Statutory topics

POPIA and payroll data protection

Payroll holds identity numbers, banking details, salaries, medical scheme membership and garnishee information. POPIA sets the conditions under which an employer may process that information and how it must be protected.

Responsible party and operator

The employer is the responsible party: it determines why and how employee information is processed. An outsourced payroll provider is an operator, processing on the employer's instruction under a written agreement that requires confidentiality and appropriate security safeguards.

Lawful processing in payroll

  • Processing must be necessary for the employment contract or required by law — payroll qualifies on both grounds
  • Only the information actually needed may be collected
  • Information must be accurate, complete and updated as circumstances change
  • Employees must know what is collected and why
  • Special personal information, such as health data linked to medical aid, requires extra care

Security safeguards that matter in payroll

  • Role-based access so only named users see payroll data
  • Secure transmission of payroll input and payslips rather than open email attachments
  • Verification controls on banking detail changes
  • Audit trails on master data changes
  • Defined breach response, including notification obligations

Retention and deletion

Tax and labour legislation prescribe minimum retention periods for payroll records. POPIA requires that information not be kept longer than necessary once those periods have passed, so retention should be a policy with an end date rather than indefinite storage.

Employee requests

Employees may request access to their personal information and may ask for correction of inaccurate data. A payroll function should be able to respond within the required timeframes without reconstructing records manually.

Frequently asked questions

Does POPIA apply to payroll data?

Yes. Employee payroll information is personal information, and some of it — such as health-related medical scheme data — is special personal information subject to stricter conditions.

Is an outsourced payroll provider a responsible party or an operator?

An operator. The employer remains the responsible party and must have a written agreement obliging the provider to process only on instruction and to apply appropriate security measures.

Can payslips be emailed to employees?

They can, provided appropriate safeguards are in place, such as encryption or password protection and delivery to a verified address. Unprotected bulk email of payslips is a common POPIA weakness.

How long may payroll records be kept?

For at least the minimum periods prescribed by tax and labour legislation. After that, POPIA requires that information no longer needed be deleted or de-identified.

Payroll data handled properly

Patuza operates payroll under a written operator agreement with access control, secure delivery and defined retention.

Book a consultation

Related services

  • Employee administration

    Employee records, onboarding, changes, banking details and statutory data kept accurate and secure.

  • Payroll processing

    Monthly and weekly payroll processing, calculations, payslips and statutory deductions.

  • Payroll audits

    Independent payroll audits covering data integrity, statutory accuracy, controls and risk.

Related topics

  • IRP5

    Employee tax certificates: what they contain, how they are generated and why they get rejected.

  • Statutory deductions

    The full deduction hierarchy: what employers may deduct, in what order and within what limits.

Related insights

Last reviewed 2026-03-01. Rates, thresholds and limits are set by legislation and change — most commonly in the annual Budget. This page explains how the obligation works; always confirm current values against the official SARS or Department of Employment and Labour publication for the applicable tax year.