POPIA and Your Scheme: What Trustees and Directors Must Know

Posted: September 15, 2026

POPIA and Your Scheme: What Trustees and Directors Must Know

The POPIA applies to every Sectional Title Scheme and Homeowners Association in South Africa. Here’s who’s responsible, what it means in practice, and how a managing agent fits in.

The Protection of Personal Information Act (POPIA) applies to every Body Corporate and Homeowners Association (HOA) in South Africa. Because schemes systematically collect and retain personal information—such as contact numbers, ID details, banking records, and biometric access data—the Body Corporate or HOA is classified as the Responsible Party under the Act. Consequently, statutory compliance remains the direct responsibility of the Trustees and Directors. While a managing agent processes data on behalf of the scheme under a written agreement and provides operational guidance, ultimate decision-making authority cannot be delegated.

Quick Reference

Question Short Answer
Does POPIA apply to my scheme? Yes — every community scheme processes owners’ personal information
Who is the Responsible Party? The Body Corporate or HOA, acting through its Trustees/Directors
Who is the managing agent, legally? An Operator — processing data on the scheme’s instruction
Who must appoint an Information Officer? The scheme (Trustees/Directors), not the managing agent
Where do you register an Information Officer? With the Information Regulator, via inforegulator.org.za
What’s the penalty for getting it wrong? Fines, and in serious cases imprisonment, plus reputational and legal risk to the scheme
Can the managing agent do this for you? We can guide, draft templates, and implement safeguards — the appointment and final decisions remain the scheme’s

What Is POPIA, in Plain Terms?

The Protection of Personal Information Act, 4 of 2013 (POPIA), is South Africa’s data protection law. It governs how any organisation, including a Body Corporate or Homeowners Association,  may collect, store, use, share, and dispose of personal information belonging to individuals.

For a community scheme, personal information isn’t an abstract compliance buzzword. It’s the everyday data your scheme already holds:

  • Owners’ full names, ID numbers, and contact details
  • Banking details for levy collection and refunds
  • Tenant and occupant information
  • Vehicle registration numbers for access control
  • CCTV footage and biometric access data (fingerprint or facial recognition entry systems)
  • Correspondence, complaints, and arrears records that reference individuals

If your scheme keeps an owners’ register, sends levy statements, or operates a boom gate with number-plate recognition, POPIA already applies to you. There’s no size or type exemption — a six-unit sectional title scheme has the same basic obligations as a six-hundred-unit scheme.

Who Is Actually Responsible? The Scheme, Not the Agent

This is the point that causes the most confusion, and it’s worth being precise about.

POPIA defines two key roles:

  • Responsible Party: the entity that decides why and how personal information is processed. For a community scheme, this is the Body Corporate or Homeowners Association itself, acting through its Trustees or Directors.
  • Operator: a party that processes personal information on behalf of the Responsible Party, under instruction, and only for the purposes agreed. A managing agent acts as an Operator.

In practice, this means:

  • The scheme decides what data is collected and why (for example, collecting ID numbers for owner verification, or vehicle details for access security).
  • The managing agent processes that data to carry out its mandate, preparing levy statements, maintaining the owners’ roll, managing correspondence, but does so on the scheme’s instruction, not its own.
  • POPIA requires a written agreement between the scheme and any Operator (including the managing agent) setting out how personal information will be processed and safeguarded. This is typically built into the management agreement.

The takeaway for Trustees and Directors: appointing a managing agent does not transfer your POPIA compliance duty. It remains with the scheme. A competent managing agent will help you meet that duty efficiently, but the legal responsibility, and the decisions that go with it, stay with the Scheme Executives.

The Eight Conditions for Lawful Processing

POPIA sets out eight conditions that any Responsible Party must meet. Applied to a community scheme, they translate roughly as follows:

  1. Accountability: the scheme must be able to show it takes POPIA seriously, not just claim to.
  2. Processing limitation: only collect what’s actually needed (an owner’s shoe size has no place in a levy database).
  3. Purpose specification: be clear about why data is collected, and don’t use it for something else without a valid reason.
  4. Further processing limitation: don’t repurpose data in ways an owner wouldn’t reasonably expect.
  5. Information quality: keep records accurate and up to date.
  6. Openness: owners should know what information is held about them and why.
  7. Security safeguards: protect data against loss, unauthorised access, or leaks (password-protected systems, restricted access to the owners’ roll, secure disposal of old records).
  8. Data subject participation: owners have the right to ask what’s held about them, request corrections, and object to certain processing.

None of these require dramatic changes for most schemes. They require documented, reasonable practice, knowing what you hold, why you hold it, and who can access it.

Do You Need to Appoint an Information Officer?

Yes. Every Responsible Party in South Africa, including a Body Corporate or HOA, must have an Information Officer. Helpfully, POPIA doesn’t require you to go looking for one: the head of the organisation is automatically the Information Officer by default. For a scheme, that typically means the Chairperson of the Trustees or Directors, unless the Trustees/Directors formally appoint someone else (a Deputy Information Officer) to take on the role.

That Information Officer must be registered with the Information Regulator before performing the role’s duties. Registration is done through the Information Regulator’s online portal at inforegulator.org.za, and the process is free.

Once registered, the Information Officer’s core duties (set out in section 55 of POPIA) include:

  • Encouraging compliance with the eight conditions above
  • Being the scheme’s point of contact for the Information Regulator
  • Handling requests from owners who want to see or correct their own information
  • Overseeing how complaints or data breaches are managed

Important: This is a decision and appointment for the Scheme Executives to make and formalise, typically by trustee or director resolution. A managing agent can advise on the process, provide the registration steps, and help draft the internal policies that support it, but cannot appoint itself as your scheme’s Information Officer, since the role is tied to the Responsible Party, not the Operator.

What Should Trustees and Directors Actually Do?

A practical, non-exhaustive starting checklist:

  • Confirm who your Information Officer is and register them with the Information Regulator if this hasn’t been done.
  • Take stock of what personal information your scheme holds: owners’ roll, financial records, CCTV, access control data, correspondence archives.
  • Check who has access to that information, both within the scheme and at your managing agent, and whether access is reasonably restricted.
  • Confirm your management agreement addresses POPIA: it should record the managing agent’s role as Operator and set out basic safeguards.
  • Have a plan for data subject requests: if an owner asks what information the scheme holds about them, someone needs to know how to respond and within what timeframe.
  • Have a basic breach-response plan: POPIA requires the Information Regulator (and, in some cases, the affected individuals) to be notified of a data breach as soon as reasonably possible.
  • Review retention practices: old owner and financial records shouldn’t be kept indefinitely “just in case”; POPIA requires disposal once the purpose for holding the data has been fulfilled, subject to other legal retention requirements (e.g. financial record-keeping rules).

None of this needs to happen overnight, and it doesn’t require a legal department. It requires a documented, sensible approach, and a managing agent who understands where the compliance line sits.

Where a Managing Agent Fits In

At ANGOR, our role under POPIA is that of an Operator: we process owners’ personal information strictly to carry out the mandate given to us by the Scheme Executives, preparing and distributing levy statements, maintaining financial and owner records, managing correspondence, and reporting on scheme finances. We apply security safeguards to the data we hold on your scheme’s behalf, and we can guide Trustees and Directors through what POPIA requires and where the gaps typically sit.

What we don’t do is make your scheme’s POPIA decisions for you. Appointing and registering your Information Officer, deciding what data your scheme collects and why, and approving your scheme’s data-handling policies are all decisions that belong with the Scheme Executives, as with every other aspect of running your scheme, our role is to advise and implement within the law, not to decide on your behalf.

This general guidance shouldn’t be treated as legal advice. Where a scheme faces a specific or complex POPIA question, for example, a data breach, or a dispute over a data subject request, independent legal advice is the right next step.

Frequently Asked Questions

Does POPIA apply to small sectional title schemes? Yes. There’s no exemption based on the number of units. Every scheme that holds owners’ personal information is subject to POPIA.

Who is legally responsible for POPIA compliance, the Trustees or the managing agent? The Body Corporate or HOA, acting through its Trustees or Directors, is the Responsible Party and carries the compliance duty. The managing agent is an Operator, processing data on the scheme’s instruction.

Does our scheme need its own privacy policy? It’s good practice. A short, clear notice telling owners what personal information is collected, why, and how it’s protected supports the “openness” condition under POPIA.

What happens if a scheme doesn’t register an Information Officer? Non-compliance with POPIA can result in fines and, for serious contraventions, criminal penalties, in addition to the reputational and legal risk of mishandling owners’ data.

Can our managing agent register as our Information Officer? No. The Information Officer role is tied to the Responsible Party (the scheme), typically defaulting to the Chairperson of Trustees or Directors. A managing agent, as an Operator, cannot take on this role for the scheme.

Where do we register an Information Officer? Through the Information Regulator’s online portal at inforegulator.org.za.

Four things you should know about the POPI Act