POPIA for landlords: a practical checklist
A tenancy runs on personal information: ID numbers, phone numbers, bank details, payslips, a payment record. The Protection of Personal Information Act (POPIA) decides how you may collect it, keep it and let it go. Here is what it asks of a landlord or letting agent, as a checklist you can work through.
Yes, it applies to you
POPIA applies to every responsible party: anyone who decides why and how personal information is processed. That is every landlord — a private owner, a property company or trust, and the letting agency that acts for them — whatever the size of the portfolio. The exclusion for purely personal or household activity does not cover letting property for income. If a managing agent runs the property for you, you and the agent share the responsibility, and anyone processing on your behalf (a bookkeeper, a software provider) is an operator who must be bound by a written agreement to keep the information secure.
The checklist
POPIA's eight conditions for lawful processing, translated into what they mean for a tenancy:
| Condition | What it means for a landlord |
|---|---|
| Accountability | You are answerable for compliance, including what your agent or service providers do with the information. |
| Processing limitation | Collect only what the lease needs, for a lawful reason, and preferably from the tenant directly. |
| Purpose specification | Know, and tell the tenant, why you collect each item. Keep it no longer than that purpose needs. |
| Further processing | Don't reuse the information for something unrelated (say, a different business) without a new lawful reason. |
| Information quality | Keep it accurate and up to date — a wrong arrears figure on a statement is a POPIA problem as well as a dispute. |
| Openness | Tell tenants what you collect, why, who sees it and their rights. A clear privacy notice with the application form does this. |
| Security safeguards | Protect it from loss, damage and unauthorised access, and report compromises. |
| Data subject participation | Let tenants see what you hold about them and correct or delete it where appropriate. |
What you may collect, and when you need consent
You do not need a separate consent for every record. Information needed to conclude and perform the lease — name, contact details, ID number, the unit, the rent, payments — can be processed on that basis, and so can information you keep to meet a legal obligation (tax records, FICA where it applies).
You do need the tenant's consent, or another specific lawful basis, for things outside the lease itself:
- A credit check and reporting payment behaviour to a credit bureau — TPN prescribes its own consent wording for both (see our tenant screening guide).
- Marketing by email, SMS or WhatsApp — section 69 limits direct marketing by electronic means to people who consented, or to your existing customers for similar services with a way to opt out. Rent reminders and statements about the tenant's own lease are not marketing.
- Sharing with anyone the tenant would not expect, and sending information outside South Africa to a country without adequate protection.
Collect less, and there is less to protect. A copy of the ID and a payslip support an application; a copy of the tenant's full bank statement for twelve months usually does not.
Special personal information
Some information is special personal information — religious beliefs, race, health, criminal behaviour, biometrics — and may only be processed in narrow circumstances. A tenant application should not ask for any of it. Children's information has similar protection: record who lives in the unit for the lease, but don't collect more about minors than that needs.
Keep it secure
- Store tenant files where only the people who need them can open them — not a shared inbox, a WhatsApp group or a desktop anyone can use.
- Protect documents you send: statements and leases carry ID numbers and addresses.
- Remove access when a staff member or agent leaves.
- Have a written agreement with every operator (bookkeeper, software, agent) requiring them to keep the information secure and to tell you about any compromise.
Don't keep it forever
Keep personal information only as long as the purpose needs it — unless a law requires or allows longer. For a landlord, the longest usual requirement is tax: SARS generally expects records to be kept for five years from the date the relevant return was submitted. Deposit and lease disputes are another reason to keep a tenancy's file for a while after the tenant leaves. After that, delete the information or de-identify it so it can no longer be linked to the person.
When a tenant asks what you hold
A tenant (or former tenant) may ask whether you hold information about them, see it, and ask you to correct or delete it. Respond within a reasonable time. The formal route for access requests runs through the Promotion of Access to Information Act (PAIA), which is also why most businesses — sole proprietors included — need a PAIA manual describing the records they keep and how to request them; small bodies may use a shorter version.
If something leaks
The Information Officer
Every responsible party has an Information Officer — by default the head of the business (the owner of a sole proprietorship, the CEO of a company). They are responsible for POPIA and PAIA compliance and must be registered with the Information Regulator through the eServices portal before taking up the role. Deputy Information Officers can be designated to share the work.
What non-compliance costs
The Information Regulator can investigate complaints, issue enforcement notices and impose administrative fines of up to R10 million; the most serious offences carry imprisonment. Tenants can also claim damages. For most landlords the realistic risk is a complaint after a deposit dispute — which is the moment a messy file becomes evidence.
Mastendi keeps the tenant file POPIA-shaped
Each tenant's communication consent is recorded with its date, and TPN screening and reporting consent is signed by the tenant on their own link. Access is by role, and restricted agents see only their assigned properties. From any tenant you can export everything held about them as a ZIP for an access request, or anonymise a former tenant's personal information once you no longer need it.
Start your 30-day free trialFrequently asked questions
Does POPIA apply to every landlord?
Yes — private owners, companies, trusts and letting agencies alike, whatever the size of the portfolio. Letting property for income is not the "purely personal or household" activity POPIA excludes.
Do I need consent to keep a tenant's details?
Not for what the lease needs, or what a law requires you to keep. Consent is needed for credit checks, bureau reporting, marketing, and sharing the tenant would not expect.
How long can I keep a former tenant's information?
As long as its purpose needs it, or longer where a law requires — SARS generally expects records for five years from submission of the return. Then delete or de-identify it.
What if tenant data leaks?
Notify the Information Regulator through its eServices portal and tell the affected tenants, as soon as reasonably possible. There is no threshold below which you can stay quiet.
Do I need to register an Information Officer?
Yes. The Information Officer — by default the head of the business — must be registered with the Information Regulator through the eServices portal.
Disclaimer: This guide is general information for South African landlords and letting agents and is not legal advice. POPIA, PAIA and the Information Regulator's rules and guidance change, and your situation may differ. Confirm the current position with the Information Regulator or a qualified attorney before acting.