Quick answer
A South African business should involve a privacy lawyer when it must make a legal classification or accept material risk, not only after something has gone wrong. Typical triggers include a new high-risk product or data use, a major operator or cross-border contract, possible prior authorisation, special or children’s information, automated or direct-marketing decisions, a security compromise, a data-subject dispute, an Information Regulator process, an acquisition or a threatened claim.
Key takeaways
- A South African business should involve a privacy lawyer when it must make a legal classification or accept material risk, not only after something has gone wrong. Typical triggers include a new high-risk product or data use, a major operator or cross-border contract, possible prior authorisation, special or children’s information, automated or direct-marketing decisions, a security compromise, a data-subject dispute, an Information Regulator process, an acquisition or a threatened claim.
- Routine compliance remains an operational responsibility. The information officer, business owner, security team, product lead, HR, procurement and records owners must know what information is processed, why, where it goes, who can access it and when it is deleted. A lawyer can interpret the law, structure decisions, review contracts, advise on notifications and disputes, and help preserve legal advice appropriately. The lawyer cannot replace technical containment, data mapping, access control, staff ownership or truthful evidence.
- Do not wait for a complete audit if a live incident, regulator communication, court paper or statutory approval question exists. Protect people and systems, preserve records and obtain focused advice in parallel.
Use a risk trigger, not the size of the business
POPIA applies to public and private responsible parties within its scope. A small business can process high-risk health, biometric, child, financial or criminal-allegation information. A large organisation can also have low-risk routine tasks that do not require a lawyer at every meeting.
Use the decision involved:
| Situation | Operational owner | When legal input becomes important |
|---|---|---|
| Routine data inventory or access review | information officer, security and process owner | the purpose, lawful ground, retention authority or role classification is disputed |
| New website form or policy update | product, marketing and information officer | the notice, consent model, direct marketing or third-party data use is legally uncertain |
| New cloud, AI, payroll or verification supplier | procurement, security and system owner | responsible-party and operator roles, foreign access, reuse, subprocessors or liability terms are material |
| High-risk product or analytics change | executive sponsor, product, security and information officer | special information, children, unique identifiers, automated decisions, surveillance or prior authorisation may be involved |
| Security compromise | incident lead, security, information officer and management | section 22 classification, notices, law-enforcement interaction, contracts, affected people or possible claims require advice |
| Complaint, assessment or enforcement process | information officer and accountable executive | allegations, evidence, formal responses, remedial commitments or litigation exposure must be managed |
A lawyer should be given a defined decision, not a request to “make us POPIA compliant.” No one document or opinion can certify every system, employee, supplier and processing activity indefinitely.
Build the operating record before seeking an opinion
POPIA places accountability on the responsible party. The Information Regulator’s current guidance connects the information-officer role to a compliance framework, personal-information impact assessments, PAIA manual controls, request procedures and staff awareness.
Before the first legal review, prepare:
- the responsible party and relevant business entities;
- the information officer and registered deputies;
- a data and system map for the activity in question;
- the categories of people and personal information;
- purposes and proposed section 11 processing grounds;
- collection notices, policies and consent records where used;
- responsible-party, joint-responsibility and operator assumptions;
- supplier contracts, subprocessors and hosting or support locations;
- access roles, security measures and audit records;
- retention rules, holds and deletion evidence;
- data-subject requests, complaints or prior findings; and
- the exact approval, contract, incident or dispute decision required.
Do not manufacture missing records before review. Mark what is confirmed, what a supplier says, what a technical log shows and what remains unknown. The lawyer’s analysis is only as reliable as the operating facts supplied.
Involve counsel before launching high-risk processing
Early advice is valuable when changing what the business collects or how it uses information. A privacy lawyer can help the project team test:
- who determines the purpose and means of processing;
- whether POPIA and any sector-specific rule apply;
- whether the purpose is specific and compatible with later use;
- which lawful ground supports each purpose;
- whether collection is direct and what section 18 information must be given;
- whether the information is adequate, relevant and not excessive;
- whether special personal information or children’s information is involved;
- whether profiling, automated decisions, direct marketing or surveillance creates added restrictions;
- whether section 57 prior-authorisation categories may be triggered;
- whether section 72 permits a proposed foreign transfer; and
- what retention, access, objection, correction and incident controls must be implemented.
The Information Regulator maintains a current prior-authorisation route for specified section 57 processing, including defined uses of unique identifiers, criminal-behaviour information on behalf of third parties, credit-reporting activity and certain foreign transfers of special or children’s information. Do not assume that every sensitive project requires prior authorisation or that a generic consent removes the issue. Classify the actual processing before it starts.
The POPIA notice and privacy policy are public references, not substitutes for a data map and activity-specific review. Published wording must match the real systems, recipients and purposes.
Review important operator and cross-border contracts
Technology procurement can create privacy obligations that a standard service agreement does not resolve. Section 21 requires a written contract where an operator processes personal information for a responsible party, with obligations concerning the section 19 security measures. Section 72 separately governs transfers to recipients in foreign countries.
Ask counsel to review the contract against the verified service architecture, including:
- which party decides each purpose and processing method;
- permitted use and prohibited independent reuse;
- data categories, locations and remote support access;
- subprocessors and change notification;
- security standards, assurance and remediation;
- operator incident notification and cooperation;
- data-subject and Regulator request support;
- retention, return, deletion and backup treatment;
- audit evidence and service-transition assistance;
- indemnities, limitations, insurance and responsibility for notices; and
- the lawful basis and safeguards for foreign transfers and onward transfers.
Calling a supplier “POPIA compliant” does not answer these questions. A lawyer should work with security, procurement and the system owner; legal clauses cannot correct an undisclosed subprocessor, uncontrolled administrator or untested deletion process.
The commercial-law hub provides the wider contract and governance context. The commercial-lawyer route can support discovery where privacy, technology and supplier-contract experience overlap.
Get immediate advice during a security compromise
If there are reasonable grounds to believe that an unauthorised person accessed or acquired personal information, section 22 may require notice to the Information Regulator and affected data subjects. POPIA uses “as soon as reasonably possible” after discovery; it does not impose a general 72-hour rule. Other laws, contracts or foreign regimes may create separate deadlines.
Do not delay containment while waiting for counsel. The incident team should secure systems, preserve volatile evidence, identify affected processing, control communications and document decisions. Legal input can help with:
- responsible-party and operator roles;
- the statutory security-compromise test;
- the notification chronology and current submission route;
- content and sequencing of notices;
- law-enforcement or regulator interaction;
- contractual notification and cooperation duties;
- employee, customer and supplier communications;
- preservation, privilege and disclosure questions; and
- complaints, claims and remediation commitments.
Not every incident document becomes privileged because a lawyer joins the call. Define the legal instruction, keep factual and technical evidence intact, use accurate distribution controls and obtain advice on the treatment of each workstream.
The Information Regulator’s 2025 fact sheet says the responsible party reports security compromises even where the assessed risk is low, while an operator notifies the responsible party. Its current materials direct section 22 submissions through eServices. The POPIA data-breach response checklist owns the operational incident sequence.
Escalate complaints, investigations and contested rights requests
Routine access, correction, deletion, restriction and objection requests should have an internal process. Involve a lawyer when the business cannot identify the correct record holder, a refusal ground or retention duty is contested, third-party or privileged material is involved, litigation is pending, the requester challenges identity verification, or the response could affect a wider group.
Obtain prompt advice for:
- a POPIA complaint or assessment request from the Information Regulator;
- a notice, summons, warrant or enforcement step;
- a demand alleging unlawful collection, disclosure, marketing or automated decision-making;
- a request that conflicts with a preservation duty, court process or third-party rights;
- repeated requests revealing a systemic failure; or
- threatened urgent relief or a section 99 damages claim.
Preserve the original communication, delivery evidence, complete data-subject history, policies actually in force, relevant system and audit records, prior responses and remedial action. Do not backdate a policy or overwrite the state of the system that produced the complaint.
The Regulator publishes current POPIA forms for objections, correction or deletion, complaints, prior authorisation and security-compromise notifications. A responsible party’s section 22 report and a data subject’s complaint are different processes.
Add legal review to major business changes
A change in ownership, operating model or data source can alter the privacy position even if the database stays in place. Include privacy counsel when a transaction or restructuring involves:
- disclosure of employee, customer or supplier data in due diligence;
- sale, migration or combination of a customer database;
- a new group company, shared service or foreign support centre;
- new advertising, data enrichment or lead acquisition;
- biometrics, workplace monitoring or location tracking;
- AI training, inference, scoring or automated workflow decisions;
- health, financial, child or criminal-allegation information;
- a new retention, archive or legal-hold model; or
- inherited complaints, undertakings, incidents or Regulator findings.
Use staged access, redaction where appropriate, a controlled data room, purpose limits and a transfer or migration plan. A commercial transaction does not suspend POPIA or convert every disclosure into a lawful use.
Choose the right privacy lawyer and mandate
“Privacy lawyer” is a functional description, not proof of a regulated specialisation. Verify the proposed practitioner through the Legal Practice Council and compare experience against the work required.
Ask about:
- POPIA advice for the relevant industry and processing model;
- operator and technology contracting;
- Information Regulator complaints, assessments and enforcement;
- security-compromise response and notification;
- PAIA and data-subject rights requests;
- employment, consumer, financial, health or other sector rules involved;
- cross-border processing and foreign-law coordination;
- technical evidence and work with security specialists;
- dispute, urgent-application and damages experience where relevant; and
- who will perform the work, report decisions and protect urgent dates.
The first written scope should name the decision, systems, entities, jurisdictions, deliverables, assumptions, excluded implementation work, responsible team, fee basis, external specialists, target dates and review point. For an incident, it should also identify the communications, forensic and notification workstreams and who holds final operational authority.
Use the broader lawyer directory and law-firms directory to discover providers, but do not treat a listing, review or profile as proof of practising status, privacy experience, independence, availability or fit.
Questions for the first privacy-law consultation
Ask:
- What exact decision or event requires advice now?
- Which entity is the responsible party for each processing purpose?
- Which factual assumption is unverified and could change the legal conclusion?
- Does a sector law, code, foreign regime or contract add to POPIA?
- Is prior authorisation, a Regulator submission or a data-subject notice potentially required?
- Which operational control must exist before the legal recommendation can be implemented?
- What should the board, information officer, security team, product owner or supplier decide?
- Which records must be preserved, restricted or produced?
- What can be completed internally, and what needs specialist legal, forensic or security work?
- What event triggers the next review?
The useful outcome is a decision record with owners and evidence, not a generic compliance label.
FAQs
Does every business need a privacy lawyer on retainer?
No general POPIA rule requires every business to keep a privacy lawyer on retainer. The business remains accountable for its processing and operational controls. Legal support is most useful when a material classification, contract, approval, incident, complaint, transaction or dispute needs independent legal analysis.
Can a lawyer replace the information officer or security team?
Not as a complete operating model. The information officer has statutory and regulatory duties, while security and system teams implement and test controls. A lawyer can advise those roles, structure decisions and handle legal work, but cannot substitute for factual ownership, incident containment or access management.
Does POPIA require every data breach to be reported within 72 hours?
POPIA does not state a general 72-hour period. Section 22 uses “as soon as reasonably possible” after discovery. The Regulator’s current position is that responsible parties report security compromises regardless of assessed risk. Other laws or contracts may add separate deadlines.
Does an operator agreement transfer POPIA responsibility to the supplier?
No. A section 21 contract is required for operator security obligations, but the responsible party remains accountable for processing it controls. The contract should match the real service, subprocessors, locations, security, incidents, rights support, deletion and foreign transfers.
When might prior authorisation be required?
Only the specified section 57 categories trigger POPIA prior authorisation. They include defined uses of unique identifiers, criminal-behaviour processing on behalf of third parties, credit-reporting processing and certain transfers of special or children’s information to countries without adequate protection. Obtain activity-specific advice before processing starts.
Can a privacy lawyer certify that a business is fully POPIA compliant?
A lawyer can give a scoped opinion based on stated facts and assumptions. That is not a permanent certification of every employee, system, supplier and processing activity. The business must implement, test, monitor and update the controls on which the advice depends.
What should I bring to the first privacy-law consultation?
Bring the entity and information-officer details, data and system map, processing purposes and grounds, notices, supplier contracts, security and retention controls, cross-border routes, complaints or incident records, and the exact decision required. Mark missing or disputed facts instead of guessing.
Related Lexuno paths
Source notes
- Protection of Personal Information Act 4 of 2013
- Consolidated Protection of Personal Information Act
- Information Regulator: POPIA
- Information Regulator: Information Officers
- Information Regulator: Prior Authorisation
- Information Regulator fact sheet: handling security compromises
- Regulations relating to the Protection of Personal Information Amendment, 2025
- Information Regulator: POPIA forms
Legal note
This article is general legal information for South African readers. It is not legal advice. Speak to a qualified legal professional about your specific facts before taking action.

