Home › Blog › POPIA for psychologists
POPIA psychologists South Africa

POPIA for psychologists: a practical guide

By Nerela · Published 27 September 2026 · 9 min read

Every psychology practice in South Africa processes what POPIA treats as special personal information from the very first intake form. Here's what that actually requires of you in practice, not just in theory.

What POPIA is, and why it applies to you

The Protection of Personal Information Act (POPIA) is South Africa's general data protection law, setting out how organisations — including a one-person psychology practice — must collect, use, store and protect personal information. Health information is treated as "special personal information", with its own conditions attached to processing it.

Lawful basis and consent

Processing special personal information generally requires a valid basis, and for a psychology practice this typically means clear consent from your patient, alongside the fact that you're processing it as part of legitimate treatment under a duty of confidentiality. In practice: make sure your intake process actually tells patients what you collect, why, and what you do with it, rather than assuming consent is implied just because someone booked a session.

Keeping the data secure

POPIA requires "appropriate, reasonable technical and organisational measures" to protect personal information against loss, damage and unauthorised access. For a psychology practice, that translates into concrete choices: encrypted storage and transmission, access limited to people who actually need it, and a real backup plan — not just good intentions.

This applies to session notes just as much as to admin data. Clinical notes, patient contact details and invoicing records are all personal information under POPIA — see our guide to what to include in session notes for the clinical side of the same requirement.

What happens if there's a breach

POPIA requires notifying the Information Regulator, and affected patients, as soon as reasonably possible after you become aware of a security compromise that could have led to unauthorised access to their personal information. Having a plan for this before it happens — who you'd contact, what you'd tell affected patients — is far better than working it out in the moment.

Your patients' rights

Patients generally have the right to know what personal information you hold about them, to request access to it, to ask for it to be corrected if it's wrong, and — subject to your professional and legal record-keeping obligations — to object to certain processing or ask for information to be deleted. Being able to actually act on these requests, not just acknowledge them, matters.

A request you can actually fulfil, not just accept

It's one thing to write a privacy notice that lists these rights; it's another to be able to produce a patient's full record within a reasonable time when they actually ask for it, in a form they can use. If your notes and invoices are scattered across paper files, personal email and a spreadsheet, a straightforward access request becomes a genuinely difficult task under time pressure. Keeping records in one place you can search and export on demand isn't just convenient day to day — it's what turns "patients have a right to access their data" from a line in a document into something you can actually do.

Cross-border data and where your records are actually hosted

If any part of your patient data is stored or processed outside South Africa — which is increasingly common once you use cloud-based practice software — POPIA requires that the information still receives an adequate level of protection once it's crossed that border. In practice, that means asking any software provider a direct question: where is the data actually hosted, is it encrypted, and does the provider's own agreement give you the guarantees POPIA expects, rather than assuming "it's in the cloud" is a sufficient answer on its own.

The Information Regulator (South Africa)

The Information Regulator is the body responsible for overseeing compliance with POPIA in South Africa — the equivalent role to a data protection authority elsewhere. If you're ever unsure how a specific POPIA requirement applies to your practice, its published guidance is the authoritative place to check, rather than relying on general summaries like this one for a specific compliance decision.

Frequently asked questions

What is POPIA?+

The Protection of Personal Information Act — South Africa's general data protection law, setting out how personal information, including patients' health information, must be collected, used, stored and protected.

Does POPIA require patient consent for every use of their data?+

Consent is one lawful basis, and typically the relevant one for a psychology practice, alongside the fact that processing happens as part of legitimate treatment under a duty of confidentiality. Being transparent with patients at intake about what you collect and why is the practical starting point either way.

What happens if there's a data breach at my practice?+

POPIA requires notifying the Information Regulator and affected patients as soon as reasonably possible once you become aware of a security compromise that could expose their personal information. Having a plan for this in advance is far better than improvising it.

Encrypted, isolated, and yours to export at any time

Nerela hosts patient data encrypted in the European Union, with database-level isolation per account.

14 days free, no card · No lock-in · We answer directly

nAbout Nerela

Nerela is practice management software built for psychologists and clinics: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.

Start on Nerela — 14 days free →