Skip to content
Bosberaaad
  • Software
  • Categories
  • Compare
  • Guides
  • About
List your software

Let’s work it out

Get in TouchList Your Software
Bosberaaad

South Africa's independent business software guide. Clear comparisons, local compliance checks and prices in rand.

South AfricaBaviaans Local Municipality, Eastern Cape

Knysna StEastern Cape 6445+27 78 083 9764hello@bosberaaad.co.za

Browse

  • All software
  • Categories
  • Compare products
  • Buying guides
  • Search

Company

  • About us
  • Contact
  • How we rate
  • Newsletter
  • List your software

Legal

  • Terms of use
  • Privacy policy
  • Cookie policy
  • Affiliate disclosure
  • PAIA manual
  • Accessibility

©2026 Bosberaaad. South Africa's independent business software guide.

Bosberaaad

  1. Home
  2. Guides
  3. Compliance
  4. POPIA and your business software: what...
Compliance18 June 2026·3 min read

POPIA and your business software: what actually applies

Every vendor claims POPIA compliance. Here is what the Act actually requires of the systems you buy, and the questions that separate a real answer from a marketing one.

KS

Kinza Shahzad

Founder and editor

POPIA has been fully in force since July 2021 and most South African businesses have done the visible work: a privacy notice on the website, a consent checkbox on a form, an information officer registered. The systems layer gets less attention, and that is where the practical obligations sit.

Operator agreements are not optional

When a software vendor processes personal information on your behalf, they are an operator in the terms of the Act and you are the responsible party. Section 21 requires a written contract obliging the operator to establish and maintain the security measures the Act requires, and to notify you of a compromise.

Most reputable vendors publish a data processing addendum that serves this purpose. Ask for it by name. If a vendor cannot produce one, that is a straightforward answer to whether you should buy from them.

Cross border transfer

Section 72 restricts sending personal information outside South Africa. It is permitted where the receiving jurisdiction has substantially similar protection, or where the operator agreement binds the recipient to equivalent standards, or with the data subject's consent.

In practice, most cloud software you buy hosts data outside South Africa, and the route through section 72 is the operator agreement. This is workable and it is not automatic. Your information officer should read the agreement rather than assume the vendor's compliance page covers it.

Where data residency genuinely matters, SimplePay, PaySpace, LabourNet and HR Companion host in South Africa, and on premises deployments of Sage Pastel, Sage 200 Evolution and SYSPRO keep the data in your building.

Special personal information

Section 26 sets a higher bar for certain categories, including health, biometrics, religious belief, trade union membership and criminal behaviour. An HR system routinely holds several of these: medical aid details, disciplinary records, union membership.

The practical requirement is that access is restricted to people who need it for a lawful purpose. A permission model that only works at module level fails this, because a line manager approving leave should not thereby be able to read a disciplinary record. Ask to see field level or record level restriction demonstrated.

The four questions worth asking every vendor

  1. Can you produce a signed operator agreement that references POPIA, not only GDPR?
  2. Where is the data hosted, and what happens to it if we terminate?
  3. Can I find and permanently delete one individual's record across the whole system, and can you show me?
  4. What is your breach notification commitment, in hours, and to whom?

Retention is the part everyone skips

Section 14 says you may not keep personal information longer than necessary for the purpose it was collected for, unless another law requires it. Other laws frequently do: tax records for five years, employment records under the BCEA, and so on.

The practical implication is that you need a retention schedule and a system that can act on it. Very few businesses have either. Where your software supports configurable retention rules, use them. Where it does not, at minimum document the schedule so the decision is deliberate rather than accidental.

The marketing consent trap

Section 69 governs direct marketing by electronic means. For people who are not existing customers, you need consent, and you may only ask once. An existing customer may be marketed to for similar products, provided you gave them an opportunity to object at collection and in every message.

If your CRM cannot record the basis on which each contact is being marketed to, and the date and source of consent where consent applies, you cannot demonstrate compliance if you are asked. That capability is worth checking in a CRM trial.

About the author

KS

Kinza ShahzadFounder and editor

Get the next guide by email

One email a month. Consent recorded as POPIA requires, one click unsubscribe.

By subscribing you consent to us emailing you. We record the consent as POPIA requires. Unsubscribe in one click, any time.

Read next

01
Compliance02 Jul 2026·3 min read

VAT201: what your accounting software has to get right

The VAT201 is where accounting software either saves you time or quietly creates work. Here is what to test before you commit to a package.

Kanizan Hassan

02
Compliance03 Jun 2026·2 min read

ETI: the calculation your payroll system must get right

The Employment Tax Incentive is worth real money and the calculation is fiddly. Here is how it works and how to check your payroll is doing it correctly.

Haseeba bibi

03
Compliance20 May 2026·3 min read

BCEA leave rules and why imported HR software gets them wrong

Annual, sick and family responsibility leave under the BCEA, and the specific configuration failures that produce wrong balances in international HR systems.

Haseeba bibi