{"id":69140,"date":"2021-07-16T17:32:34","date_gmt":"2021-07-16T15:32:34","guid":{"rendered":"https:\/\/www.sage.com\/en-za\/blog\/?p=69140"},"modified":"2026-01-29T15:32:19","modified_gmt":"2026-01-29T13:32:19","slug":"popia-compliance-what-accountants-need-to-know","status":"publish","type":"post","link":"https:\/\/www.sage.com\/en-za\/blog\/popia-compliance-what-accountants-need-to-know\/","title":{"rendered":"POPIA compliance: What accountants need to know"},"content":{"rendered":"<header class=\"entry-header has-dark-background-color entry-header--has-illustration entry-header--has-illustration--generic\">\n\t<div class=\"container\">\n\t\t<div class=\"entry-header__row row align-center\">\n\t\t\t<div class=\"col col-lg-7 col-xlg-6 entry-header__content\">\n\t\t\t\t\t\t\t<div class=\"component component-single-header\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"entry-header__misc text--subtitle text--uppercase text--small\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.sage.com\/en-za\/blog\/category\/strategy-legal-operations\/compliance\/\" class=\"entry-header__link\">Compliance<\/a>\t\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t<div class=\"entry-title-wrapper\">\n\t\t\t\t\t<h1 class=\"entry-title\">\n\t\t\t\t\t\tPOPIA compliance: What accountants need to know\t\t\t\t\t<\/h1>\n\t\t\t\t<\/div>\n\n\t\t\t\t\t\t\t\t\t<p class=\"entry-header__description\">\n\t\t\t\t\t\t\t\t\t\t\t<\/p>\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n\t<div class=\"single-post-details container\">\n\t\t<div class=\"col\">\n\t\t\t<span class=\"posted-on \"><time class=\"entry-date published\" datetime=\"2021-07-16T17:32:34+02:00\">Jul 16, 2021<\/time><\/span><span class=\"reading-time\"> min read<\/span>\n\t\t<button\n\t\t\ttype=\"button\"\n\t\t\tclass=\"social-share-button button button--icon button--secondary js-social-share-button\"\n\t\t\tdata-share-title=\"POPIA compliance: What accountants need to know\"\n\t\t\tdata-share-url=\"https:\/\/www.sage.com\/en-za\/blog\/popia-compliance-what-accountants-need-to-know\/\"\n\t\t\tdata-share-text=\"Please read this interesting article\"\n\t\t>\n\t\t\t<span class=\"social-share-button__share-label\">Share<\/span>\n\t\t\t<span class=\"social-share-button__copy-label\" hidden>Copy Link<\/span>\n\t\t\t<span class=\"social-share-button__copy-tooltip\" aria-hidden=\"true\" hidden>Copied<\/span>\n\t\t<\/button>\n\n\t\t\t\t<\/div>\n\t<\/div>\n<\/header>\n\n\n\n<div class=\"wp-block-post-author\">\n\t\t\t<div class=\"co-authors\">\n\t\t\t\n\t\t<div class=\"entry-author-wrapper\">\n\t\t\t<a class=\"entry-author\" href=\"https:\/\/www.sage.com\/en-za\/blog\/author\/mongezilupindo\/\">\n\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.sage.com\/en-za\/blog\/wp-content\/uploads\/sites\/9\/2021\/12\/Mongezi-350x350.jpg\" class=\"entry-author__image\" alt=\"\" \/>\t\t\t\t<span class=\"entry-author__name\">Mongezi Lupindo<\/span>\n\t\t\t<\/a>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t<\/div>\n\t\t<\/div>\n\n\n\n<p>News about the <a href=\"https:\/\/www.sage.com\/en-za\/blog\/small-business-data-protection-low-hanging-fruit\/\">Protection of Personal Information Act<\/a> (POPIA) has dominated headlines and flooded our inboxes in recent weeks. That\u2019s because, as of 1 July 2021, any individual or entity has to be POPIA compliant. The legislation, passed by the South African Parliament, outlines what individuals and businesses that process or record personal information must do in order to safeguard this data.<\/p>\n\n\n\n<p>This means reviewing all the operational processes running within your organisation that touch personal information of employees, customers, and suppliers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-so-what-do-accountants-need-to-know-about-popia\">So, what do accountants need to know about POPIA?<\/h2>\n\n\n\n<p>POPIA has a big impact on any business working in financial services.<\/p>\n\n\n\n<p>Accountants process a great deal of personal information around the financial history of their clients and their businesses. While ensuring the integrity and confidentiality of this information has always been best industry practice, POPIA makes it a legal obligation.<\/p>\n\n\n\n<p>For accountants and accounting firms, POPIA demands that the way they interact with customers and clients must adhere to the requisite privacy laws. In addition, how accountants collect, store, or process employee information must also align with the protections set out by POPIA.<\/p>\n\n\n\n<p>Below, we unpack four steps accountants can take in order to start their journey to POPIA compliance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-1-nbsp-nbsp-nbsp-raise-awareness\">1.&nbsp;&nbsp;&nbsp; Raise awareness<\/h2>\n\n\n\n<p>When it comes to POPIA, knowledge is critical. Education and awareness must be a top priority because people play a major role in making sure that any organisation remains POPIA compliant.<\/p>\n\n\n\n<p>All employees need to understand basic POPIA privacy principles, what is required of them, and how to apply these to the work they do. Effective compliance demands that you secure buy-in from everyone \u2013 be it senior management or the most junior staff member.<\/p>\n\n\n\n<p>This kind of security and privacy awareness training not only reduces the risk of costly errors in handling sensitive information but also protects the company\u2019s confidential data and information systems. Training and privacy\/security awareness workshops must happen regularly to guarantee that the responsible handling and safeguarding of personal information is always top of mind.<\/p>\n\n\n\n<p>At Sage, we have developed a POPIA internal training programme for employees and partners. We\u2019ve also created a <a href=\"https:\/\/www.sage.com\/en-za\/legal\/privacy-and-cookies\/protection-of-personal-information\/\">Privacy Hub<\/a> containing our updated POPIA Privacy Policy, Cookies Policy, and PAIA Manual, and have joined the Michalsons Compliance Programme for Data Protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-2-nbsp-nbsp-nbsp-develop-a-compliance-plan\">2.&nbsp;&nbsp;&nbsp; Develop a compliance plan<\/h2>\n\n\n\n<p>Depending on the size, scope, and function of your business, you\u2019ll either need to appoint a dedicated POPIA compliance\/information officer or a compliance team. In most instances, a compliance officer \u2013 typically the CEO, unless the role has been delegated to someone else \u2013 will suffice.<\/p>\n\n\n\n<p>This individual is responsible for developing and implementing a compliance framework, ensuring that POPIA awareness workshops are set up and attended, and conducting regular assessments to flag risks and identify what safeguards are needed to protect any personal information being processed.<\/p>\n\n\n\n<p>In order to develop a compliance framework, it\u2019s essential to audit each business unit to determine what information is collected, how it\u2019s collected, who collects it, what it\u2019s used for, and how it\u2019s stored and processed.<\/p>\n\n\n\n<p>Beyond this, accountants need to assess how information is retained and destroyed and, importantly, whether the information was collected with the necessary consent. These audits will highlight any gaps that exist and, from this, you will be able to compile a risk assessment report. When developing this plan, ensure that your policies are reasonable, appropriate, and enforceable and that they are designed for diverse groups of stakeholders.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-3-nbsp-nbsp-nbsp-implement-your-strategy\">3.&nbsp;&nbsp;&nbsp; Implement your strategy<\/h2>\n\n\n\n<p>Once the right compliance policies and procedures have been established, these need to be implemented, monitored, and maintained \u2013 regularly.<\/p>\n\n\n\n<p>A gap analysis will reveal how employee contracts and supplier agreements must be updated and what changes need to be made to your marketing practices. Any gaps you identify will determine what policies need to be put in place around personal information sharing and the use of personal devices at work, for example. If you\u2019re using any business or financial management software, you\u2019ll need to check with the supplier to find out if the solution adheres to POPIA security requirements.<\/p>\n\n\n\n<p>Any plan you\u2019ve put together is only effective if it is properly implemented. In some cases, this may require that you enlist the help of an outside service provider, such as a law firm, to help your business put the proper measures and controls in place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-4-nbsp-nbsp-nbsp-review\">4.&nbsp;&nbsp;&nbsp; Review<\/h2>\n\n\n\n<p>Even with all of these new privacy policies in place, your work isn\u2019t over yet. In fact, continued POPIA compliance requires ongoing monitoring of the data protection ecosystem and demands that you keep up to date with any changes to legislation, new regulations, and the latest security threats.<\/p>\n\n\n\n<p>Remember that more data means more risk. Under POPIA, businesses cannot keep records of personal information once the reason for which the information was collected no longer exists; that is, unless storing the data is required by law. As such, accountants shouldn\u2019t keep the personal information of former suppliers once the business relationship has ended.&nbsp;As part of the review process, businesses must check if they are holding onto any financial records that they no longer need.<\/p>\n\n\n\n<p>POPIA demands consistency and transparency. If you\u2019re processing, sharing, or storing someone\u2019s personal information, you need to let him or her know why. With this in mind, it\u2019s imperative to regularly review why you are processing, saving, or sharing any personal information and verify that these reasons are still valid. This also applies to information received from a third party.<\/p>\n\n\n\n<p>POPIA compliance must become \u201cbusiness-as-usual\u201d and should be built into any product, service, and process going forward. Think of compliance as privacy by design. That being said, complying with POPIA is not a case of one size fits all. Different organisations must take different actions to comply. Failure to comply has&nbsp;serious implications, from fines and imprisonment to reputational damage and a loss of client trust.<\/p>\n\n\n\n<p>Need help getting started on your POPIA compliance journey? <a href=\"https:\/\/www.sage.com\/en-za\/legal\/privacy-and-cookies\/protection-of-personal-information\/\">Visit our dedicated Sage Legal Information website<\/a>,<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-disclaimer\">Disclaimer:<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-sage-popia-legal-disclaimer\"><strong>Sage POPIA legal disclaimer<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The information contained on this document\/website\/publication is for general guidance purposes only. It should not be taken for, nor is it intended as, legal advice.<\/li>\n\n\n\n<li>We would like to stress that there is no substitute for conducting your own detailed investigations or seeking their own professional advice if they are unsure of the implications of POPIA on their businesses.<\/li>\n\n\n\n<li>Sage will not accept any liability for errors or omissions and will not be liable for any damage (including, without limitation, damage for loss of business or loss of profits) arising in contract, tort or otherwise, from the use of or reliance on this information or from any action or decisions taken as a result of using this information.<\/li>\n<\/ul>\n\n\n<div class=\"single-cta\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">Subscribe to the Sage Advice enewsletter<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p>Get a roundup of our best business advice in your inbox every month.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-84fe79b5-668d-41f8-a0cc-6229018c4ac9\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Subscribe<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-za\/blog\/wp-content\/uploads\/sites\/9\/2022\/04\/GettyImages-1181404518-1440x810.jpg\" class=\"single-cta__image\" alt=\"\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-za\/blog\/wp-content\/uploads\/sites\/9\/2022\/04\/GettyImages-1181404518-1440x810.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>News about the Protection of Personal Information Act (POPIA) has dominated headlines and flooded our inboxes in recent weeks. That\u2019s because, as of 1 July 2021, any individual or entity has to be POPIA compliant. The legislation, passed by the South African Parliament, outlines what individuals and businesses that process or record personal information must [&hellip;]<\/p>\n","protected":false},"author":904,"featured_media":68774,"menu_order":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sage_video":false,"post_featured_image_hide":false,"footnotes":""},"categories":[35],"tags":[321],"business_type":[5],"lilypad":[],"context":[],"industry":[],"persona":[15],"imagine_tag":[51],"coauthors":[430],"class_list":["post-69140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-compliance","business_type-accountants"],"sage_meta":{"region":"en-za","author_name":"Mongezi Lupindo","featured_image":"https:\/\/www.sage.com\/en-za\/blog\/wp-content\/uploads\/sites\/9\/2020\/09\/SAGE-14-scaled.jpg","imagine_tags":{"51":"Accountants"}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Sage Advice South Africa","distributor_original_site_url":"https:\/\/www.sage.com\/en-za\/blog","push-errors":false,"_links":{"self":[{"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/posts\/69140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/users\/904"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/comments?post=69140"}],"version-history":[{"count":0,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/posts\/69140\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/media\/68774"}],"wp:attachment":[{"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/media?parent=69140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/categories?post=69140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/tags?post=69140"},{"taxonomy":"business_type","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/business_type?post=69140"},{"taxonomy":"lilypad","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/lilypad?post=69140"},{"taxonomy":"context","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/context?post=69140"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/industry?post=69140"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/persona?post=69140"},{"taxonomy":"imagine_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/imagine_tag?post=69140"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sage.com\/en-za\/blog\/api\/wp\/v2\/coauthors?post=69140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}