Employee Data Rights Under POPIA: A Guide for Employers.

What your staff can ask for, and what you must have in place before they do.

Published: 8 September 2026  |  By AOLC

Most South African employers know that POPIA (the Protection of Personal Information Act) places obligations on how they handle customer data. What fewer realise is that their own employees have significant rights under the same Act — and that the workplace is one of the most data-intensive environments imaginable.

Payroll details, performance reviews, disciplinary records, biometric time-and-attendance data, email monitoring logs, productivity tracking screenshots — the list of personal information a typical employer holds about each staff member is extensive. Under POPIA, employees have the right to know what you hold, to request access to it, to demand corrections, and in some circumstances to object to how it is used.

This guide walks you through the key employee data rights under POPIA, what they mean practically for your business, and what you need to have in place before your first access request arrives.

POPIA applies to every person whose personal information you process — including every one of your employees. Ignorance of employee rights is not a defence before the Information Regulator.

What Personal Information Do You Hold?

Before you can manage employee data rights, you need to know what you actually have. A typical employer in South Africa holds a surprising range of personal information about each staff member:

8

The eight conditions for lawful processing under POPIA — accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation — all apply to employee data, not just customer records.

The first step toward compliance is a data inventory. Map what you collect, where it is stored (HR system, payroll software, cloud drives, email), how long you retain it, and who has access. Without this, you cannot respond meaningfully to an employee's access request.

The Right of Access.

Under Section 23 of POPIA, every employee (as a "data subject") has the right to request a description of the personal information you hold about them, and to request a copy of that information in a reasonably understandable form. They also have the right to know the identity of any third parties who have had access to their information.

This is not a hypothetical right — employees are becoming increasingly aware of it, and the Information Regulator has made clear that it expects businesses to have processes in place to respond.

Tip

Build a simple internal request form and a documented 21-business-day response workflow before you receive your first access request. An ad hoc response to a POPIA request — piecing together data from different systems under time pressure — is where errors happen and complaints arise.

Note that the right of access is not absolute. You may legitimately decline or redact parts of a request where disclosure would reveal information about third parties, prejudice legal proceedings, or compromise your security monitoring activities. But you must document your reasons carefully — a blanket refusal is not acceptable.

The Right to Correct and Delete.

If an employee believes that personal information you hold about them is inaccurate, incomplete, misleading, or out of date, they can request that you correct or delete it. This applies across all systems — HR records, payroll software, cloud storage, and email archives.

In practice, this right has limits. You are not required to delete information that you are legally obligated to retain — payroll records and UIF submissions, for example, must be kept for prescribed periods under the Basic Conditions of Employment Act and the Income Tax Act. Similarly, disciplinary records may be retained for legitimate business reasons during an employment relationship.

What you cannot do is continue processing information that the employee has demonstrated is wrong. An employee who can prove their home address has changed, or that a disciplinary record contains factual errors, is entitled to have those corrected. POPIA requires you to ensure the information you hold is accurate and up to date.

R10M

The maximum administrative fine the Information Regulator can impose for POPIA violations — and criminal prosecution is possible for the most serious breaches, with penalties of up to 10 years' imprisonment.

The Right to Object: Monitoring and Surveillance.

Employee monitoring is one of the most sensitive areas of POPIA in the workplace. Many South African employers use tools to monitor email, internet usage, productivity, and in some cases location — and POPIA requires that this be done lawfully.

Section 11 of POPIA allows processing of personal information without consent where it is necessary to pursue the legitimate interests of the responsible party (the employer), provided those interests do not outweigh the employee's right to privacy. But POPIA also gives employees the right to object to processing of their personal information where that processing is based solely on this legitimate-interest ground.

In practice, this means:

If you use employee monitoring tools — productivity tracking, screenshot capture, email monitoring — make sure your IT and HR policies are updated to reflect exactly what data is collected and why. An undisclosed monitoring tool is a POPIA liability. See our StaffWatch product page for how compliant employee monitoring is designed to work.

What Employers Must Have in Place.

Meeting your obligations under POPIA with respect to employee data requires more than good intentions. Here is a practical checklist of what you should have in place:

Tip

The Information Regulator's website (inforegulator.org.za) provides the official form for Information Officer registration, as well as guidance documents on data subject rights. Register your Information Officer if you have not already done so — it is a legal requirement and there is no grace period.


What to Do Next.

POPIA compliance is not a once-off exercise — it is an ongoing operational commitment. The employee data rights described in this guide are not theoretical; they are enforceable, and the Information Regulator has made clear that it will act on complaints.

The good news is that most of what POPIA requires of employers around employee data is simply good HR and IT hygiene: know what you hold, keep it accurate and secure, disclose what you do, and give people a way to exercise their rights. The businesses that struggle are those that have never mapped their data flows, never updated their employment contracts, or are running monitoring tools without proper disclosure.

If you are not sure where your business stands on POPIA compliance — particularly around employee data, monitoring, and cloud storage — an IT and compliance review is a sensible starting point. AOLC can help you assess your current practices, identify gaps, and put the right technical controls in place.

Related reading: POPIA and Cloud Storage: What You Need to Know and How to Handle a Data Breach Under POPIA.

Is Your Business POPIA Compliant?

We can review your employee data practices, update your IT policies, and help you put the right controls in place — before a complaint, not after.

Book a Compliance Review

← Back to Blog