Print

Data subject access requests under POPIA - what to do when a customer asks

  • popia, south africa law, privacy policy, data protection, cookie consent, dsar, compliance, data subject access
  • 0

Data subject access requests

POPIA gives every person a right to ask any business what personal information they hold about them, and to demand correction or deletion. This is called a "data subject access request" or DSAR. You must respond within a reasonable time - most legal advisers settle on 30 days as the safe maximum.

What a valid request looks like

The person sends an e-mail (or letter) saying something like: "Under POPIA section 23, I request copies of all personal information you hold about me." They need to include enough information to identify themselves - usually their full name and an account / order reference.

Step-by-step response process

  1. Verify identity. Confirm the requester is who they claim to be - especially important if the request comes from a different e-mail than your records. A reply via the customer's known e-mail confirming "yes I sent that request" is usually enough for most requests.
  2. Search every system. Your CRM, e-mail account, accounting software, hosting database, mailing list platform. Personal info hides in places you forget about.
  3. Compile the data. A neat document or PDF listing each category (contact info, order history, support tickets, mailing list status) with the actual values.
  4. Respond within a reasonable time. Aim for under 30 days. If a request is genuinely complex, let them know an estimated date.
  5. Charge a reasonable fee only if necessary. Most one-off requests should be free. Repeat or excessive requests may be charged at cost.
  6. Document everything. Keep a log of every DSAR, when it came in, when you responded, and what you sent. The Information Regulator may ask.

What if they ask for deletion?

POPIA gives a right to deletion (erasure) where the data is no longer needed for the purpose collected. But you can refuse if:

  • You have a legal obligation to keep it (SARS requires invoice retention for 5 years).
  • It is needed for an active contract or pending litigation.
  • It is needed for fraud prevention or security.

Where you can't delete, you can usually anonymise (replace name with "DELETED") and keep the rest.

Pro tip: have a public process

Add a section to your privacy policy: "To request a copy of the personal information we hold about you, e-mail privacy@yourdomain.co.za. We respond within 30 working days." This makes most requests quick to handle - the requester knows where to send it, and you have a fixed e-mail to monitor.

Need help with a complex DSAR?

Need a hand?

The Trinico Cloud team is in South Africa and replies during local business hours. Reach us via WhatsApp, e-mail or a support ticket - whichever suits you best.

Contact us Open a support ticket


Was this answer helpful?

« Back
Loading