HR holds more sensitive personal information than almost any other part of a business — ID numbers, salaries, medical notes, disciplinary records, banking details. That makes the Protection of Personal Information Act (POPIA) less of a legal abstraction and more of a daily responsibility. The good news: the day-to-day of it is more sensible than the wording suggests.

This isn't legal advice — confirm your specific obligations with a professional. But here's what POPIA actually asks of an HR function, in language you can act on.

The whole Act, in one sentence

POPIA says: only collect the personal information you genuinely need, be honest about why you have it, keep it safe, and let people see and correct what you hold about them. Everything else is detail. If you internalise that one sentence, most decisions answer themselves.

Collect less than you're used to

The instinct in HR is to gather everything "just in case." POPIA pushes the opposite: collect only what you need for a clear purpose. A recruitment form doesn't need an applicant's marital status. An onboarding pack doesn't need a copy of a spouse's ID. Every extra field is something you now have to justify, protect and eventually delete.

A useful habit: for every field on every form, ask "what decision does this let us make?" If there isn't one, drop it.

The safest personal information is the information you never collected in the first place.

Be clear about why you have it

People have a right to know what you're collecting and why. In practice that means a plain-language privacy notice employees and applicants can actually read — not buried in a 40-page handbook. State what you collect, the purpose, how long you keep it, and who you share it with. Our own privacy notice is written to that standard if you want a reference point.

Keep it safe — and "safe" is specific

POPIA expects "reasonable" technical and organisational safeguards. For an HR team that translates to a short, concrete list:

The spreadsheet problem

If your employee data lives in spreadsheets passed around by email, you have a POPIA risk no policy can fix. Centralising HR data with proper permissions isn't a nice-to-have — it's the practical heart of compliance.

Let people see and fix their data

Data subjects can ask what you hold about them and request corrections. You need to be able to answer that without a week of digging. A system where an employee record is one search away makes this trivial; a pile of folders and spreadsheets makes it a crisis.

Delete what you no longer need

POPIA doesn't let you keep personal information forever "just in case." Once the purpose is done and any legal retention period has passed, it should go. That means having a retention rule for things like unsuccessful applicants' CVs — and actually following it.

Know who to call

Every organisation needs an Information Officer (by default, the head of the organisation, who can delegate). They register with the Information Regulator and are the point of accountability. If a breach happens, you must notify the Regulator and affected people — so knowing your process before anything goes wrong is the point.

Where software fits

You can be POPIA-compliant with discipline and good habits. But it gets dramatically easier when your HR data lives in one system with permissions, audit trails and retention built in — which is exactly why we designed PeopleCore the way we did. Compliance stops being a project and becomes the default state of how you work.

POPIA isn't there to make HR harder. It's there to make sure the trust employees place in you — handing over their most personal details — is actually earned. Treated that way, most of it is just good practice with a legal name attached.