Trevern Technologies · POPIA

POPIA, and the personal details your company holds.

Your company writes down names, numbers, appointment notes, sometimes health details. POPIA sets the rules for those details, wherever they are kept. This page is the plain version: what the law asks, and where one system helps.

Book a free call

Free call · no obligation · one fixed quote in writing

Who it applies to

POPIA applies to your company.

Written by engineers, not lawyers · this is not legal advice.

POPIA is the Protection of Personal Information Act 4 of 2013. The Act applies to anyone who processes personal information in South Africa. There is no exemption based on how many people you employ.

You may hold names, phone numbers, addresses, appointment notes or staff records. If you hold any of those, the Act applies to you.

The size of the duty follows what you hold, and what you do with those details. A name and a number are lighter than an identity number or a health note. Every extra system that holds the same details is one more place to account for.

More systems, more copies

Every system that touches a customer keeps its own copy.

One list is easy to manage. The same customer details usually sit in several places nobody chose: spreadsheets, inboxes, WhatsApp threads, paper diaries.

  • A manager keeps a WhatsApp thread and a paper diary. The company cannot see, back up or delete those names and numbers.
  • One team keeps a spreadsheet. Another team keeps a shared inbox. Nobody can say who else holds a copy.
  • Somebody leaves, and the customer list leaves with them. That list was never in a system you control.
  • A customer asks what you hold about them. At a group with several branches, the answer depends on which branch they last visited.

A policy document does not fix scattered copies. One system that everybody uses does.

Each person sees only what their job needs. You delete a customer’s details in one place, not in every list. You can answer “what do we hold about this person” in minutes.

Book a free call

The part that catches organisations out

Health details are a special case.

POPIA protects ordinary details like a name and a phone number. Section 26 adds a stricter class called special personal information. That class covers health and sex life, biometrics and race.

The same class covers religious or philosophical belief, and political persuasion. Trade union membership and criminal behaviour are on the list too.

Processing special personal information is prohibited by default. The Act allows the processing only under specific exceptions. Section 32 covers medical professionals who need health information to treat a patient.

A form or a chat may ask what the appointment is for. That one question raises the bar for those details.

Booking a haircut and booking a consultation carry two different sets of duties. The higher bar applies wherever the question is asked.

Two roles, one duty

You carry the duty. We carry the contract.

  • You are the responsible party

    Your company decides why and how customer details get used. If the group is one legal entity, the duty covers every branch. The duty never passes to a supplier, whatever a supplier tells you.

  • We are the operator

    We use your customers’ details only on your instruction. Section 21 requires a written contract, and requires us to keep the details secure. You get that contract before we build anything.

Section 21 requires the operator agreement to be in writing. Section 21 also requires the operator to keep the information secure. If a supplier has never given you that agreement, you do not have an agreement.

In every system we build

What we build in to protect those details.

  • The official WhatsApp Business Platform

    We work under a written agreement with Meta. We never put customer names in a personal WhatsApp account on somebody’s phone. A personal account is the hardest set-up to defend.

  • We ask permission before we take any details

    The first message says what we store and why. That message also says the chat passes through servers outside South Africa. Every form and every chat asks in the same words.

  • Marketing kept separate from service messages

    Section 69 bans unsolicited electronic marketing. The ban covers messages to businesses too, not only messages to people. Service messages and marketing messages never share a list.

  • We store as little as we can, encrypted

    We keep only what the job needs. We encrypt every record. You name who sees what: a manager sees their own area, head office sees everything.

  • A record of who agreed to what, and when

    Consent only counts if you can prove it. We time-stamp every permission and every withdrawal. You can export that record from one screen.

  • We can delete or export on request

    People can ask what you hold about them. They can ask you to delete those details. One system answers in minutes, instead of an afternoon of phone calls.

Straight answers

The questions groups ask.

Does POPIA apply to us, or only to large organisations?

POPIA applies to you, whatever the size of your organisation. POPIA covers anyone who processes personal information in South Africa. Every extra system that collects names and numbers is one more place to account for.

Is health information treated differently under POPIA?

Yes. Section 26 lists health and sex life as special personal information, along with race, religious belief and biometrics. POPIA bans processing special personal information by default. The exceptions are narrow, such as a doctor who needs health information to treat a patient.

Can software make us POPIA compliant?

No, and any supplier who claims otherwise is misleading you. Compliance is your own duty, and that duty reaches your paper files, your front desk and your Information Officer registration. A properly built system closes the biggest technical gap.

Is WhatsApp allowed for messages with customers and patients?

Yes, on the official WhatsApp Business Platform, under a written agreement. Take consent before you collect any details. Tell people the messages leave South Africa, because section 72 governs sending personal information out of the country.

Who is the Information Officer?

By default, the Information Officer is the head of the organisation, not the IT manager. You may appoint deputy Information Officers, but the duty stays with the head. The role is automatic under POPIA, and registration with the Regulator is free. inforegulator.org.za.

What happens if customer information leaks?

Section 22 requires you to tell the Information Regulator as soon as reasonably possible. You must usually tell the people affected too. You have to say exactly what was exposed, and whose details they were.

Do we still need a lawyer?

Quite possibly, for the organisation as a whole. We are engineers, not attorneys, and this page is no substitute for legal advice. We can tell you how your system handles data, in writing, for your lawyer.

Here is the honest version. No tool can make a company POPIA compliant on its own. Anyone who promises that is selling you something.

We build your systems properly, and the same way every time. We hand you the paperwork that shows how the details are handled. The rest of the company is still yours to get right.

How Trevern handles your own data · How our AI and automation works.

One system, one place for those details.

Tell us how customer details reach you today. Tell us where those details end up. You will get a plain answer about the gaps, whether or not you build anything with us.

Book a free call

Replies within one working day · the call is free and commits you to nothing