POPIA: what employers need to know

​​​The Protection of Personal Information Act 4 of 2013 (POPIA) which came into force on 1 July 2020 places several obligations on employers in terms of managing employees personal information; it also gives certain rights to privacy to employees. Employers need to be fully complaint with POPIA by 30 June 2021. Non-compliance can result in significant penalties - up to 10  years' imprisonment and/or ZAR 10 million in administrative fines.

We set out below – the key things you ought to know as an employer.

POPIA applies to personal information and special personal information that is subject to processing or further processing. Processing encompasses a wide range of activities including the initial obtaining of personal information and the use and retention of that information as well as access, disclosure and final disposal of that information.

From an employment perspective, POPIA applies to:

  • information such as identity numbers, contact details, employment history, psychometric assessment results, references, qualifications, disciplinary records, union membership, grievances, health and biometric information; and
  • the full life cycle of the employment relationship - from recruitment to post termination and continues to apply for five years after the relationship has ended (and still applies where the employer is approached as a reference).

Employers must therefore ensure that they lawfully process the personal information of job applicants, employees, retired employees and dismissed employees. To the extent that employers process personal information of independent contractors and other service providers, they must also ensure that they lawfully process such information. Lawful processing will be achieved by complying with the eight conditions set out in POPIA -



Processing limitations

Purpose specifications

Further processing limitation

Information quality


Security safeguards

Data subject participation

POPIA prohibits processing of special personal information, which includes information on race, health, criminal behaviour and trade union membership unless:

  • an employer obtains express consent to do so from the relevant employee; or
  • the information is required by law –(legal necessity); or
  • the information is for historical, statistical or research purposes; or​
  • the information was deliberately made public by the data subject.

Next steps for employers

From an employment perspective, employers should take the following steps to ensure POPIA compliance -

Civil claims against employers

Section 99(1) of POPIA provides that a data subject or the Regulator (at the request of the data subject) may institute a civil action for damages against a responsible party for breach of POPIA. Action may be instituted irrespective of whether or not there is intent or negligence on the part of the "responsible party". "Responsible party" include employers.

Employers must bear in mind that many employees process high volumes of personal information both internally and externally. A good example of this in practice is the Human Resources function of any employer.

Employers will need to ensure that they follow the steps listed above to limit the risk of employees processing information unlawfully and in contravention of POPIA.

Employers should bear this section in mind as it creates significant legal risk for employers if employees do not process information lawfully and in compliance with POPIA.

Our employment team is able to assist employers in implementing POPIA and ensuring full compliance. For more information on our data protection & information offering, click here.

​We have produced a ​​POPIA infographic​ which sets out an overview of the instances in which POPIA will apply to processing activities and the obligations which come with POPIA.​


These materials are provided for general information purposes only and do not constitute legal or other professional advice. While every effort is made to update the information regularly and to offer the most current, correct and accurate information, we accept no liability or responsibility whatsoever if any information is, for whatever reason, incorrect, inaccurate or dated. We accept no responsibility for any loss or damage, whether direct, indirect or consequential, which may arise from access to or reliance on the information contained herein.

© Copyright Webber Wentzel. All Rights reserved.

Webber Wentzel > News > POPIA: what employers need to know
Johannesburg +27 (0) 11 530 5000
Cape Town +27 (0) 21 431 7000
Validating email against database, please wait...
Validating email: please wait...
Email verified: Please click the confirmation link sent to your mailbox, also check junk/spam folder. If you no longer have access to this email address or haven't received the verification email then email communications@webberwentzel.info
Email verified: You are being redirected to manage your subscription
Email could not be verified: Please wait while you are redirected to the Subscription Form
Unanticipated error: Saving your CRM information Subscription Form