The Protection of Personal Information Act 4 of 2013 (POPIA) has been fully in force since 1 July 2021. Five years on, the Information Regulator is increasingly willing to issue enforcement notices and fines — and South African law firms, as custodians of some of the most sensitive personal information in the economy, are squarely in the regulator's sights. This guide walks through every POPIA section that applies to legal practice and gives you a practical, action-oriented checklist you can implement today.
Before we begin, an honest disclosure: LexPrime OS has a POPIA-aware architecture — meaning the technical controls POPIA requires are built into the software. But full POPIA compliance also requires firm-level policies, staff training, and governance practices that no software can deliver on its own. This guide covers both layers.
Why POPIA matters more for attorneys than for most businesses
Legal practices process what POPIA calls "special personal information" — Section 26 covers religious beliefs, health information, criminal behaviour, and biometric data. If you handle personal injury matters (RAF, medical negligence), family law (divorce, custody), criminal defence, or estates (deceased person information), you are processing special personal information almost every working day.
Special personal information carries stricter processing conditions under Section 27. You need explicit consent, or you must fall within one of the narrow exceptions (e.g., the information is necessary for the establishment, exercise or defence of a right or claim — which covers most litigation). Documenting which exception applies is critical.
POPIA applies to every "responsible party" that processes personal information in South Africa. As an attorney, you are a responsible party for your clients' data — and a "data processor" for your firm's clients if you handle their information on their behalf. Both roles carry obligations.
The 10-section POPIA compliance checklist for law firms
1. Section 6–7: Lawful processing and minimum requirements
You must process personal information lawfully and reasonably, in a way that does not infringe the data subject's privacy. For attorneys, this means: only collect client information you actually need for the matter; do not retain it longer than necessary; and do not use it for purposes unrelated to the mandate without consent.
- •Audit every form your firm uses — intake forms, retainer agreements, KYC forms. Are you collecting only what you need?
- •Review your retention schedule. How long do you keep closed matter files? Most attorneys default to "forever" — POPIA requires a defined period.
- •Document the lawful basis for each processing activity (consent, contract, legal obligation, legitimate interest, public interest).
2. Section 11: Lawful justification for processing
Section 11 sets out the conditions for lawful processing. For law firms, the most common bases are: (a) processing is necessary to carry out actions for the conclusion or performance of a contract (the attorney-client retainer); (b) the processing complies with an obligation imposed by law (FICA, LPA); (c) the processing protects a legitimate interest of the data subject (your client); or (d) the processing is necessary for the proper performance of a public law duty by a public body.
3. Section 17: Designation of an Information Officer
Every responsible party must designate an Information Officer — and for law firms, this is a legal requirement, not a "nice to have." The Information Officer's duties include: facilitating requests from the Information Regulator, working with the Regulator on investigations, and ensuring internal compliance. The Information Officer must be registered with the Information Regulator via the online portal.
- •Designate an Information Officer (typically a partner or the compliance officer).
- •Register the Information Officer with the Information Regulator at inforegulator.org.za.
- •Ensure the Information Officer has Deputy Information Officers if the firm has multiple branches or high volume.
- •Publish the Information Officer's contact details on your website and in your PAIA manual.
4. Section 19: Security safeguards
Section 19 requires "reasonable technical and organisational measures" to secure personal information. This is the section most relevant to legal practice management software. The measures must: (a) identify reasonably foreseeable risks; (b) establish and maintain appropriate safeguards against those risks; and (c) regularly verify that safeguards are effectively implemented and updated.
In practice, this means your practice management software must provide: encrypted password storage, role-based access control so that junior staff cannot see senior partners' matters without authorisation, audit logging of every action taken on a client file, two-factor authentication for staff logins, and secure transmission of client data (TLS encryption).
LexPrime OS implements every Section 19 control: bcrypt password hashing with 12 rounds, six-tier role-based access (Super Admin → Managing Attorney → Attorney → Paralegal → Receptionist → Viewer), full audit logging for Section 30 access requests, 2FA via TOTP/SMS/email, and SA data residency. See our Security & Compliance page for the full technical details.
5. Section 22: Breach notification
If a data breach occurs (loss, theft, unauthorised access, unauthorised modification), Section 22 requires you to notify: (a) the Information Regulator, and (b) the affected data subjects — "as soon as reasonably possible" after discovering the breach. The notification must include: what happened, what personal information was compromised, the likely consequences, the measures taken to address the breach, and recommendations on what the data subject can do to mitigate adverse effects.
Practically, this means you need: an incident response plan (written down, not just in your head); the ability to identify which clients were affected; and a notification template ready to use. If you cannot identify which clients were affected (because your audit logging is inadequate), you cannot comply with Section 22.
6. Section 23: Data subject rights
Data subjects (your clients) have eight rights under Section 23: (1) to be notified when their personal information is collected; (2) to request access to their personal information; (3) to request correction or deletion; (4) to object to processing; (5) to withdraw consent; (6) to complain to the Information Regulator; (7) to institute civil proceedings; and (8) to be notified if their personal information has been accessed by an unauthorised person.
For law firms, the most exercised right is access (Section 30) — clients asking "what information do you hold about me?" Your software must be able to produce this within a reasonable time. If your client data is scattered across email, WhatsApp, paper files, and an old practice management system, fulfilling a Section 30 request is a nightmare.
7. Section 30: Access requests
A Section 30 access request must be responded to within a "reasonable time" — the Information Regulator's guidance suggests 30 days. The response must include: whether the firm holds personal information about the data subject; what that information is; the identity of third parties who have had access; and what the firm is doing to ensure the information is accurate.
A modern practice management system with proper audit logging makes this trivial — you run a query for "all records linked to client X" and you have your response. Without it, you are manually trawling through matter files.
8. Section 32: Destruction or deletion of records
Once the retention period expires, you must destroy or de-identify the personal information. For law firms, this is complicated by the Legal Practice Council's rules on file retention — typically 5 years for most matters, longer for certain types of litigation. Your retention schedule must align with both POPIA and the LPC rules.
9. Section 57: Direct marketing
Section 57 restricts direct marketing. You cannot market to a prospective client via electronic means (email, SMS, WhatsApp) unless: (a) they are an existing customer (you have an existing relationship), and the marketing is for similar products/services; OR (b) they have given consent. For law firms, this means your "we got your details from a referral" email outreach must comply — either obtain consent first or limit yourself to non-electronic outreach.
10. Section 72: Cross-border transfers
You may not transfer personal information to a third party in another country unless: (a) the recipient is subject to a law or binding code that provides equivalent protection; (b) you have the data subject's consent; (c) the transfer is necessary for performance of a contract; or (d) the transfer is for the benefit of the data subject and it is impractical to obtain consent.
This is why we built LexPrime OS on local Ollama AI — your client files never leave South African jurisdiction. If your practice management software uses OpenAI or Anthropic APIs for AI features, every client document you upload is sent to US servers, and you need Section 72 compliance (typically via consent in your retainer agreement).
If your current legal software uses cloud-based AI (ChatGPT, Claude, etc.), you are transferring client data outside South Africa. Check your retainer agreement — does it disclose this to clients and obtain consent? If not, you may be in breach of Section 72.
The POPIA compliance checklist (print this)
- 1Designate and register an Information Officer with the Information Regulator.
- 2Conduct a personal information impact assessment — what data do you hold, where, why, and for how long?
- 3Update your retainer agreement to disclose data processing, AI usage, and cross-border transfers.
- 4Implement technical safeguards: encrypted passwords, 2FA, role-based access, audit logging.
- 5Train all staff (including receptionists and paralegals) on POPIA — they handle personal information daily.
- 6Create a written data breach response plan with notification templates ready to use.
- 7Set retention periods for each matter type, aligned with Legal Practice Council rules.
- 8Implement a Section 30 access request workflow — who handles them, how long it takes, what format the response takes.
- 9Audit your direct marketing — are you emailing prospects without consent or an existing relationship?
- 10If you use cloud AI tools, ensure Section 72 compliance (consent in retainer, or switch to local AI).
What software can and cannot do for POPIA
Legal practice management software can deliver the technical controls POPIA Section 19 requires — encrypted storage, access control, audit logging, breach detection. It cannot deliver the governance layer: your Information Officer designation, your retention policies, your staff training, your incident response plan. Those are the firm's responsibility.
When evaluating legal software, ask vendors these five questions: (1) Where is the data hosted? (SA residency matters for Section 72.) (2) Does AI run locally or in the cloud? (Cloud AI = cross-border transfer.) (3) What audit logging is built in? (You need this for Section 30 access requests.) (4) Is 2FA available for all user accounts? (Section 19 security.) (5) Can you produce a full export of a client's data within 30 days? (Section 30 compliance.) If the vendor cannot answer all five, look elsewhere.