Mastendi Start free trial
Compliance · South Africa

POPIA for landlords: a practical checklist

A tenancy runs on personal information: ID numbers, phone numbers, bank details, payslips, a payment record. The Protection of Personal Information Act (POPIA) decides how you may collect it, keep it and let it go. Here is what it asks of a landlord or letting agent, as a checklist you can work through.

Updated September 2026 · ~7 min read · General guidance, not legal advice (see disclaimer)

The short version: Know why you hold each piece of tenant information, collect only what the lease needs, get consent for anything beyond it (credit checks, bureau reporting, marketing), keep it secure, let tenants see and correct it, delete it when you no longer need it, and report any leak to the Information Regulator through its eServices portal.

Yes, it applies to you

POPIA applies to every responsible party: anyone who decides why and how personal information is processed. That is every landlord — a private owner, a property company or trust, and the letting agency that acts for them — whatever the size of the portfolio. The exclusion for purely personal or household activity does not cover letting property for income. If a managing agent runs the property for you, you and the agent share the responsibility, and anyone processing on your behalf (a bookkeeper, a software provider) is an operator who must be bound by a written agreement to keep the information secure.

The checklist

POPIA's eight conditions for lawful processing, translated into what they mean for a tenancy:

ConditionWhat it means for a landlord
AccountabilityYou are answerable for compliance, including what your agent or service providers do with the information.
Processing limitationCollect only what the lease needs, for a lawful reason, and preferably from the tenant directly.
Purpose specificationKnow, and tell the tenant, why you collect each item. Keep it no longer than that purpose needs.
Further processingDon't reuse the information for something unrelated (say, a different business) without a new lawful reason.
Information qualityKeep it accurate and up to date — a wrong arrears figure on a statement is a POPIA problem as well as a dispute.
OpennessTell tenants what you collect, why, who sees it and their rights. A clear privacy notice with the application form does this.
Security safeguardsProtect it from loss, damage and unauthorised access, and report compromises.
Data subject participationLet tenants see what you hold about them and correct or delete it where appropriate.

What you may collect, and when you need consent

You do not need a separate consent for every record. Information needed to conclude and perform the lease — name, contact details, ID number, the unit, the rent, payments — can be processed on that basis, and so can information you keep to meet a legal obligation (tax records, FICA where it applies).

You do need the tenant's consent, or another specific lawful basis, for things outside the lease itself:

Collect less, and there is less to protect. A copy of the ID and a payslip support an application; a copy of the tenant's full bank statement for twelve months usually does not.

Special personal information

Some information is special personal information — religious beliefs, race, health, criminal behaviour, biometrics — and may only be processed in narrow circumstances. A tenant application should not ask for any of it. Children's information has similar protection: record who lives in the unit for the lease, but don't collect more about minors than that needs.

Keep it secure

Don't keep it forever

Keep personal information only as long as the purpose needs it — unless a law requires or allows longer. For a landlord, the longest usual requirement is tax: SARS generally expects records to be kept for five years from the date the relevant return was submitted. Deposit and lease disputes are another reason to keep a tenancy's file for a while after the tenant leaves. After that, delete the information or de-identify it so it can no longer be linked to the person.

When a tenant asks what you hold

A tenant (or former tenant) may ask whether you hold information about them, see it, and ask you to correct or delete it. Respond within a reasonable time. The formal route for access requests runs through the Promotion of Access to Information Act (PAIA), which is also why most businesses — sole proprietors included — need a PAIA manual describing the records they keep and how to request them; small bodies may use a shorter version.

If something leaks

Every compromise is reportable. If there are reasonable grounds to believe tenant information has been accessed or acquired by someone unauthorised — a stolen laptop, a hacked email account, a statement sent to the wrong tenant — notify the Information Regulator and the affected tenants as soon as reasonably possible. Since 1 April 2025 notifications to the Regulator must be made through its eServices portal. POPIA sets no minimum threshold.

The Information Officer

Every responsible party has an Information Officer — by default the head of the business (the owner of a sole proprietorship, the CEO of a company). They are responsible for POPIA and PAIA compliance and must be registered with the Information Regulator through the eServices portal before taking up the role. Deputy Information Officers can be designated to share the work.

What non-compliance costs

The Information Regulator can investigate complaints, issue enforcement notices and impose administrative fines of up to R10 million; the most serious offences carry imprisonment. Tenants can also claim damages. For most landlords the realistic risk is a complaint after a deposit dispute — which is the moment a messy file becomes evidence.

Mastendi keeps the tenant file POPIA-shaped

Each tenant's communication consent is recorded with its date, and TPN screening and reporting consent is signed by the tenant on their own link. Access is by role, and restricted agents see only their assigned properties. From any tenant you can export everything held about them as a ZIP for an access request, or anonymise a former tenant's personal information once you no longer need it.

Start your 30-day free trial

Frequently asked questions

Does POPIA apply to every landlord?

Yes — private owners, companies, trusts and letting agencies alike, whatever the size of the portfolio. Letting property for income is not the "purely personal or household" activity POPIA excludes.

Do I need consent to keep a tenant's details?

Not for what the lease needs, or what a law requires you to keep. Consent is needed for credit checks, bureau reporting, marketing, and sharing the tenant would not expect.

How long can I keep a former tenant's information?

As long as its purpose needs it, or longer where a law requires — SARS generally expects records for five years from submission of the return. Then delete or de-identify it.

What if tenant data leaks?

Notify the Information Regulator through its eServices portal and tell the affected tenants, as soon as reasonably possible. There is no threshold below which you can stay quiet.

Do I need to register an Information Officer?

Yes. The Information Officer — by default the head of the business — must be registered with the Information Regulator through the eServices portal.

Disclaimer: This guide is general information for South African landlords and letting agents and is not legal advice. POPIA, PAIA and the Information Regulator's rules and guidance change, and your situation may differ. Confirm the current position with the Information Regulator or a qualified attorney before acting.