<img src="https://secure.leadforensics.com/85165.png" alt="" style="display:none;">
Skip to content
Everything your engagement programme runs on, in one system, from register to report.
Every feature, mapped to how a South African participation process actually runs.
Log grievances, track issues and commitments, and report them by type.
ISO 27001, Cyber Essentials Plus, and a straight answer on POPIA, hosting and cross-border transfer.
Run comment windows and surveys, with every response held against the person who made it.
150+ pre-built reports and dashboards, including the comments and responses report.
A named Client Success Manager, unlimited support, and a four to six week implementation.
Map interested and affected parties against the categories the law actually names.
The public side of the process: documents, comments and self-registration, priced separately.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Social and labour plan consultation, mine communities, traditional councils, informal rights.
IDP and budget participation, ward committees, and the duty to report back.
Licence participation and a register you keep during processing and for two years after.
Transmission corridors, renewables and community trusts, across project lives measured in decades.
Corridor-scale engagement across rail, ports and third-party network access.
Run every client project from one system, with the evidence pack ready when the authority asks.
The EIA Regulations mapped to the system, from first notice to comments and responses report.
Notice, representations and reasons, recorded well enough to survive a PAJA review.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Read our customer success stories and discover how our clients are delivering impact with Tractivity.
The step-by-step guide to building an effective stakeholder engagement plan, with template.
Views and insights from engagement experts, recorded at our events and free to watch.
Helpful tips, guides and articles about stakeholder engagement, project management and more.
Learn how to identify, categorise and prioritise your stakeholders with our complete guide.
Empower sustainable engagement with AccountAbility's framework and Tractivity's system.
Free guides, whitepapers, templates and more to help you deliver sustainable outcomes.
Understand your stakeholders' needs, interests and influence with our practical framework.
What POPIA means for a register of interested and affected parties, answered in full.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Rate your organisation across five categories in minutes and get an instant, tailored score.
Calculate the time your team loses to manual admin into a defensible number for the board.
What POPIA means for a register of interested and affected parties, answered in full.
A six-part toolkit for planning, running and documenting your stakeholder engagement.
The legal test for fair public participation, and a self-audit to find where yours is weak.
Free, practical resources for managing engagement and running public participation well.
You’re the expert. We’re the software, and the home of stakeholder engagement.
dropdown-demo-2
Learn why leading organisations trust Tractivity.
Our annual Stakeholder Engagement Day, held in the United Kingdom and open to anyone working in engagement.
The 2026 event is coming soon. Held in the United Kingdom, with sessions worth watching wherever you are.
Talks and presentations from the 2025 event, free to watch online.
Keynotes and real-world case studies from the 2024 summit, online.
Sessions and insights from our first live event, online.

POPIA and your stakeholder database

A register of interested and affected parties is a list of named people you are legally required to hold, made up of people who never asked to be on it. That's an unusual data protection problem, and POPIA answers it differently from GDPR.  Here's what actually applies.

Written for environmental assessment practitioners, municipalities, mining companies and water use licence applicants who hold a register of interested and affected parties (I&APs).

If your system was built for GDPR, these four things will catch you

Most guidance on POPIA is written for customer databases. A stakeholder register is not a customer database, and four differences do all the work.

1

Consent is the wrong lens for statutory participation

A register populated by legal compulsion is not a consent-based record, and a product or a pitch built around consent capture misreads the regime.

2

Special personal information is prohibited by default

Race, political persuasion and trade union membership fall into this category under POPIA, and South African engagement records contain all three as a matter of routine practice.

3

Juristic persons are protected

POPIA defines personal information as relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person. Your organisation record is a data subject record in South Africa, with rights of access, correction and deletion attached. There is no UK or EU equivalent.

4

There is no adequacy mechanism

Cross-border transfer cannot rest on a government finding, because none exist. Every offshore hosting arrangement needs a bespoke binding agreement covering onward transfers, or South African data residency.

Each is set out below, with what it means for a system.

Why this matters now

The Information Regulator is enforcing. It issued an enforcement notice against the Department of Justice and Constitutional Development in May 2023, imposed its first administrative fine of R5 million in July 2023, and issued its first direct marketing enforcement notice in February 2024. The ceiling is R10 million in administrative fines and offences punishable by up to 10 years’ imprisonment, alongside a civil damages action under section 99 that requires no proof of intent or negligence.

Why a stakeholder register breaks the usual rules

You didn't collect these records. Regulation 42 of the environmental impact assessment (EIA) Regulations 2014 requires the applicant to open and maintain a register of everyone who submitted written comments or attended meetings during public participation, everyone who asked in writing to be added, and all organs of state with jurisdiction. Regulation 18 of the Water Use Licence Application and Appeals Regulations requires the same for a water use licence, maintained during processing and for two years after the licence is issued. The Mineral and Petroleum Resources Development Act (MPRDA) Regulations require consultation with mine communities, traditional councils, land claimants, lawful occupiers and holders of informal rights, all of whom end up in the record.

Deletion requests still have to be handled, but they're weighed against your duty to keep the record. Section 14 allows retention where a law requires it, and the register has to stay open for inspection, be supplied to the competent authority on request, and remain intact for registered I&APs whose appeal rights depend on being on it.

And a good proportion of the people in it are objectors. They are on the register because they disagree with you. Consent isn't what put them there and consent is not what keeps them there.

POPIA sets eight conditions for lawful processing in Chapter 3, and a stakeholder register can satisfy all eight. Three of them are where the design decisions actually sit: processing limitation, because your lawful basis is not consent; further processing limitation, because an EIA record must not drift into a marketing list; and security safeguards, because the operator contract and the breach notification duty are statutory preconditions rather than commercial courtesies. The rest is documentation.

Your lawful basis is the law, not consent

Section 11 provides six justifications for processing personal information. For statutory public participation, two of them do the work: section 11(1)(c), processing complies with an obligation imposed by law on the responsible party, and section 11(1)(e), processing is necessary for the proper performance of a public law duty by a public body.

If Regulation 42 obliges you to keep the register, section 11(1)(c) is your basis. If you are a municipality discharging Chapter 4 of the Municipal Systems Act, section 11(1)(e) is available to you as well. Neither is withdrawable.

That matters practically. A register built on consent collapses the moment an objector withdraws it, and you are left unable to hold a record you are legally required to maintain and legally required to produce. Consent belongs in exactly one place in this picture, and that is direct marketing.

Whatever your basis, section 18 requires you to tell the data subject at the point of collection what you are collecting and why, where you got it if not from them, whether supply is voluntary or mandatory, whether the information will leave South Africa and what protection applies there, and what their rights are. In system terms, that means a configurable collection notice on every registration form, comment form and Background Information Document reply slip, versioned, with a record of which notice each I&AP actually received.

Prohibited by default, and already in your record

This is the sharpest exposure in South African engagement data and it is almost universally missed.

Sections 26 to 33 prohibit the processing of special personal information unless a general authorisation under section 27, a specific authorisation under sections 28 to 33, or Information Regulator authorisation applies. The categories are religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour.

Three of those are structural features of South African engagement practice, not accidents.

  • Race and ethnic origin is recorded for broad-based black economic empowerment (B-BBEE) scorecards, social and labour plan (SLP) demographic reporting, community trust beneficiary verification and employment equity.
  • Political persuasion is inherent in recording ward councillors, party structures, community forums and the affiliations of stakeholder contacts.
  • Trade union membership sits in the record by design, because SLP consultation involves unions and their representatives.

A stakeholder database built for UK GDPR treats these as ordinary fields. Under POPIA the default position is prohibition and the justification has to be positively identified. What that requires in a system is not a policy document. It is field-level access control, so the fields carrying special personal information are visible only to the roles that need them, and a recorded justification that survives an audit.

One more difference with no UK equivalent. Section 57 requires the Information Regulator’s prior authorisation before transferring special personal information, or the personal information of children, to a foreign country that does not provide an adequate level of protection. Read alongside section 72 and the absence of any adequacy list, that is a live question for anyone hosting a South African engagement record offshore.

A ratepayers’ association is a data subject

POPIA’s extension to juristic persons has no equivalent in UK or EU law, so the organisation records in your register are not neutral reference data.

A ratepayers’ association named in EIA Regulation 41 as a mandatory notice recipient, a community trust holding Renewable Energy Independent Power Producer Procurement Programme (REIPPPP) equity, a communal property association, a traditional council, a non-profit company objecting to an application: each is a data subject with rights of access, correction and deletion, and each is entitled to the section 18 notification.

Practically, the organisation record needs the same treatment as the contact record: a lawful basis, a retention position, an audit trail, and a route to respond to a request. If your system treats organisation as a lookup table, it is not built for South Africa.

A statutory notice isn't marketing, a newsletter to the same list is

Section 69 prohibits direct marketing by unsolicited electronic communication unless the data subject has consented, requested on the prescribed Form 4 of the POPIA Regulations and requested only once, or is an existing customer whose details were obtained in the context of an actual sale, where the marketing is for your own similar products or services and they were given a free and easy opportunity to object at collection and on every occasion a communication is sent.

The Information Regulator issued its first direct marketing enforcement notice in February 2024 and read the existing-customer exception narrowly on all three limbs.

For an engagement team, the line falls here.

Communication Direct marketing? Basis
Notice of an EIA application to a registered I&AP No Section 11(1)(c), legal obligation
Invitation to a statutory public meeting No Section 11(1)(c)
Comments and responses report circulated to registered I&APs No Section 11(1)(c)
integrated development plan (IDP) or budget consultation notice from a municipality No Section 11(1)(e), public law duty
Project newsletter with no statutory trigger Yes Section 69
Invitation to a corporate event or webinar Yes Section 69
Anything promoting your organisation’s services Yes Section 69

The system requirement is that the two are separated at the point of sending, that opt-in and objection state is held per recipient and per purpose, and that there is an audit trail showing which basis applied to which send. Blending them is not a policy slip, it is an enforcement notice.

Section 72, and why there is no easy answer on hosting

Section 72 permits transfer of personal information out of South Africa on five grounds. The one that carries commercial weight is the first: the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection that upholds principles substantially similar to POPIA’s conditions, including provisions substantially similar to section 72 governing onward transfers.

South Africa has no adequacy decision mechanism. The Information Regulator has issued no guidance on adequacy criteria and designated no approved jurisdictions. So this route has to be built contractually, case by case, and South African practitioners generally default to a transfer agreement modelled on GDPR standard contractual clauses, adapted for POPIA’s extension to juristic persons and for the onward-transfer requirement.

The other four grounds are weaker for a register. Consent is withdrawable and, again, objectors did not consent. The contract grounds do not describe the relationship between a municipality and an adjacent landowner. And transfer for the benefit of the data subject where consent is not reasonably practicable is not a foundation on which to build a procurement answer.

South African law has no general data localisation requirement. But the National Policy on Data and Cloud, gazetted in 2024, promotes government data classification and residency in policy terms, and departments and state-owned entities increasingly include in-country hosting in ICT tenders. Treat South African data residency as a de facto requirement for public sector and state-owned entity deals.

Where Tractivity stands. We run on Microsoft Azure with UK data residency by default, and European, US and other regions available. If your record holds special personal information, section 57 may require the Information Regulator's authorisation before it's hosted outside South Africa, so raise it at the outset, along with any in-country hosting requirement in your tender. We'll confirm in writing what we can deliver for your deployment, rather than give you a marketing answer.

The operator agreement is a legal requirement, not a courtesy

When you buy stakeholder engagement software, you are the responsible party and the vendor is the operator.

Section 20 says an operator may process only with your knowledge or authorisation and must treat the information as confidential. Section 21 requires the relationship to be governed by a written contract obliging the operator to establish and maintain the section 19 security measures, and to notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Section 22 then places the notification duty on you: notify the Information Regulator and the affected data subjects as soon as reasonably possible, with enough information for them to take protective measures.

Two questions worth asking any vendor. Will you sign a POPIA operator agreement, or are you offering a UK GDPR data processing agreement with the word POPIA inserted? They are not the same document: the onward-transfer provisions, the juristic person extension and the immediate-notification wording all differ. And what does immediately mean in your contract, in hours?

Where Tractivity stands. Ask us for the operator agreement as part of your assessment and we will answer in writing, including the notification window we will commit to. We would rather agree that in the contract than publish a number we have not tested against your requirement.

What a compliant system looks like

Use this list to brief your procurement or security review.

  • Lawful basis recorded per record and per purpose, not assumed
  • Configurable, versioned section 18 collection notices on every registration and comment route, with a record of which notice each data subject received
  • Field-level access control so special personal information is visible only to the roles that need it, with a recorded justification
  • Juristic person records treated as data subject records, not lookup data
  • Opt-in and objection state held per recipient and per purpose, with objection honoured on every send
  • Statutory communications and marketing communications separated at the point of sending, with an audit trail of which basis applied
  • Retention rules that can differ by record type, because a water use licence register has a statutory two-year tail and an EIA record has to survive the appeal window
  • Access, correction and deletion workflow that can be evidenced
  • Encryption at rest and in transit, and a stated hosting region
  • A written operator agreement meeting section 21, with an immediate breach notification obligation
  • A full date-stamped audit trail, exportable, because both the Promotion of Access to Information Act (PAIA) and the Promotion of Administrative Justice Act (PAJA) will ask for it

Where Tractivity stands, briefly. Role-based permissions operate at project, module and record level. Every record carries a date-stamped audit trail and exports to Word, Excel and PDF. The Mailshot module validates every address and checks opt-in before a send goes out. The Enquiries module handles complaints, grievances, project feedback and access-to-information requests as a categorised, date-stamped process. For the rest of this list, send us your questionnaire and we'll answer each point in writing. Our security certifications and hosting details are on our data security and compliance page.

Bring us your security questionnaire

Tractivity is a stakeholder relationship management platform used in South Africa, the UK and Europe to maintain a register of interested and affected parties, record every engagement against the relevant party, produce comments and responses reports, track commitments, and manage grievances.

If you are assessing a stakeholder engagement platform against POPIA, send us the questionnaire and we will answer it in writing, including the parts where the answer is not yet. A call is usually faster than three rounds of email.

To compare the two regimes, we have written the same analysis for GDPR-ready stakeholder databases.

See Tractivity in action

This page is written for practitioners and is not legal advice. POPIA compliance depends on your own processing and your own contracts, and you should take advice from a qualified South African practitioner. Statutory references are to the Protection of Personal Information Act 4 of 2013 and the POPIA Regulations as at September 2026.

Frequently asked questions

Do you need consent to hold a register of interested and affected parties under POPIA?

No. Consent is the wrong lawful basis for a statutory register. Section 11 of POPIA provides six justifications for processing, and the relevant ones for public participation are compliance with an obligation imposed by law and processing necessary for the proper performance of a public law duty by a public body. Regulation 42 of the EIA Regulations 2014 compels the applicant to open and maintain the register, so the register exists by legal obligation, not by consent. Relying on consent creates a withdrawable basis for a record you are required to keep.

Is a community organisation protected by POPIA?

Yes. POPIA defines personal information as information relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person. A ratepayers’ association, a community trust, a non-profit company, a traditional council or a corporate objector is a data subject with rights of access, correction and deletion. There is no equivalent provision in UK or EU data protection law, so a stakeholder system designed for GDPR will treat these as ordinary organisation records.

Can a stakeholder database record race, political affiliation or union membership under POPIA?

Only with a positive justification. Sections 26 to 33 of POPIA prohibit the processing of special personal information unless a general authorisation under section 27, a specific authorisation under sections 28 to 33, or Information Regulator authorisation applies. Race or ethnic origin, political persuasion and trade union membership are all special personal information, and South African engagement records routinely contain all three: race for B-BBEE and SLP demographic reporting, political persuasion in recording ward councillors and party structures, and union membership because SLP consultation involves unions by design. The practical requirement is field-level access control and a recorded justification.

Does POPIA allow stakeholder data to be hosted outside South Africa?

Yes, but not automatically. Section 72 permits transfer where the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection that upholds principles substantially similar to POPIA conditions and includes provisions substantially similar to section 72 governing onward transfers. South Africa has no adequacy list and the Information Regulator has designated no approved jurisdictions, so this route has to be built contractually in each case. Consent is a weak alternative for a register populated by people who did not ask to be on it.

Is sending a public participation notice direct marketing under POPIA?

No. A statutory notice sent to an I&AP under the EIA Regulations is processing for compliance with a legal obligation, not direct marketing, and section 69 does not apply to it. A newsletter or a service promotion sent to the same list is direct marketing and section 69 does apply, which means either consent requested on the prescribed Form 4, or the narrow existing-customer exception. The two must be separated in the system, with opt-in and objection state held per recipient and per purpose, and an audit trail. The Information Regulator’s first direct marketing enforcement notice in February 2024 confirmed the existing-customer exception requires an actual prior sale, permits only similar offerings, and requires an objection opportunity on every occasion.

What are the penalties for POPIA non-compliance?

Administrative fines of up to R10 million and offences punishable by up to 10 years’ imprisonment. The Information Regulator imposed its first administrative fine, R5 million, on 3 July 2023 against the Department of Justice and Constitutional Development following a security compromise involving the loss of approximately 1,204 files. Data subjects also have a civil damages action under section 99 that does not require proof of intent or negligence.