Quick answer
A POPIA-compliant law firm intake form should collect the minimum information needed for a defined intake stage, tell the person how that information will be used, separate optional marketing from legal-service processing, restrict access, and send the data into a documented retention and incident-response process.
Key takeaways
- A POPIA-compliant law firm intake form should collect the minimum information needed for a defined intake stage, tell the person how that information will be used, separate optional marketing from legal-service processing, restrict access, and send the data into a documented retention and incident-response process.
- Do not solve POPIA by adding one broad consent checkbox. A law practice may process information on different grounds, including consent, a contract, a legal obligation, protection of a legitimate interest, performance of a public-law duty or pursuit of the responsible party's or a third party's legitimate interests. The correct ground depends on the field, person, purpose and stage. Legal practitioners may also have conflict, professional, anti-money-laundering and evidential duties that justify particular information, but those duties do not permit unlimited collection.
- The safer design is staged: capture a minimal enquiry; run a controlled conflict check; open the engagement and mandate; complete FIC or other verification where required; then request matter-specific evidence. Keep marketing permission separate. This article is current to 21 July 2026 and is aimed at a practice owner, information officer, operations lead, intake manager or supplier designing a client-intake workflow.
Start with a field-level processing register
Before changing the form, list every proposed field in a processing register. A label such as “client details” is too broad. Record:
| Control | What to document |
|---|---|
| Field | the exact item, such as email address, opposing party name or identity number |
| Person | prospective client, related party, witness, child, employee, director or opponent |
| Purpose | enquiry response, conflict screening, mandate, billing, FIC customer due diligence or matter preparation |
| Lawful ground | the section 11 ground relied on, with any special-information or children's-information authorisation |
| Required or optional | whether the workflow can proceed without it and the truthful consequence of not providing it |
| Source | the person directly, an authorised representative, a public record or another permitted source |
| Recipient | the practice team, counsel, correspondent, expert, operator, regulator or other defined category |
| Location | intake platform, document system, email, practice-management system, conflict index or archive |
| Access role | who needs to view, change, export or delete it |
| Retention trigger | declined enquiry, completed conflict check, mandate termination, closed matter, statutory period or litigation hold |
This register turns POPIA's processing conditions into a design decision for each field. It also exposes duplicate questions, fields collected “just in case”, and information that is arriving too early.
Section 10 of the Protection of Personal Information Act 4 of 2013 (POPIA) requires personal information to be adequate, relevant and not excessive for the purpose. Section 13 requires a specific, explicitly defined and lawful purpose. A large free-text box inviting a prospective client to “tell us everything” before a conflict check is difficult to reconcile with either principle. Use constrained questions for the first stage and request detailed evidence only after the practice knows why it is needed and who may access it.
Stage the intake instead of building one universal form
Stage 1: minimal enquiry
The first screen or contact form normally needs only enough information to route the enquiry safely. Depending on the practice, that may include:
- the prospective client's name and reliable contact route;
- a short matter category;
- a location or court only where jurisdiction or service coverage matters;
- an urgent date or deadline, clearly identified as the person's report rather than a verified calculation;
- the names needed for an initial conflict check; and
- a warning not to submit unnecessary identity documents, medical records, children's information or a full evidence bundle yet.
Do not imply that submitting the form creates an attorney-client relationship, confirms acceptance, stops a deadline or guarantees confidentiality against all conflicts. The form should route the enquiry; the engagement process should establish the mandate.
Stage 2: conflict screening
Collect the minimum names and relationships needed to test whether the practice can consider the instruction. Depending on the matter, this may include former or trading names and the names of related companies, counterparties or key witnesses. It rarely requires the full merits file.
Keep the conflict index separate from the full prospective-client narrative where the systems permit it. Limit visibility of confidential enquiry details and define what remains in the index if the practice declines to act. A record that an identified person approached the firm may itself be sensitive and must not become a general staff search tool.
The Legal Practice Council Code of Conduct should be assessed together with the practice's conflict and confidentiality rules. POPIA does not replace professional duties, and professional duties do not make every requested field necessary.
Stage 3: engagement and mandate
Once the conflict and capacity checks permit the practice to proceed, capture the contracting party, authorised representative, billing details, scope, communication preferences and records needed to establish the mandate. Link the engagement terms and the law-firm glossary without treating a website enquiry as accepted work.
The practice should be able to prove when the engagement was accepted, which entity is the client, who may give instructions, and which notices or terms were delivered. A pre-ticked box, buried privacy wording or a signature that purports to authorise every future use is not a substitute for that record.
Stage 4: FIC customer due diligence where required
Legal practitioners are accountable institutions under the Financial Intelligence Centre Act framework. The practice's risk management and compliance programme should determine when and how customer due diligence, verification, beneficial-ownership and record-keeping steps apply. Those steps are a separate purpose and should not be disguised as optional profile completion.
Use a risk-based workflow. Ask only for the identity and verification records required for the client, authorised person, entity, beneficial owner and transaction under the applicable FIC controls. Record why a verification step was required, the source used, the result, who reviewed it and whether enhanced measures or escalation were triggered.
Minimality does not mean omitting information that the law requires. It means avoiding unrelated data, duplicate copies and premature collection while preserving the practice's documented legal obligations. The FIC's current legal-practitioner material and Guidance Note 7A should be reviewed when designing the workflow.
Stage 5: matter-specific evidence
Only after the practice can receive the matter should it request pleadings, contracts, correspondence, bank records, medical reports or other evidence. Use a matter-specific checklist rather than the same upload list for every service. The client document packs resource can structure that later handover without expanding the first-contact form.
Make each request explain its purpose in the workflow. Do not ask a person to upload an unredacted identity document where a narrower verification method is available. Do not collect the same document through email, a form and a messaging channel merely because all three are enabled.
Stage 6: optional communications
Marketing permission belongs in a separate, optional control. It must not be bundled into the instruction, privacy notice, terms or FIC declaration. Record the communication channel, wording shown, date, source and withdrawal. Section 69 has specific rules for unsolicited electronic communications; an enquiry about legal services is not permanent permission to send promotions.
Give the section 18 notice at the correct time
POPIA section 18 generally requires specified information to be given when personal information is collected, subject to its qualifications and exceptions. The notice should be available before or at collection and should match the actual workflow.
Check that it accurately states:
- the name and address of the responsible party;
- the purpose for collecting the information;
- whether supply is voluntary or mandatory;
- the consequence if required information is not supplied;
- any law authorising or requiring collection;
- whether the practice intends to transfer the information outside South Africa;
- the recipient or category of recipients;
- the person's rights of access and correction;
- the right to object where applicable;
- the right to complain to the Information Regulator and the Regulator's contact details; and
- any further information needed for the processing to be fair, including the source, nature and category of information, having regard to the circumstances.
Use the POPIA notice and privacy policy as approved public references, but verify that the intake notice names the real responsible party, systems, purposes, recipients and cross-border position. A generic policy link does not cure a form whose fields or routing contradict the policy.
If information is collected from a representative, public record or another source rather than directly from the person, assess section 12 and the timing requirements in section 18. Record the source and the reason direct collection was not used. Do not scrape or enrich a prospective client's profile merely because information is publicly accessible.
Do not use consent as the answer to every field
For each purpose, select and record the section 11 ground that actually applies. Examples may include:
- steps requested by the prospective client before entering a contract;
- performance of the engagement agreement;
- compliance with FIC or another legal obligation;
- protection of a legitimate interest of the data subject;
- a legitimate interest of the practice or a third party, balanced against the person's rights; or
- consent where consent is the genuine basis and can be proved and withdrawn.
Consent must be voluntary, specific and informed. If the practice would still collect an item under a legal duty or contract after consent is withdrawn, calling consent the basis creates a false choice. Conversely, a legitimate-interest label should not be used without defining the interest, necessity and impact on the person.
Maintain separate records for processing ground, privacy-notice delivery, contractual acceptance and direct-marketing choice. They answer different questions.
Add a gate for special personal information and children
An intake form can easily receive health information, biometric identifiers, criminal allegations, religious or political information, trade-union membership, sex-life information and children's information. POPIA restricts processing of special personal information and applies additional rules to children's information.
Create a gate that asks:
- whether the information is necessary at this stage;
- which statutory authorisation applies;
- whether the matter involves establishing, exercising or defending a right or obligation in law;
- whether a child or authorised representative is involved;
- which team members may access the information;
- whether a general free-text or ordinary email channel should be disabled;
- whether redaction, segregation or stronger encryption is required; and
- what retention trigger applies if the practice declines the instruction.
The legal-proceedings authorisation in section 27 can be relevant to a law practice, but it does not waive POPIA's other conditions. The practice must still have a purpose, minimise collection, provide required notice, secure the information and control retention.
Regulations for processing health information were published in March 2026 for specified categories including insurance companies, medical schemes, administrators, managed-healthcare organisations, certain pension funds, employers and institutions working for specified entities. Do not assume that every law practice falls within those categories. A practice should determine whether it is itself covered or acts as an operator for a covered entity; the general POPIA and special-information rules remain relevant regardless.
Decide who is the responsible party and who is an operator
The practice is usually the responsible party where it determines why and how intake information is processed. A form host, practice-management supplier, cloud provider, document processor, call centre or verification supplier may be an operator where it processes information for the practice under a mandate.
Map each supplier and integration. For every operator, record:
- the service and categories of information;
- processing instructions and prohibited uses;
- storage and backup locations;
- authorised personnel and access controls;
- subprocessors;
- deletion or return when the service ends;
- audit and assurance evidence;
- security-incident notification to the practice; and
- cross-border transfers.
Section 21 requires a written contract obliging an operator to establish and maintain the security measures referred to in section 19. An operator must notify the responsible party immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person. A supplier's public privacy policy is not, by itself, the practice's operator agreement.
Do not allow an intake-platform supplier to train a model, create unrelated profiles, contact prospective clients or reuse uploads unless a lawful, transparent and authorised arrangement has been separately assessed. Vendor convenience does not change the practice's accountability under section 8.
Build security into the form and its destinations
Section 19 requires appropriate, reasonable technical and organisational measures. Risk depends on the information, likely harm, system and threat environment. At minimum, test:
- encryption in transit and at rest where appropriate;
- role-based access and least privilege;
- multi-factor authentication for staff and administrators;
- secure upload links instead of unnecessary ordinary-email attachments;
- file-type, size and malware controls;
- protection against malicious input and automated spam;
- expiration and revocation of upload links;
- audit logging for viewing, export, change and deletion;
- controls on downloads, local copies and shared mailboxes;
- backup protection and tested restoration;
- safe error messages that do not reveal whether a person or matter exists;
- notification delivery without sensitive details in the subject line; and
- a tested offboarding process for staff and suppliers.
Run a permission test using isolated test data, never a real client's file. Confirm that a receptionist, candidate attorney, practitioner, finance user, system administrator and external supplier can see only what their role requires. Test mobile use, failed uploads, duplicate submissions, link forwarding and account compromise scenarios.
If there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person, POPIA section 22 requires notification to the Information Regulator and, subject to limited delay grounds, the data subject as soon as reasonably possible after discovery. POPIA does not impose a general “72-hour” notification rule. The POPIA data-breach response checklist owns the detailed incident workflow.
Set an exact retention and deletion rule
“We keep information for as long as necessary” is a principle, not an operational schedule. Section 14 requires records not to be retained longer than necessary for the purpose unless an exception applies, including legal requirements, lawful functions, contractual need, consent or permitted historical, statistical or research use with safeguards.
Set a trigger and action for each intake state:
| Intake state | Retention decision to document |
|---|---|
| abandoned or spam enquiry | short security and operational period, then secure deletion |
| conflict-only enquiry | minimum conflict record, access restrictions and deletion of unnecessary narrative or files |
| declined instruction | period justified by conflict, complaint, professional, limitation or legal-risk needs |
| accepted client | transfer into the authorised client and matter record; remove intake duplicates |
| FIC record | retention required by the applicable FIC framework and the practice's programme |
| litigation hold or investigation | restriction against deletion, with owner, reason, scope and review date |
| supplier termination | verified return or deletion across production, exports and backups under the contract |
When retention is no longer authorised, destroy, delete or de-identify the information so that it cannot be reconstructed in an intelligible form. If accuracy is disputed or deletion must pause, assess restriction under section 14 instead of leaving an unmanaged duplicate.
Keep evidence of the rule, system action, exception and approval. A manual annual clean-up is not enough if every enquiry is silently copied into a permanent mailbox, spreadsheet, contact list and supplier dashboard.
Review cross-border storage and access
Identify where the intake form, email, practice-management system, analytics, backups and support personnel are located. Remote access from another country can be relevant even where the primary server is in South Africa.
POPIA section 72 restricts transfers to a recipient in a foreign country unless an applicable basis exists, such as adequate legal or binding protection, consent, contractual necessity or another listed ground. Record the basis, recipient, safeguards and onward-transfer controls. Do not describe a vendor as “POPIA compliant” solely because it publishes a security page or uses a familiar cloud provider.
Make the information officer controls real
The information officer and registered deputy information officers should have defined authority for the intake system. Current Information Regulator guidance ties the role to a compliance framework, personal-information impact assessments, PAIA manual compliance, internal request procedures and staff awareness.
For this workflow, assign owners for:
- approving fields, purposes and processing grounds;
- maintaining the section 18 notice;
- operator and cross-border review;
- access approvals and quarterly access review;
- retention exceptions and deletion evidence;
- data-subject access, correction and objection routes;
- security monitoring and incident escalation;
- staff training and change approval; and
- periodic personal-information impact reassessment.
The Regulator's current information-officer page states that its eServices registration portal is under construction and provides a manual registration form and email route. Verify the current channel at the time of action rather than relying on an old screenshot or cached instruction.
Test the full lifecycle before launch
Use synthetic test records created only for isolated testing. Do not copy a real prospective client's identity or evidence into a staging environment.
The release test should prove that:
- every field appears in the processing register;
- optional and required fields behave as described;
- the section 18 notice is available at collection and its version is recorded;
- conflict data is separated from detailed matter material;
- marketing is unbundled and off by default;
- special-information and child-data gates trigger correctly;
- the correct team receives the enquiry without sensitive content leaking into notifications;
- uploads reject unsafe types and cannot be accessed through a guessed or forwarded link;
- role permissions, audit events and administrator activity are recorded;
- supplier and cross-border routes match the approved data map;
- declined and abandoned enquiries enter the correct retention path;
- access, correction, objection and deletion requests reach an accountable owner;
- a suspected compromise reaches the incident team and operator notices can be reconciled; and
- the form does not claim that a mandate, deadline protection, conflict clearance, advice or outcome exists before the authoritative process confirms it.
Schedule a fresh review when a field, practice area, supplier, integration, AI feature, marketing use, office location or legal requirement changes. A form that passed once is not permanently compliant.
Questions for the practice's POPIA review
Ask:
- What exact intake stage and purpose does every field serve?
- Which section 11 ground applies to each purpose, and where is that assessment recorded?
- What information is needed for conflict screening before a mandate, and what should wait?
- Which FIC customer-due-diligence controls apply to this client or service?
- Could the form receive special personal information or children's information, and what gate applies?
- Has the section 18 notice been reconciled with the real systems, recipients and foreign access?
- Which suppliers are operators, and do section 21 contracts cover security, incidents, deletion and subprocessors?
- Who can access enquiries, exports, notifications and conflict records?
- What exact event starts each retention period, and how is deletion or restriction proved?
- Can the practice respond to access, correction, objection and security-compromise events from the records the system creates?
The commercial-law hub and commercial-lawyer directory can support an operational and contract review. Use the broader lawyer directory where the required experience spans information law, professional regulation, technology, FIC compliance or disputes.
Source and review note
This is general legal and operational information, not legal advice or a compliance certification. The source review covered POPIA, current Information Regulator guidance and forms, the 2025 POPIA Regulations amendment, the March 2026 health-information regulations, the Legal Practice Council Code of Conduct and current Financial Intelligence Centre material for legal practitioners. A qualified South African information-law, professional-regulation and FIC reviewer must verify the practice's processing grounds, notice, conflict duties, CDD controls, operator terms, special-information authorisations, foreign transfers, retention schedule and incident procedure before publication or implementation.
FAQs
Does a law firm need consent for every intake field?
No. POPIA section 11 provides several lawful grounds. A field may be necessary for requested pre-contract steps, a contract, a legal obligation, protection of an interest or a properly assessed legitimate interest. Use consent only where it is the real basis and the choice is voluntary, specific, informed and provable.
Can the first contact form ask for an identity document?
Only where the practice can justify collecting it at that stage. Many initial enquiries can be routed and conflict-checked without a copy of an identity document. Collect identity and verification records when the engagement, FIC or another defined process requires them, using an appropriately secure channel.
Is a link to the privacy policy enough?
Not automatically. The section 18 information must match the responsible party, purpose, mandatory or voluntary status, consequences, legal authority, recipients, cross-border position, rights and complaint route. A policy link does not cure a form or data flow that contradicts it.
May a prospective client describe the whole matter in a free-text box?
A practice should avoid inviting unnecessary detail before conflict and capacity checks. Use a short, constrained first-stage description and warn against submitting special information or documents prematurely. Request the fuller narrative through the controlled matter workflow if the practice can receive it.
Must declined enquiries be deleted immediately?
Not in every case. The practice may need a limited record for conflict, professional, complaint, limitation or legal-risk purposes. It should identify the lawful reason, restrict access, delete unnecessary narrative and files, set a review trigger and avoid permanent default retention.
Is a cloud form supplier responsible for POPIA compliance?
The supplier may be an operator, but the law practice remains accountable where it determines the purpose and means. The practice must assess the supplier, document instructions in a section 21 contract, control access and subprocessors, address cross-border transfers and reconcile incidents and deletion.
Does POPIA require breach notification within 72 hours?
POPIA does not set a general 72-hour period. Section 22 requires notification to the Regulator and affected data subjects as soon as reasonably possible after discovery, subject to its requirements and limited grounds for delayed data-subject notification. Preserve the chronology and obtain incident-specific advice.
Related Lexuno paths
Source notes
- Protection of Personal Information Act 4 of 2013
- Consolidated Protection of Personal Information Act
- Information Regulator: POPIA
- Information Regulator: Information Officers
- Guidance Note on Information Officers and Deputy Information Officers
- Regulations relating to the Protection of Personal Information Amendment, 2025
- Regulations on processing health information, 2026
- Legal Practice Council Code of Conduct
- Financial Intelligence Centre: Legal practitioners
- FIC: Drafting a risk management and compliance programme
- FIC Guidance Note 7A
- FIC Public Compliance Communication 47A
Legal note
This article is general legal information for South African readers. It is not legal advice. Speak to a qualified legal professional about your specific facts before taking action.

