POPIA, the Protection of Personal Information Act, regulates how any organisation that processes personal information - of customers, employees or anyone else - must collect, use, store, secure and eventually dispose of that data.
What it means
It requires a lawful basis for processing personal information, reasonable security safeguards, and notification of the Information Regulator and affected people if a data breach occurs. Employee records - ID numbers, banking details, medical information used for leave - are personal information subject to POPIA.
Where it fits in
Payroll and HR systems hold some of the most sensitive personal information a business processes - banking details, tax numbers, medical certificates - making POPIA compliance directly relevant to how employee self-service portals and payroll data are secured and accessed.
Key rules
- Regulates collection, use, storage and disposal of personal information.
- Requires a lawful basis and reasonable security safeguards for processing.
- Requires breach notification to the Information Regulator and affected data subjects.
- Applies directly to payroll and HR data - banking, tax and medical records.