
POPIA gives every person a right to ask any business what personal information they hold about them, and to demand correction or deletion. This is called a "data subject access request" or DSAR. You must respond within a reasonable time - most legal advisers settle on 30 days as the safe maximum.
What a valid request looks like
The person sends an e-mail (or letter) saying something like: "Under POPIA section 23, I request copies of all personal information you hold about me." They need to include enough information to identify themselves - usually their full name and an account / order reference.
Step-by-step response process
- Verify identity. Confirm the requester is who they claim to be - especially important if the request comes from a different e-mail than your records. A reply via the customer's known e-mail confirming "yes I sent that request" is usually enough for most requests.
- Search every system. Your CRM, e-mail account, accounting software, hosting database, mailing list platform. Personal info hides in places you forget about.
- Compile the data. A neat document or PDF listing each category (contact info, order history, support tickets, mailing list status) with the actual values.
- Respond within a reasonable time. Aim for under 30 days. If a request is genuinely complex, let them know an estimated date.
- Charge a reasonable fee only if necessary. Most one-off requests should be free. Repeat or excessive requests may be charged at cost.
- Document everything. Keep a log of every DSAR, when it came in, when you responded, and what you sent. The Information Regulator may ask.
What if they ask for deletion?
POPIA gives a right to deletion (erasure) where the data is no longer needed for the purpose collected. But you can refuse if:
- You have a legal obligation to keep it (SARS requires invoice retention for 5 years).
- It is needed for an active contract or pending litigation.
- It is needed for fraud prevention or security.
Where you can't delete, you can usually anonymise (replace name with "DELETED") and keep the rest.
Pro tip: have a public process
Add a section to your privacy policy: "To request a copy of the personal information we hold about you, e-mail privacy@yourdomain.co.za. We respond within 30 working days." This makes most requests quick to handle - the requester knows where to send it, and you have a fixed e-mail to monitor.
Need help with a complex DSAR?
Need a hand?
The Trinico Cloud team is in South Africa and replies during local business hours. Reach us via WhatsApp, e-mail or a support ticket - whichever suits you best.