Guide · 8 min read
POPIA and payment records: what finance teams should keep
Yes, POPIA applies to your payment records. Invoices, bank details, staff claims and approval notes contain personal information about sole traders, individuals and your own staff. You must use it only for paying and accounting, limit who can see it, keep it secure, keep it no longer than you need to, and report a breach to the Information Regulator.
Updated By the EzeFlow team
In short
- Supplier bank details, invoices from individuals and staff claims are personal information under POPIA.
- You normally do not need consent to pay a supplier, but you must use the information only for that purpose.
- Give access only to people who need it, per branch or company, and log who looked at and changed what.
- Keep records as long as tax and other laws require, then destroy or de-identify them.
- Know who your information officer is, and have a plan for a breach before you need it.
This guide is general information, not legal advice.
Are supplier and payment records personal information?
Yes, in most cases. POPIA covers information about an identifiable living person, and also about an existing company or other juristic person. A finance department holds a lot of it.
| Record | Personal information in it |
|---|---|
| Supplier master file | Names, bank account numbers, phone numbers, email addresses, VAT and registration numbers |
| Invoices from sole traders, contractors and locums | Name, address, sometimes an ID number, bank details |
| Staff expense claims and slips | Employee names, bank details, where they were and what they bought |
| Approval notes and chats | Opinions about people, reasons for rejecting a claim |
| Bank payment files | Recipient names and account numbers, in bulk |
Bank account numbers need extra care. POPIA has specific offences for mishandling account numbers, and a leaked supplier list with bank details is exactly what fraudsters use to fake invoices.
The eight POPIA conditions, applied to payment records
- Accountability. Someone in the business owns compliance, starting with the information officer.
- Processing limitation. Collect only what the payment needs, on a lawful ground.
- Purpose specification. Know why you hold each record, and how long you need it.
- Further processing limitation. Do not reuse supplier data for something unrelated, such as marketing.
- Information quality. Keep bank details accurate and up to date. A wrong account number is a POPIA problem and a payment problem.
- Openness. Tell suppliers and staff what you hold and why, usually in your privacy notice or supplier terms.
- Security safeguards. Protect the records against loss, damage and unauthorised access.
- Data subject participation. A supplier or employee can ask what you hold about them and ask for corrections.
Collect only what the payment needs
To pay a supplier you need their name, bank details, the invoice and enough proof that the goods or service arrived. You rarely need a copy of an owner's ID document, their home address or their personal cellphone number. If a supplier form asks for those out of habit, remove the fields.
You do not usually need consent. POPIA allows processing when it is needed to carry out a contract with the person, or to comply with a law, such as keeping records for SARS. Paying a supplier for delivered goods fits the first ground.
Purpose limitation also means not letting the data drift. The supplier list should not end up in a sales team's mailing list, and scanned staff slips should not be forwarded around on WhatsApp.
Who should be able to see bank details and invoices?
Only people whose job needs it. In practice:
- Requesters see their own requests and the documents they attached.
- Approvers see the requests of the branches or companies they approve for, not the whole group.
- The bank team maintains supplier bank details. Nobody else should be able to change them.
- Exports of supplier lists and payment files should be limited to a few people, and each export should be logged.
Pair access rules with strong sign-in. Shared passwords and a finance mailbox everyone can open undo every other control. Two-factor sign-in for anyone who can see bank details is a reasonable security safeguard.
How long should you keep payment records?
POPIA says you may not keep personal information longer than you need it for its purpose, unless a law, a contract or your legitimate business need requires it. For payment records, tax law usually sets the minimum. SARS generally expects records to be kept for five years from the date the relevant return was submitted, and other laws or your auditor can require longer.
Write a short retention schedule: record type, how long, and who deletes it. Review it once a year. When the period ends, destroy or de-identify the records, in your software, your shared drives and the email inboxes where copies ended up.
Who is responsible? The information officer
Every business has an information officer. By default it is the head of the business, such as the owner or managing director. They can appoint deputy information officers, and the information officer must be registered with the Information Regulator.
The finance manager is often a sensible deputy, because finance holds bank details, salaries and supplier records. The information officer's job includes a compliance framework, staff awareness and dealing with requests from people who want to see their information.
What to do if payment data is breached
If you have reasonable grounds to believe someone accessed personal information without authority, POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. Typical finance breaches are a hacked mailbox, a lost laptop with supplier files on it, or a payment file emailed to the wrong person.
- Contain it. Reset passwords, end sessions, recall or block what you can.
- Find out what was exposed and whose information it was. An audit log makes this a lot quicker.
- Warn suppliers and staff that fake emails asking for payments or bank changes may follow.
- Notify the Information Regulator and the affected people. The Regulator's website explains the current way to report.
- Fix the cause and record what you changed.
Questions to ask your software provider
A provider that stores your payment records for you acts as your operator under POPIA. You need a written agreement that requires them to keep the information secure and confidential. Ask:
- Where is the data hosted? If it leaves South Africa, POPIA's rules on cross-border transfers apply.
- Can access be limited per branch or company, and per role?
- Are bank account numbers stored encrypted?
- Is there an audit log of sign-ins, changes and exports that you can search and export?
- Can you get your data out in a standard format?
How EzeFlow helps
EzeFlow is hosted in South Africa, in Johannesburg. Users are assigned to one or more organizations and only see those payments, reports and search results. Roles control what each person can do, and on Professional and Enterprise you can build your own from 24 permissions. When you @tag a colleague on a payment, they get access to that one payment only.
Supplier bank account numbers are stored encrypted and shown masked. Two-factor sign-in (emailed code or a free authenticator app) can be made compulsory for finance and admin roles, sessions time out and accounts lock after repeated failed sign-ins. The audit log records sign-ins, approvals, edits and exports, and you can search it and export it to CSV.
Frequently asked questions
Does POPIA apply to supplier bank details?
Yes. A sole trader's or individual's name, bank account number, phone number and email address are personal information. POPIA also protects existing juristic persons, so information about supplier companies is covered too. Handle all supplier records as if POPIA applies.
Do we need a supplier's consent to keep their bank details?
Usually not. POPIA allows processing without consent when it is needed to carry out a contract with the person, or to comply with a law, such as tax record-keeping. Paying a supplier for goods they delivered fits the first ground. You still need to tell them why you hold the information and keep it safe.
How long can we keep invoices and payment records under POPIA?
For as long as you need them for the purpose, or as long as a law requires. SARS generally expects tax records to be kept for five years from the date the return was submitted, and other laws or your auditor may require longer. After that, destroy or de-identify the records.
Who is the information officer in a small business?
By default it is the head of the business: the owner, managing director or CEO. They can appoint deputy information officers, and the information officer must be registered with the Information Regulator. The finance manager is often a sensible deputy because finance holds so much personal information.
Do we have to report a hacked email account that exposed supplier invoices?
If there are reasonable grounds to believe personal information was accessed by someone without authority, POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. Contain the breach first, then work out what was exposed. The Regulator's website explains how to report.
Is this guide legal advice?
No. It is general information for finance teams, based on how payment records are usually handled. For decisions about your own business, speak to your information officer or a legal adviser.
Keep reading
More guides for finance teams
8 min read
How to set up a payment approval process in South Africa
Who may request, who approves, what evidence you keep, and how to prove it at audit time.
Read the guide7 min read
FNB bulk payments from a CSV file: a step-by-step guide
How the FNB Online Banking Enterprise payment import works and how to avoid rejected lines.
Read the guide6 min read
Why WhatsApp and email approvals fail at audit time
The five gaps auditors find, and what a proper approval trail looks like instead.
Read the guide