POPIA and your stakeholder database
A register of interested and affected parties is a list of named people you are legally required to hold, made up of people who never asked to be on it. That's an unusual data protection problem, and POPIA answers it differently from GDPR. Here's what actually applies.
Written for environmental assessment practitioners, municipalities, mining companies and water use licence applicants who hold a register of interested and affected parties (I&APs).
If your system was built for GDPR, these four things will catch you
Most guidance on POPIA is written for customer databases. A stakeholder register is not a customer database, and four differences do all the work.
Consent is the wrong lens for statutory participation
A register populated by legal compulsion is not a consent-based record, and a product or a pitch built around consent capture misreads the regime.
Special personal information is prohibited by default
Race, political persuasion and trade union membership fall into this category under POPIA, and South African engagement records contain all three as a matter of routine practice.
Juristic persons are protected
POPIA defines personal information as relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person. Your organisation record is a data subject record in South Africa, with rights of access, correction and deletion attached. There is no UK or EU equivalent.
There is no adequacy mechanism
Cross-border transfer cannot rest on a government finding, because none exist. Every offshore hosting arrangement needs a bespoke binding agreement covering onward transfers, or South African data residency.
Why this matters now
The Information Regulator is enforcing. It issued an enforcement notice against the Department of Justice and Constitutional Development in May 2023, imposed its first administrative fine of R5 million in July 2023, and issued its first direct marketing enforcement notice in February 2024. The ceiling is R10 million in administrative fines and offences punishable by up to 10 years’ imprisonment, alongside a civil damages action under section 99 that requires no proof of intent or negligence.
Why a stakeholder register breaks the usual rules
You didn't collect these records. Regulation 42 of the environmental impact assessment (EIA) Regulations 2014 requires the applicant to open and maintain a register of everyone who submitted written comments or attended meetings during public participation, everyone who asked in writing to be added, and all organs of state with jurisdiction. Regulation 18 of the Water Use Licence Application and Appeals Regulations requires the same for a water use licence, maintained during processing and for two years after the licence is issued. The Mineral and Petroleum Resources Development Act (MPRDA) Regulations require consultation with mine communities, traditional councils, land claimants, lawful occupiers and holders of informal rights, all of whom end up in the record.
Deletion requests still have to be handled, but they're weighed against your duty to keep the record. Section 14 allows retention where a law requires it, and the register has to stay open for inspection, be supplied to the competent authority on request, and remain intact for registered I&APs whose appeal rights depend on being on it.
And a good proportion of the people in it are objectors. They are on the register because they disagree with you. Consent isn't what put them there and consent is not what keeps them there.
POPIA sets eight conditions for lawful processing in Chapter 3, and a stakeholder register can satisfy all eight. Three of them are where the design decisions actually sit: processing limitation, because your lawful basis is not consent; further processing limitation, because an EIA record must not drift into a marketing list; and security safeguards, because the operator contract and the breach notification duty are statutory preconditions rather than commercial courtesies. The rest is documentation.
Your lawful basis is the law, not consent
Section 11 provides six justifications for processing personal information. For statutory public participation, two of them do the work: section 11(1)(c), processing complies with an obligation imposed by law on the responsible party, and section 11(1)(e), processing is necessary for the proper performance of a public law duty by a public body.
If Regulation 42 obliges you to keep the register, section 11(1)(c) is your basis. If you are a municipality discharging Chapter 4 of the Municipal Systems Act, section 11(1)(e) is available to you as well. Neither is withdrawable.
That matters practically. A register built on consent collapses the moment an objector withdraws it, and you are left unable to hold a record you are legally required to maintain and legally required to produce. Consent belongs in exactly one place in this picture, and that is direct marketing.
Whatever your basis, section 18 requires you to tell the data subject at the point of collection what you are collecting and why, where you got it if not from them, whether supply is voluntary or mandatory, whether the information will leave South Africa and what protection applies there, and what their rights are. In system terms, that means a configurable collection notice on every registration form, comment form and Background Information Document reply slip, versioned, with a record of which notice each I&AP actually received.
Prohibited by default, and already in your record
This is the sharpest exposure in South African engagement data and it is almost universally missed.
Sections 26 to 33 prohibit the processing of special personal information unless a general authorisation under section 27, a specific authorisation under sections 28 to 33, or Information Regulator authorisation applies. The categories are religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour.
Three of those are structural features of South African engagement practice, not accidents.
- Race and ethnic origin is recorded for broad-based black economic empowerment (B-BBEE) scorecards, social and labour plan (SLP) demographic reporting, community trust beneficiary verification and employment equity.
- Political persuasion is inherent in recording ward councillors, party structures, community forums and the affiliations of stakeholder contacts.
- Trade union membership sits in the record by design, because SLP consultation involves unions and their representatives.
A stakeholder database built for UK GDPR treats these as ordinary fields. Under POPIA the default position is prohibition and the justification has to be positively identified. What that requires in a system is not a policy document. It is field-level access control, so the fields carrying special personal information are visible only to the roles that need them, and a recorded justification that survives an audit.
One more difference with no UK equivalent. Section 57 requires the Information Regulator’s prior authorisation before transferring special personal information, or the personal information of children, to a foreign country that does not provide an adequate level of protection. Read alongside section 72 and the absence of any adequacy list, that is a live question for anyone hosting a South African engagement record offshore.
A ratepayers’ association is a data subject
POPIA’s extension to juristic persons has no equivalent in UK or EU law, so the organisation records in your register are not neutral reference data.
A ratepayers’ association named in EIA Regulation 41 as a mandatory notice recipient, a community trust holding Renewable Energy Independent Power Producer Procurement Programme (REIPPPP) equity, a communal property association, a traditional council, a non-profit company objecting to an application: each is a data subject with rights of access, correction and deletion, and each is entitled to the section 18 notification.
Practically, the organisation record needs the same treatment as the contact record: a lawful basis, a retention position, an audit trail, and a route to respond to a request. If your system treats organisation as a lookup table, it is not built for South Africa.
A statutory notice isn't marketing, a newsletter to the same list is
Section 69 prohibits direct marketing by unsolicited electronic communication unless the data subject has consented, requested on the prescribed Form 4 of the POPIA Regulations and requested only once, or is an existing customer whose details were obtained in the context of an actual sale, where the marketing is for your own similar products or services and they were given a free and easy opportunity to object at collection and on every occasion a communication is sent.
The Information Regulator issued its first direct marketing enforcement notice in February 2024 and read the existing-customer exception narrowly on all three limbs.
For an engagement team, the line falls here.
| Communication | Direct marketing? | Basis |
|---|---|---|
| Notice of an EIA application to a registered I&AP | No | Section 11(1)(c), legal obligation |
| Invitation to a statutory public meeting | No | Section 11(1)(c) |
| Comments and responses report circulated to registered I&APs | No | Section 11(1)(c) |
| integrated development plan (IDP) or budget consultation notice from a municipality | No | Section 11(1)(e), public law duty |
| Project newsletter with no statutory trigger | Yes | Section 69 |
| Invitation to a corporate event or webinar | Yes | Section 69 |
| Anything promoting your organisation’s services | Yes | Section 69 |
The system requirement is that the two are separated at the point of sending, that opt-in and objection state is held per recipient and per purpose, and that there is an audit trail showing which basis applied to which send. Blending them is not a policy slip, it is an enforcement notice.
Section 72, and why there is no easy answer on hosting
Section 72 permits transfer of personal information out of South Africa on five grounds. The one that carries commercial weight is the first: the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection that upholds principles substantially similar to POPIA’s conditions, including provisions substantially similar to section 72 governing onward transfers.
South Africa has no adequacy decision mechanism. The Information Regulator has issued no guidance on adequacy criteria and designated no approved jurisdictions. So this route has to be built contractually, case by case, and South African practitioners generally default to a transfer agreement modelled on GDPR standard contractual clauses, adapted for POPIA’s extension to juristic persons and for the onward-transfer requirement.
The other four grounds are weaker for a register. Consent is withdrawable and, again, objectors did not consent. The contract grounds do not describe the relationship between a municipality and an adjacent landowner. And transfer for the benefit of the data subject where consent is not reasonably practicable is not a foundation on which to build a procurement answer.
South African law has no general data localisation requirement. But the National Policy on Data and Cloud, gazetted in 2024, promotes government data classification and residency in policy terms, and departments and state-owned entities increasingly include in-country hosting in ICT tenders. Treat South African data residency as a de facto requirement for public sector and state-owned entity deals.
Where Tractivity stands. We run on Microsoft Azure with UK data residency by default, and European, US and other regions available. If your record holds special personal information, section 57 may require the Information Regulator's authorisation before it's hosted outside South Africa, so raise it at the outset, along with any in-country hosting requirement in your tender. We'll confirm in writing what we can deliver for your deployment, rather than give you a marketing answer.
The operator agreement is a legal requirement, not a courtesy
When you buy stakeholder engagement software, you are the responsible party and the vendor is the operator.
Section 20 says an operator may process only with your knowledge or authorisation and must treat the information as confidential. Section 21 requires the relationship to be governed by a written contract obliging the operator to establish and maintain the section 19 security measures, and to notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Section 22 then places the notification duty on you: notify the Information Regulator and the affected data subjects as soon as reasonably possible, with enough information for them to take protective measures.
Two questions worth asking any vendor. Will you sign a POPIA operator agreement, or are you offering a UK GDPR data processing agreement with the word POPIA inserted? They are not the same document: the onward-transfer provisions, the juristic person extension and the immediate-notification wording all differ. And what does immediately mean in your contract, in hours?
Where Tractivity stands. Ask us for the operator agreement as part of your assessment and we will answer in writing, including the notification window we will commit to. We would rather agree that in the contract than publish a number we have not tested against your requirement.
What a compliant system looks like
Use this list to brief your procurement or security review.
- Lawful basis recorded per record and per purpose, not assumed
- Configurable, versioned section 18 collection notices on every registration and comment route, with a record of which notice each data subject received
- Field-level access control so special personal information is visible only to the roles that need it, with a recorded justification
- Juristic person records treated as data subject records, not lookup data
- Opt-in and objection state held per recipient and per purpose, with objection honoured on every send
- Statutory communications and marketing communications separated at the point of sending, with an audit trail of which basis applied
- Retention rules that can differ by record type, because a water use licence register has a statutory two-year tail and an EIA record has to survive the appeal window
- Access, correction and deletion workflow that can be evidenced
- Encryption at rest and in transit, and a stated hosting region
- A written operator agreement meeting section 21, with an immediate breach notification obligation
- A full date-stamped audit trail, exportable, because both the Promotion of Access to Information Act (PAIA) and the Promotion of Administrative Justice Act (PAJA) will ask for it
Where Tractivity stands, briefly. Role-based permissions operate at project, module and record level. Every record carries a date-stamped audit trail and exports to Word, Excel and PDF. The Mailshot module validates every address and checks opt-in before a send goes out. The Enquiries module handles complaints, grievances, project feedback and access-to-information requests as a categorised, date-stamped process. For the rest of this list, send us your questionnaire and we'll answer each point in writing. Our security certifications and hosting details are on our data security and compliance page.
Bring us your security questionnaire
Tractivity is a stakeholder relationship management platform used in South Africa, the UK and Europe to maintain a register of interested and affected parties, record every engagement against the relevant party, produce comments and responses reports, track commitments, and manage grievances.
If you are assessing a stakeholder engagement platform against POPIA, send us the questionnaire and we will answer it in writing, including the parts where the answer is not yet. A call is usually faster than three rounds of email.
To compare the two regimes, we have written the same analysis for GDPR-ready stakeholder databases.
This page is written for practitioners and is not legal advice. POPIA compliance depends on your own processing and your own contracts, and you should take advice from a qualified South African practitioner. Statutory references are to the Protection of Personal Information Act 4 of 2013 and the POPIA Regulations as at September 2026.
Frequently asked questions
No. Consent is the wrong lawful basis for a statutory register. Section 11 of POPIA provides six justifications for processing, and the relevant ones for public participation are compliance with an obligation imposed by law and processing necessary for the proper performance of a public law duty by a public body. Regulation 42 of the EIA Regulations 2014 compels the applicant to open and maintain the register, so the register exists by legal obligation, not by consent. Relying on consent creates a withdrawable basis for a record you are required to keep.
Yes. POPIA defines personal information as information relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person. A ratepayers’ association, a community trust, a non-profit company, a traditional council or a corporate objector is a data subject with rights of access, correction and deletion. There is no equivalent provision in UK or EU data protection law, so a stakeholder system designed for GDPR will treat these as ordinary organisation records.
Only with a positive justification. Sections 26 to 33 of POPIA prohibit the processing of special personal information unless a general authorisation under section 27, a specific authorisation under sections 28 to 33, or Information Regulator authorisation applies. Race or ethnic origin, political persuasion and trade union membership are all special personal information, and South African engagement records routinely contain all three: race for B-BBEE and SLP demographic reporting, political persuasion in recording ward councillors and party structures, and union membership because SLP consultation involves unions by design. The practical requirement is field-level access control and a recorded justification.
Yes, but not automatically. Section 72 permits transfer where the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection that upholds principles substantially similar to POPIA conditions and includes provisions substantially similar to section 72 governing onward transfers. South Africa has no adequacy list and the Information Regulator has designated no approved jurisdictions, so this route has to be built contractually in each case. Consent is a weak alternative for a register populated by people who did not ask to be on it.
No. A statutory notice sent to an I&AP under the EIA Regulations is processing for compliance with a legal obligation, not direct marketing, and section 69 does not apply to it. A newsletter or a service promotion sent to the same list is direct marketing and section 69 does apply, which means either consent requested on the prescribed Form 4, or the narrow existing-customer exception. The two must be separated in the system, with opt-in and objection state held per recipient and per purpose, and an audit trail. The Information Regulator’s first direct marketing enforcement notice in February 2024 confirmed the existing-customer exception requires an actual prior sale, permits only similar offerings, and requires an objection opportunity on every occasion.
Administrative fines of up to R10 million and offences punishable by up to 10 years’ imprisonment. The Information Regulator imposed its first administrative fine, R5 million, on 3 July 2023 against the Department of Justice and Constitutional Development following a security compromise involving the loss of approximately 1,204 files. Data subjects also have a civil damages action under section 99 that does not require proof of intent or negligence.
