2. Purpose

The Operator will process personal information on behalf of the Responsible Party for the following purpose: [Describe service]

3. Operator Obligations

The Operator agrees to:

  • Process personal information only with the knowledge and authorisation of the Responsible Party
  • Treat personal information as confidential and not disclose without written consent
  • Implement appropriate security measures as set out in Annexure A
  • Not transfer personal information outside South Africa without written consent
  • Notify the Responsible Party immediately upon becoming aware of any breach
  • Return or delete all personal information upon termination of this agreement
  • Allow the Responsible Party to audit compliance upon reasonable notice

4. Security Measures

The Operator shall implement at minimum the security measures specified in Annexure A of this agreement.

5. Sub-Operators

The Operator may not engage sub-operators without prior written consent of the Responsible Party.

6. Term and Termination

This agreement commences on [Date] and continues until [Date] or until terminated by either party with 30 days written notice. Upon termination, all personal information must be returned or securely deleted.

7. Signatures

Responsible Party: _________________

Date: _________________

Operator: _________________

Date: _________________

8. Employee Processing Register

Record of all processing activities involving employee personal information. POPIA Section 17.

Print / Save PDF
CategoryDetails
Categories of data subjectsCurrent employees, former employees, job applicants, contractors
Categories of personal informationName, ID number, contact details, bank details, tax number, qualifications, employment history, performance records, disciplinary records, medical information (if applicable)
RecipientsPayroll provider, SARS, UIF, COIDA, medical aid, pension fund, professional bodies
Cross-border transfersNone (unless specified)
Retention period5 years after employment ends (tax records); 3 years (general HR records); indefinitely (proof of employment)
Security measuresAccess controls, encryption, secure storage, confidentiality agreements

9. Customer Processing Register

Record of all processing activities involving customer personal information.

Print / Save PDF
CategoryDetails
Categories of data subjectsCurrent customers, potential customers, website visitors, marketing contacts
Categories of personal informationName, email, phone, address, ID number (if required), payment information, purchase history, communication preferences, website usage data
RecipientsPayment gateway, delivery services, accounting services, marketing platforms
Cross-border transfersNone (unless payment processor requires it)
Retention period5 years after last transaction (tax records); 3 years (marketing records); until consent withdrawn (opt-in lists)
Security measuresEncryption, access controls, secure payment processing, data minimisation

10. Data Retention Schedule

How long different types of personal information must be kept, and when it must be deleted or anonymised.

Print / Save PDF
Data CategoryRetention PeriodLegal BasisDisposal Method
Employee records5 years after terminationIncome Tax Act, BCEASecure shredding, digital wipe
Payroll records5 yearsIncome Tax Act, UIF ActDigital wipe, archive if required
Customer financial records5 yearsIncome Tax Act, VAT ActDigital wipe
Customer personal data3 years after last interactionPOPIA legitimate interestDigital wipe, anonymise for analytics
Marketing contactsUntil consent withdrawnPOPIA consentRemove from all lists immediately
CCTV footage90 days (unless incident)POPIA data minimisationAutomatic overwrite, incident footage retained
Website analytics26 months (anonymised)POPIA legitimate interestAnonymise IP addresses, aggregate data
Supplier records5 years after last transactionIncome Tax ActDigital wipe

11. Direct Marketing Opt-Out Procedure

How to handle electronic marketing opt-outs. POPIA Section 69 + ECTA Section 45.

Print / Save PDF

1. Legal Requirements

Direct marketing by electronic means requires prior consent. You must provide a clear opt-out mechanism in every marketing communication. Opt-out requests must be processed within a reasonable time.

2. Opt-Out Mechanism

Every marketing email, SMS, or WhatsApp message must include:

  • Clear identification of the sender
  • Purpose of the communication
  • Simple opt-out instructions (unsubscribe link, reply STOP)
  • Contact details for manual opt-out requests

3. Processing Opt-Out Requests

  • Process within 48 hours of receipt
  • Remove from all marketing lists permanently
  • Confirm removal to the data subject
  • Do not require data subject to create account or log in
  • Do not charge any fee for opt-out

4. Record Keeping

Maintain records of all opt-out requests, including date, method, and confirmation sent. These records may be required as evidence of compliance.

5. Opt-Out Form (for website)

To opt out of marketing communications, provide your email or phone:

Email: [text field]

Phone: [text field]

13. Social Media Policy

Rules for employees using social media. Protects company data and reputation. POPIA compliant.

Print / Save PDF

1. Purpose

This policy sets guidelines for employee use of social media to protect the company's data, reputation, and compliance with POPIA.

2. Personal Social Media

  • Do not disclose company confidential information
  • Do not share client or customer personal information
  • Do not make statements on behalf of the company without authorisation
  • Include a disclaimer: "Views are my own" if mentioning the company
  • Do not post anything that could damage the company's reputation

3. Company Social Media

  • Only authorised personnel may post on company accounts
  • Obtain consent before posting photos or information about clients
  • Do not share personal information without explicit consent
  • Respond to complaints professionally and promptly
  • Keep records of all interactions

4. POPIA Compliance

  • Never share personal information of data subjects without consent
  • Remove any personal information if requested
  • Report any suspected data breaches immediately
  • When in doubt, do not post

5. Consequences

Breaches of this policy may result in disciplinary action, including termination. Serious breaches may also result in legal liability.

14. Incident Response Plan

What to do when a data breach occurs. Roles, responsibilities, and step-by-step response.

Print / Save PDF

1. Incident Response Team

RoleNameContact
Information Officer (Lead)[Name][Email/Phone]
IT Security[Name][Email/Phone]
Legal Counsel[Name][Email/Phone]
Communications[Name]

2. Response Phases

  • Phase 1 — Detection & Containment (0-1 hour): Identify the breach, contain the threat, preserve evidence
  • Phase 2 — Assessment (1-24 hours): Determine scope, identify affected individuals, assess risk
  • Phase 3 — Notification (24-72 hours): Notify Information Regulator if required, notify affected individuals
  • Phase 4 — Recovery (1-7 days): Restore systems, implement additional safeguards, monitor
  • Phase 5 — Review (7-30 days): Root cause analysis, lessons learned, policy updates, retraining

3. Contact Information

OrganisationContact Details
Information Regulator (SA)Tel: 010 023 5207 | Email: enquiries@justice.gov.za
South African Police ServiceCrime Stop: 08600 10111
Cybersecurity HubTel: 0860 234 567
Print All Documents

© 2026 MY-LO · POPIA Compliance Pack · All documents are templates — customise with your business details