POPIA compliance checklist
The 7 things every SA agent needs to be doing.
POPIA isn't optional, and the Information Regulator is increasingly active. Here are the 7 things every South African estate agent must be doing to stay compliant, and how RealtyPA helps with each one.
- 1
Have a privacy policy on your website
Plain-language description of what data you collect, why, and how. RealtyPA-published agencies inherit a starter policy you can customise.
- 2
Get explicit consent, scoped to purpose
Consent for marketing is separate from consent for deal updates. RealtyPA's consent tracking handles this per contact, per purpose.
- 3
Log every data access
POPIA requires you to know who accessed what, when. Every view of a contact in RealtyPA is logged automatically.
- 4
Honour subject access requests
A data subject can request a copy of everything you hold, or ask you to delete it. RealtyPA gives you one-click export and one-click deletion per contact.
- 5
Have a data processing agreement
When you use a CRM, you and the CRM are joint controllers. RealtyPA provides a POPIA-aligned DPA for every customer, request via support.
- 6
Notify breaches within 72 hours
POPIA requires notifying affected parties + the Regulator within 72 hours of a confirmed breach. RealtyPA monitors for unauthorised access patterns and alerts you immediately.
- 7
Train your agents
Every agent needs basic POPIA awareness. RealtyPA's onboarding includes a 10-minute POPIA primer for new agents.
From agents who've done it.
The Information Regulator publishes enforcement actions. Read them, most are agencies that didn't do step 1 or step 4.
Schedule a quarterly review of your consent records. Stale consent is invalid consent.
Two-factor authentication on every agent's RealtyPA login is the single biggest security upgrade you can make today.

Want to try it yourself?
Start with 30 days free and 5 property reports. No card. Same login across desktop and mobile.