POPIA and client data: what every South African law firm must have in place
Law firms are unusual data processors. They collect and hold some of the most sensitive personal information that exists - financial details, family disputes, criminal matters, health information connected to personal injury claims - under a duty of confidentiality that predates data protection law by centuries. POPIA adds a statutory compliance layer to that existing professional duty. The two frameworks do not conflict: they reinforce each other. But POPIA creates specific obligations that the legal profession's traditional confidentiality principles do not fully address.[1]
Which POPIA obligations are most critical for law firms?
Information Officer registration
Every organisation must appoint and register an Information Officer. For law firms, the managing partner is the default IO. Registration is done through the Information Regulator's eServices portal. The April 2025 amendments expanded IO responsibilities to include active ongoing oversight of a compliance programme - this is now a substantive role, not a nominal one.[2]
Written operator agreements
Any third party that processes personal information on your instruction is an "operator" under POPIA (s. 1). This includes your hosted email provider, your practice management system, your cloud storage provider, your CRM, and your document management platform. Section 21 requires a written agreement with each operator prescribing the processing terms and the operator's obligations. Most firms have no such agreements.
Retention schedules and deletion
POPIA's storage limitation condition (s. 14) prohibits retaining personal information longer than is necessary for the purpose for which it was collected. For law firms, the limitation period for most civil matters is three years from the date on which the debt became due (Prescription Act 68 of 1969). File retention policies should be informed by both the Prescription Act and the firm's professional obligations - but retention should not be indefinite by default.
Security: the higher bar for law firms
The sensitivity of client information means law firms face a higher practical expectation under POPIA's security safeguard condition (s. 19) than most SMBs. At minimum:
- Encrypted storage for all client files
- Multi-factor authentication on email and practice management systems
- Documented access controls - who can access what, under what circumstances
- A written, tested breach response procedure that ends with eServices portal notification
- Regular software updates to prevent known vulnerabilities
Data subject rights
The April 2025 amendments tightened data subject rights. Clients can request access to their personal information, correction of inaccurate data, and deletion (subject to lawful grounds for retention). These requests must be acknowledged and responded to within 30 days. A firm with no documented process for handling such requests is directly non-compliant with the amended regulations.[3]
Practical compliance checklist for law firms
| Obligation | What is required | POPIA reference |
|---|---|---|
| IO registration | IO registered on eServices portal | s. 55; April 2025 amendments |
| Operator agreements | Written agreements with all third-party processors | s. 21 |
| Privacy policy | POPIA-compliant; IO named; processors listed | ss. 17–18 |
| PAIA manual | Published on website; kept current | PAIA s. 51 |
| Retention schedule | Documented; applied consistently | s. 14 |
| Breach procedure | Written, tested, portal access confirmed | s. 22; April 2025 amendments |
| Data subject requests | Process documented; 30-day response window | ss. 23–25; April 2025 amendments |
Frequently asked questions
Does legal professional privilege protect law firms from POPIA?
No. Legal professional privilege governs disclosure in legal proceedings and the attorney-client relationship. POPIA is a separate statutory framework governing how personal information is collected and processed. The two can overlap - but privilege is not a defence to POPIA non-compliance.
Can a law firm use client data to market its other services?
Only with separate, explicit consent for that specific use. The fact that a client instructed the firm on a conveyancing matter does not constitute consent to receive marketing about the firm's litigation services.