Opaido · Wiki · Concepts

POPIA (Protection of Personal Information Act)

Last updated 2026-08-07

POPIA is South Africa's data protection law, setting the rules for how businesses may collect, use, store and share personal information.

POPIA, the Protection of Personal Information Act, regulates how any organisation that processes personal information - of customers, employees or anyone else - must collect, use, store, secure and eventually dispose of that data.

What it means

It requires a lawful basis for processing personal information, reasonable security safeguards, and notification of the Information Regulator and affected people if a data breach occurs. Employee records - ID numbers, banking details, medical information used for leave - are personal information subject to POPIA.

Where it fits in

Payroll and HR systems hold some of the most sensitive personal information a business processes - banking details, tax numbers, medical certificates - making POPIA compliance directly relevant to how employee self-service portals and payroll data are secured and accessed.

Key rules

  • Regulates collection, use, storage and disposal of personal information.
  • Requires a lawful basis and reasonable security safeguards for processing.
  • Requires breach notification to the Information Regulator and affected data subjects.
  • Applies directly to payroll and HR data - banking, tax and medical records.

Related terms

Address
The Pavilion, Cube Workspace, Portswood Rd, Cape Town, WC, 8001, South Africa
Programs (planned)

Copyright © 2026 Opaido™. All rights reserved.
Christian † Company