A research compliance checklist for POPIA and survey data is a systematic way to make sure your study aligns with South Africa's Protection of Personal Information Act. It covers the principles and practical steps for lawfully collecting, processing, and storing personal information from participants, so getting it right protects you from fines and builds the trust that produces better response quality.
This guide is not legal advice. It's a practical field checklist covering the areas researchers most often get wrong: consent, data minimisation, security, cross-border transfers, and breach response, built from POPIA's actual text and current Information Regulator guidance.
Does POPIA apply to your survey?
Almost certainly, if your research touches South Africa in any way. POPIA governs how personal information is collected, used, and stored by any "responsible party" operating in South Africa, and it has applied in full since 1 July 2021. The scope is broad: it covers international researchers using data processing tools based in South Africa, and it protects both natural persons and juristic persons (companies, trusts, and other legal entities), which is wider than comparable laws like the GDPR. If your survey collects names, opinions, contact details, or anything that can be traced back to a person, POPIA is in play.
The foundation: consent and legal basis
Survey consent requirements
Consent is POPIA's most common legal basis for processing survey data, defined as a voluntary, specific, and informed expression of will. In practice, that means a participant must actively agree, typically through an "I agree" checkbox or by proceeding past a clear notice, rather than through a vague, blanket agreement to unspecified future uses.
POPIA consent vs. research (ethics) consent
These two are related but not identical. Research consent is the ethical approval a person gives to take part in a study; POPIA consent is the specific legal permission to process their personal data. Ideally your ethics consent form captures both. Where this gets tricky is "broad consent," the practice in some academic and health research of asking participants to agree to future, related studies in general terms. POPIA leans toward requiring specific consent for each processing purpose, particularly for sensitive data, so the safest approach is to write ethics consent language specific enough to also satisfy the legal standard.
Other legal bases for processing
- 01Consent. The participant has given clear, informed agreement for a specific purpose.
- 02Contractual necessity. Processing is required to perform a contract with the participant.
- 03Legal obligation. Processing is required to comply with an obligation imposed by law.
- 04Legitimate interest. Processing protects a legitimate interest of the participant or a third party.
Document whichever basis you're relying on before fieldwork starts, not after.
Communicating with participants: transparency
Transparency is one of POPIA's core conditions. Participants need a clear privacy notice at the start of the survey, usually covering who is collecting the data, why, what will be done with it, how long it will be kept, and who to contact with questions or complaints. Being upfront tends to improve engagement too, participants who understand what's happening are more likely to complete a study and answer honestly. Starting from survey templates with built-in intro and consent language helps standardise this across projects.
A practical compliance checklist across the data lifecycle
Plan for the smallest sample you actually need before you collect anything, a sample size calculator helps scope this upfront.
Data minimisation
Only collect personal data that's genuinely necessary for the research purpose. Before adding a question, ask whether you truly need that specific piece of information. Collecting extra data "just in case" isn't compliant and simply increases your risk if something goes wrong. Pulling from a curated survey question bank rather than writing new items for every construct keeps instruments lean by default.
De-identification and pseudonymisation
Assigning participants a system ID instead of working directly with names or phone numbers reduces exposure if data is ever accessed without authorisation. Platforms built for research automate much of this, letting researchers work with response data without ever seeing raw contact details.
Retention and deletion
POPIA's purpose limitation principle means data shouldn't be kept indefinitely. Define a retention period in your Data Management Plan, and delete data securely once it's no longer needed for its original purpose. Configurable retention rules on your research platform help automate this rather than relying on someone remembering to do it manually.
Protecting your data: security and transfers
Security safeguards
Condition 7 of POPIA requires "appropriate, reasonable technical and organisational measures" to prevent loss, damage, or unauthorised access to personal data. In practice that means encryption at rest and in transit, access controls limiting who can see raw data, and regular security reviews of any platform or vendor handling participant information.
Cross-border transfers
Section 72 restricts sending personal information outside South Africa unless specific conditions are met. The most common lawful grounds are set out below.
| Ground | What it requires |
|---|---|
| Adequate protection | Recipient is bound by law, corporate rules, or agreement offering protection substantially similar to POPIA |
| Data subject consent | Participant has given informed consent to the specific cross-border transfer |
| Contractual necessity | Transfer is required to perform a contract with, or for the benefit of, the participant |
| Benefit of data subject | Transfer benefits the participant and consent could not reasonably be obtained |
Regional data residency options simplify this considerably. Yazi, for example, allows survey data to be stored in data centres in South Africa or the EU, which keeps most cross-border questions off the table entirely; see the Data Security Executive Summary for specifics.
When things go wrong: breach response
Section 22 requires that if you have reasonable grounds to believe a breach has occurred, meaning personal information may have been accessed or acquired by an unauthorised person, you must notify the Information Regulator and affected participants as soon as reasonably possible. As of April 2025, breach notifications must be submitted through the Information Regulator's eServices portal rather than the older paper-based form, so it's worth confirming your incident response plan reflects the current process.
Documenting everything: your compliance paper trail
- 01Ethics approval letters. Evidence an ethics committee or IRB reviewed and approved the study.
- 02Data Management Plan. A living document covering security, consent, retention, and anonymisation.
- 03De-identification logs. The key mapping identities to codes, stored separately and securely from the research data itself.
- 04Data sharing agreements. Formal contracts with any third party or "operator" processing data on your behalf.
Advanced compliance: assessing risk
Privacy Impact Assessments
A Personal Information Impact Assessment (also called a PIIA or DPIA) systematically evaluates how a project might affect participant privacy and helps identify risks before they become incidents. POPIA doesn't make these mandatory for every project, but they're strongly encouraged for anything involving high-risk processing.
What makes research "high risk"
POPIA doesn't provide an exhaustive list, but research is generally treated as higher risk if it involves large-scale processing, vulnerable groups such as children, special personal information, or novel technology like automated profiling. If your study falls into these categories, a PIIA and stronger-than-baseline security measures are worth the extra time.
Special personal information and child data
Special personal information includes health status, race or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, and criminal history. Processing it is generally prohibited unless you have explicit consent or another specific legal exception applies. Child data, meaning information from anyone under the age of 18, cannot be processed without consent from a parent or legal guardian, and research with children typically needs both parental consent and the child's own assent where they're old enough to understand what's being asked.
Frequently asked questions
What is the most important part of a POPIA compliance checklist for survey data?
Establishing a lawful basis for processing, usually participant consent, and being transparent about how the data will be used. Without that foundation, the rest of your compliance effort may not hold up.
Does POPIA apply to anonymous surveys?
If a survey is genuinely and completely anonymous, with zero identifiers and no way to link responses back to a person, POPIA does not apply. Many "anonymous" surveys collect data that becomes identifiable once combined, so it's best to treat borderline cases with caution.
What's the biggest mistake researchers make with POPIA?
Collecting more data than necessary, or reusing existing data for a new purpose without fresh consent. Missing data sharing agreements with third-party collaborators or service providers is another common gap.
Can survey data be reused for a different research project later?
Generally not without explicit permission. POPIA's purpose specification principle means data is collected for a defined purpose, and reusing it for something else typically requires new consent, unless the data has been fully de-identified.
How does a platform like Yazi help with POPIA compliance?
By building compliance into the workflow itself: encrypted storage in compliant regions like South Africa or the EU, structured consent capture, configurable retention rules, and pseudonymisation that reduces the researcher's exposure.
Do I need a lawyer to be POPIA compliant?
For complex or high-risk projects, consulting a legal expert is worthwhile. For most standard research, understanding the principles in this guide and using a compliant platform puts you in a strong position on your own.
What happens if I don't comply with POPIA?
The Information Regulator can issue enforcement notices and administrative fines of up to R10 million for the most serious contraventions, alongside reputational damage and lost participant trust that can be harder to recover from than the fine itself.
Run studies that respect POPIA from the first message to the last data point.
Ready to run surveys that deliver strong response rates while staying compliant? Request a WhatsApp research software demo to see how Yazi supports compliant research end to end.
Book a Demo →%202.png)



