SARS & VAT

POPIA Compliance Checklist for Invoicing in South Africa

A practical POPIA checklist for businesses that invoice clients: what belongs on an invoice, what to tell clients, retention versus SARS's five years, Information Officer registration, operator agreements and marketing rules.

· · Updated

If you send invoices, you process personal information: names, email addresses, phone numbers, physical addresses and payment history. Under the Protection of Personal Information Act 4 of 2013 (POPIA) that makes you a responsible party, whether you are a one-person consultancy or a company with staff. This checklist covers what POPIA actually asks of an invoicing business, in the order you will meet each obligation.

Nothing here is legal advice. It is the working list we use at Rebill and the questions our customers ask most.

Who POPIA applies to

POPIA has been fully in force since 1 July 2021 and is enforced by the Information Regulator. It applies to any person or organisation in South Africa that decides why and how personal information is processed. That is the “responsible party”. Anyone who processes the information on the responsible party’s behalf, such as your invoicing software or your accountant, is an “operator”.

Personal information means anything that identifies a living person. A company name on its own is not personal information, but the billing contact’s name, email address and mobile number are. Sole proprietor clients are natural persons, so everything about them is.

The checklist

1. Collect only what the invoice needs

The processing limitation condition says collect no more than the purpose requires. For an invoice, the purpose is billing and payment.

  • Name or trading name, billing address, email address and phone number: needed.
  • VAT number and company registration number: needed for tax invoices to vendors.
  • ID number: not needed for an invoice. Do not ask for it unless a separate process, such as a credit application, genuinely requires it.
  • Client bank details: only if you refund or debit clients. Their EFT reference on your statement is enough to match a payment.

Removing ID numbers from your client form is the single most common fix.

2. Tell clients what you hold and why

The openness condition requires a short notice at the point of collection. A sentence on your quote, client onboarding form or terms is enough:

We collect your name, contact details and address to issue invoices, process payments and meet our SARS record-keeping obligations. Read our privacy policy at yourbusiness.co.za/privacy.

Then publish a privacy policy that says what you collect, why, how long you keep it, who else sees it (your accountant, your invoicing software, your payment gateway) and how a client can ask for access or correction.

3. Register an Information Officer

Every responsible party has an Information Officer by default: the head of the business. For a sole proprietor that is you. Registration with the Information Regulator through its online portal is required and free. Larger businesses may add deputy Information Officers.

4. Keep a PAIA manual

Since 1 January 2022 every private body must have a manual under the Promotion of Access to Information Act, the earlier small business exemption having lapsed. The Regulator publishes a template. For a small invoicing business it is a short document listing your contact details, the records you hold and how someone requests access. Keep it on your website or available on request.

5. Keep records for five years, then review

POPIA says do not keep personal information longer than the purpose requires. The Tax Administration Act says keep invoices and supporting records for five years from the date the relevant return was submitted. Tax compliance is a lawful purpose, so five years is your minimum retention for anything on an invoice.

After five years with no ongoing relationship, delete or anonymise. Write the rule down so it is applied consistently: for example, “client records are reviewed each March and deleted where the last invoice is older than five years”.

6. Secure the data

The security safeguards condition asks for measures appropriate to the risk. In practice for invoicing:

  • Store client records in software with access control and encryption, not in a shared spreadsheet or an email folder.
  • Use a unique password and two-factor authentication on the accounts that hold client data.
  • Limit who on your team can see client records.
  • Keep card details out of your systems entirely. Let a PCI-DSS gateway handle payment.

7. Sign an operator agreement with your software

Section 21 requires a written contract with any operator that processes personal information for you, obliging them to keep it confidential and secure. For most businesses the operators are the invoicing platform, the accounting package, the email provider and the accountant. A vendor’s terms of service or data processing terms normally satisfy this. Check that yours say so, and that the vendor commits to telling you about a breach.

8. Know the rules for cross-border storage

Section 72 allows personal information to leave South Africa when the recipient is bound by law or contract to a similar standard of protection, or the transfer is necessary to perform a contract with the client. Cloud software hosted outside the country is permitted on that basis. Your privacy policy should say where data is stored.

9. Respond to access and correction requests

A client may ask what you hold about them, ask you to correct it, or ask you to delete it. You must respond within a reasonable time. Deletion has a limit: you may keep what tax law requires you to keep, and you should say so in your reply.

10. Report breaches

Section 22 requires notification to the Regulator and to the affected people as soon as reasonably possible after you become aware that personal information was accessed or acquired by an unauthorised person. A lost laptop with unencrypted client records qualifies. So does a phishing incident on the mailbox that holds your invoices.

11. Separate transactional from marketing messages

Invoices, statements, payment reminders and receipts are transactional. They need no consent. Section 69 governs electronic direct marketing:

  • Existing clients may be sent marketing about similar products or services, provided every message offers an easy opt-out.
  • Anyone else needs to opt in before you send the first message.

If your invoicing tool also sends promotional email, check that it honours unsubscribes and keeps the lists separate.

Quick answer

What does POPIA require from a business that invoices clients in South Africa?

Under POPIA, a South African business that stores client names, contact details and addresses for invoicing is a responsible party and must: collect only the details the invoice needs, tell clients why the information is collected, register an Information Officer with the Information Regulator, keep a PAIA manual, secure the data with access controls and encryption, sign a written operator agreement with any software or accountant that processes the data, respond to access and correction requests, and report breaches to the Regulator and affected clients. Invoice records may be kept for the five years that SARS requires, because tax compliance is a lawful purpose. Invoices and reminders are transactional and need no consent. Marketing to existing clients needs an opt-out and marketing to anyone else needs opt-in. The Regulator can impose administrative fines of up to R10 million.

How Rebill covers the technical side

You stay the responsible party for your clients’ data. Tora Technologies, which builds Rebill, is your operator, and the privacy policy and terms set out that relationship.

  • Client names, contact details and VAT numbers are encrypted with AES-256 before storage, with a separate key per account, and everything travels over TLS.
  • Card details never touch Rebill. Payments go through your own Paystack, Yoco, PayFast or iKhokha account.
  • Access is limited to the users you add to your account.
  • You can delete a client, or your whole account, yourself.
  • Marketing email from Rebill is separate from invoice delivery and carries an unsubscribe link.

Read more about security in Rebill.

Frequently asked questions

Does POPIA apply to sole proprietors and small businesses?

Yes. POPIA applies to every responsible party that processes personal information in South Africa. There is no exemption based on size or turnover. Enforcement attention goes to larger data holders first, but the obligations are the same and the fines can apply to anyone.

How long can I keep client invoicing data under POPIA?

At least five years, because the Tax Administration Act requires you to keep invoices and supporting records for five years and tax compliance is a lawful purpose. After that, if the client relationship has ended, delete or anonymise the records.

Do I need consent to send invoices and payment reminders?

No. Invoices, statements, receipts and payment reminders are transactional messages needed to perform the contract with your client. Consent rules under section 69 apply only to direct marketing.

What is the penalty for not complying with POPIA?

The Information Regulator can issue enforcement notices and administrative fines of up to R10 million. Certain offences, such as obstructing the Regulator or unlawfully processing account numbers, carry criminal liability with up to 10 years imprisonment. For most small business gaps the first step is a notice requiring correction.

Do I need to appoint an Information Officer?

You already have one. The head of the business is the Information Officer by default, and for a sole proprietor that is the owner. You must register with the Information Regulator through its online portal. Registration is free.

Ready to simplify your invoicing?

Free forever. Built for South Africa. No credit card required.