Statutory topics
POPIA and payroll data protection
Payroll holds identity numbers, banking details, salaries, medical scheme membership and garnishee information. POPIA sets the conditions under which an employer may process that information and how it must be protected.
Responsible party and operator
The employer is the responsible party: it determines why and how employee information is processed. An outsourced payroll provider is an operator, processing on the employer's instruction under a written agreement that requires confidentiality and appropriate security safeguards.
Lawful processing in payroll
- Processing must be necessary for the employment contract or required by law — payroll qualifies on both grounds
- Only the information actually needed may be collected
- Information must be accurate, complete and updated as circumstances change
- Employees must know what is collected and why
- Special personal information, such as health data linked to medical aid, requires extra care
Security safeguards that matter in payroll
- Role-based access so only named users see payroll data
- Secure transmission of payroll input and payslips rather than open email attachments
- Verification controls on banking detail changes
- Audit trails on master data changes
- Defined breach response, including notification obligations
Retention and deletion
Tax and labour legislation prescribe minimum retention periods for payroll records. POPIA requires that information not be kept longer than necessary once those periods have passed, so retention should be a policy with an end date rather than indefinite storage.
Employee requests
Employees may request access to their personal information and may ask for correction of inaccurate data. A payroll function should be able to respond within the required timeframes without reconstructing records manually.
Frequently asked questions
Does POPIA apply to payroll data?
Yes. Employee payroll information is personal information, and some of it — such as health-related medical scheme data — is special personal information subject to stricter conditions.
Is an outsourced payroll provider a responsible party or an operator?
An operator. The employer remains the responsible party and must have a written agreement obliging the provider to process only on instruction and to apply appropriate security measures.
Can payslips be emailed to employees?
They can, provided appropriate safeguards are in place, such as encryption or password protection and delivery to a verified address. Unprotected bulk email of payslips is a common POPIA weakness.
How long may payroll records be kept?
For at least the minimum periods prescribed by tax and labour legislation. After that, POPIA requires that information no longer needed be deleted or de-identified.
Patuza operates payroll under a written operator agreement with access control, secure delivery and defined retention.
Book a consultationRelated services
- Employee administration →
Employee records, onboarding, changes, banking details and statutory data kept accurate and secure.
- Payroll processing →
Monthly and weekly payroll processing, calculations, payslips and statutory deductions.
- Payroll audits →
Independent payroll audits covering data integrity, statutory accuracy, controls and risk.
Related topics
- IRP5 →
Employee tax certificates: what they contain, how they are generated and why they get rejected.
- Statutory deductions →
The full deduction hierarchy: what employers may deduct, in what order and within what limits.
Related insights
- POPIA and payroll data →
Practical steps to protect employee payroll information under POPIA.
- What payroll processing involves →
A cycle-by-cycle walkthrough of how a South African payroll actually runs.
Last reviewed 2026-03-01. Rates, thresholds and limits are set by legislation and change — most commonly in the annual Budget. This page explains how the obligation works; always confirm current values against the official SARS or Department of Employment and Labour publication for the applicable tax year.