HR holds more sensitive personal information than almost any other part of a business — ID numbers, salaries, medical notes, disciplinary records, banking details. That makes the Protection of Personal Information Act (POPIA) less of a legal abstraction and more of a daily responsibility. The good news: the day-to-day of it is more sensible than the wording suggests.
This isn't legal advice — confirm your specific obligations with a professional. But here's what POPIA actually asks of an HR function, in language you can act on.
The whole Act, in one sentence
POPIA says: only collect the personal information you genuinely need, be honest about why you have it, keep it safe, and let people see and correct what you hold about them. Everything else is detail. If you internalise that one sentence, most decisions answer themselves.
Collect less than you're used to
The instinct in HR is to gather everything "just in case." POPIA pushes the opposite: collect only what you need for a clear purpose. A recruitment form doesn't need an applicant's marital status. An onboarding pack doesn't need a copy of a spouse's ID. Every extra field is something you now have to justify, protect and eventually delete.
A useful habit: for every field on every form, ask "what decision does this let us make?" If there isn't one, drop it.
The safest personal information is the information you never collected in the first place.
Be clear about why you have it
People have a right to know what you're collecting and why. In practice that means a plain-language privacy notice employees and applicants can actually read — not buried in a 40-page handbook. State what you collect, the purpose, how long you keep it, and who you share it with. Our own privacy notice is written to that standard if you want a reference point.
Keep it safe — and "safe" is specific
POPIA expects "reasonable" technical and organisational safeguards. For an HR team that translates to a short, concrete list:
- Access control. Not everyone needs to see salaries or medical records. Limit who can open what.
- No personal data in spreadsheets emailed around. This is the single most common breach we see. A shared HR system with permissions beats a spreadsheet on five laptops.
- Encryption in transit. Data moving between systems should be encrypted as standard.
- An audit trail. You should be able to answer "who looked at this record, and when?"
The spreadsheet problem
If your employee data lives in spreadsheets passed around by email, you have a POPIA risk no policy can fix. Centralising HR data with proper permissions isn't a nice-to-have — it's the practical heart of compliance.
Let people see and fix their data
Data subjects can ask what you hold about them and request corrections. You need to be able to answer that without a week of digging. A system where an employee record is one search away makes this trivial; a pile of folders and spreadsheets makes it a crisis.
Delete what you no longer need
POPIA doesn't let you keep personal information forever "just in case." Once the purpose is done and any legal retention period has passed, it should go. That means having a retention rule for things like unsuccessful applicants' CVs — and actually following it.
Know who to call
Every organisation needs an Information Officer (by default, the head of the organisation, who can delegate). They register with the Information Regulator and are the point of accountability. If a breach happens, you must notify the Regulator and affected people — so knowing your process before anything goes wrong is the point.
Where software fits
You can be POPIA-compliant with discipline and good habits. But it gets dramatically easier when your HR data lives in one system with permissions, audit trails and retention built in — which is exactly why we designed PeopleCore the way we did. Compliance stops being a project and becomes the default state of how you work.
POPIA isn't there to make HR harder. It's there to make sure the trust employees place in you — handing over their most personal details — is actually earned. Treated that way, most of it is just good practice with a legal name attached.
