Your HR Files Could Be a POPIA Problem

How New VAT Thresholds Are Reshaping SME Year-End Planning
July 28, 2026

Your HR Files Could Be a POPIA Problem

Keeping everything “just in case” can become a liability

Many HR departments freely collect employee information and keep it indefinitely. The reason is almost always the same: we might need it someday. Payslips and medical certificates of former employees, CCTV footage stored on a shared drive, or disciplinary records retained long after a case has expired, create far less security. It creates a liability.

It may feel practical, but under the Protection of Personal Information Act 4 of 2013 (POPIA), it can expose employers to serious legal and operational risk. POPIA requires employers to justify not only what personal information they collect, but also who has access to it, why they continue to retain it, and whether that retention remains lawful and necessary.

What Counts as Employee Data?

Most of what sits in an HR file counts as personal information. That includes ID numbers, addresses, banking details, payroll records, leave forms, performance reviews, disciplinary records, and resignation letters.

Some categories of employee data carry stricter legal obligations and should not be treated like routine HR administration. A shared folder containing medical records, disciplinary histories, or criminal background checks that multiple managers can freely access is not just poor admin. It is a major compliance risk. Improper handling of this type of data can contribute to workplace discrimination and expose employers to serious legal and compliance consequences.

Consent Is Not Everything

In most companies, HR needs to process personal information to run payroll, manage leave, and handle disciplinary matters. A common mistake many employers make is thinking that an employee’s written consent for every piece of information is enough, but that is not always the case. Employee consent does not automatically make the processing of information lawful.

Monitoring Needs Boundaries

In certain circumstances, employers may monitor workplace systems such as emails, internet usage, access logs, or CCTV footage, particularly where there are operational, security, compliance, or misconduct-related concerns.

Unstructured or excessive monitoring practices may create privacy and labour-related risks, particularly where employees are unaware of the monitoring or where no internal controls exist.

A written policy that explains what may be monitored, the purpose of the monitoring, who has access to the information, and how long the information will be retained might not remove all privacy concerns, but it does help establish transparency and clearer workplace boundaries.

Your HR Archive Is Not a Museum

Many businesses store large volumes of outdated employee information across email inboxes, shared drives, payroll systems, and former managers’ laptops. The risk is not merely that the records exist. It is that nobody knows exactly what is being stored, who still has access to it, whether it remains accurate, or what happens if there is a breach.

Certain employee records must legally be stored for specific periods under labour, tax, employment equity, health and safety, or pension-related laws. Once those retention periods expire, employers are expected to reassess whether there is still a lawful reason to keep the information.

That is where a retention schedule becomes essential. A proper retention schedule is not a complicated legal document. It is a practical internal framework that identifies:

  • what records are kept;
  • where they are stored;
  • who may access them;
  • how long they must legally remain on file; and
  • when they should be disposed of.

Without a legal obligation, operational need, active dispute, investigation, or regulatory requirement, indefinite retention becomes difficult to justify under POPIA.

A Practical HR POPIA Checklist

Before your next HR audit or compliance review, employers should already have the following in place:

  1. A privacy notice explaining what employee information is collected and why.
  2. Access controls limiting who can view payroll, medical, disciplinary, and HR records.
  3. A retention schedule covering every major category of employee information.
  4. Written policies dealing with email monitoring, internet use, CCTV, remote work, and company devices.
  5. A process for responding to lost devices, hacked accounts, accidental disclosures, or other data breaches.
  6. Basic POPIA training for managers, HR staff, and anyone handling employee information.
  7. A process for securely deleting or destroying records that are no longer needed.

The Real Issue Is Not Collection. It Is Control.

Most employers need to collect employee information. Payroll cannot function without it. Neither can recruitment, performance management, disciplinary processes, or workplace security. The real compliance risk lies in how that data is stored, accessed, monitored, shared, and retained over time.

Good HR data management is not about deleting everything indiscriminately. It is about keeping the right information, for the right reasons, for the right amount of time, and being able to justify those decisions if a complaint, breach, or investigation arises.

 

While every reasonable effort is taken to ensure the accuracy and soundness of the contents of this publication, neither the writers of articles nor the publisher will bear any responsibility for the consequences of any actions based on information or recommendations contained herein. Our material is for informational purposes.

Comments are closed.

We use cookies to improve your experience on our website. By continuing to browse, you agree to our use of cookies
X