POPIA and payment reminders
POPIA-aware payment reminders for South African businesses
A practical guide to personal information, communication purpose, access, opt-outs, records, security, and retention when following up overdue accounts.
Start with the purpose
Before choosing a channel or writing a message, state why the information is being processed.
A useful purpose statement might be:
To administer the customer account, reconcile payments, communicate an accurate overdue balance, resolve disputes, and arrange payment where appropriate.
Do not quietly reuse the same data for unrelated promotion, profiling, or list sharing. A clear purpose controls which fields are needed, who needs access, how long records should remain, and what the message may say.
Identify the roles
In a typical software-supported reminder process:
- the business that supplied the goods or services decides why and how customer information is used; and
- the software provider processes that information to provide the service on the business's instructions.
POPIA uses the terms responsible party and operator. A contract with an operator does not transfer all responsibility away from the business. The business still needs an appropriate basis, accurate data, suitable instructions, security, and a way to handle data-subject requests.
Use only the information the reminder needs
A basic reminder may need:
- customer name;
- approved contact detail;
- business or account reference;
- invoice number;
- amount and due date;
- payment status;
- communication preference; and
- dispute or plan status.
It probably does not need a full identity document, unrelated notes, complete medical history, or every document in the customer file.
The channel matters. A lock-screen notification or shared phone may expose a message. Use the minimum detail needed for the recipient to recognise the account and reach a secure route.
Keep collection and marketing separate
The Information Regulator's direct-marketing guidance explains section 69 rules for unsolicited electronic direct marketing. A factual reminder about an existing account is not automatically the same as marketing a product.
However, this message mixes the purposes:
Your invoice is overdue. Pay today and receive 15% off your next service.
The promotional offer introduces direct marketing. It can affect the required consent, objection, opt-out, and recordkeeping analysis.
Keep reminders focused on the account. Run promotional communication through its own approved process.
Choose and document the lawful basis
POPIA provides conditions for lawful processing rather than a single rule for every account. The appropriate basis depends on the relationship, contract, law, and purpose.
Document the business's assessment. Do not label every processing activity “consent” by default if the operation actually relies on another lawful basis. Equally, do not treat a contract as permission for any future use of the data.
Where direct marketing by unsolicited electronic communication applies, consult section 69, the Information Regulator's current guidance, and the amended regulations. The 2025 regulations include ways to request consent and state that opt-out does not constitute consent.
Build rights and preferences into operations
A customer should have a usable route to:
- correct a wrong phone number or account detail;
- object where POPIA provides that right;
- change an applicable communication preference;
- request access to relevant personal information;
- raise a dispute; and
- contact the business's privacy or information officer function.
Do not leave these requests in an unmonitored inbox. Assign an owner and response process.
For WhatsApp, platform opt-in requirements apply in addition to South African law. See the WhatsApp payment reminder guide.
Keep information accurate
Incorrect debt data can cause direct harm. Before and during a campaign:
- reconcile recent payments;
- remove duplicate accounts;
- verify contact details;
- apply credits and adjustments;
- pause disputed amounts;
- stop contact with wrong recipients; and
- make correction history visible.
A system should not overwrite a dispute or opt-out the next time a spreadsheet is imported.
Limit access and secure the workflow
Use role-based access. A receptionist may need to see a reply and account status without seeing all billing administration. An external support user should not receive broad access by default.
Security controls should include:
- unique user accounts;
- multi-factor authentication where available;
- encryption in transit and at rest;
- audit records;
- controlled exports;
- tested backup and recovery;
- secure deletion; and
- a documented incident process.
When connecting channel or payment providers, keep credentials out of spreadsheets and messages.
Set retention rules
“Keep everything forever” is not a retention policy.
Define retention by record type:
| Record | Retention question |
|---|---|
| Invoice and accounting record | What law and financial process requires it? |
| Communication history | How long is it needed for account administration, disputes, or proof? |
| Opt-in or preference evidence | How long must the business demonstrate the permission or choice? |
| Failed contact data | Can it be corrected, suppressed, or deleted? |
| Export files | When will temporary copies be securely removed? |
When a purpose ends, delete or de-identify information unless another lawful requirement justifies retention.
Special cases need additional care
Healthcare
Do not reveal a diagnosis, treatment, or sensitive medical detail in a payment reminder. Use a neutral practice and account reference, then move the conversation to an authenticated route.
Schools
Information involving learners and family circumstances needs careful access and message design. School exemptions and other sector obligations should not be reduced to generic reminder logic.
Credit agreements
If the National Credit Act applies, collection, notices, debt review, and enforcement require their own controls. POPIA compliance does not prove compliance with the National Credit Act.
A pre-send checklist
- The purpose is documented.
- The customer and balance are accurate.
- The chosen channel is permitted and appropriate.
- The message contains no unnecessary sensitive detail.
- Marketing content is not mixed into the reminder.
- Preference, objection, and wrong-number flags are applied.
- Replies are monitored.
- A dispute pauses the normal workflow.
- Access and export permissions are limited.
- Retention and deletion rules are defined.
How Zeroed approaches the roles
The business using Zeroed remains responsible for its customer relationship and instructions. Zeroed processes account information to provide the configured first-party reminder service and builds preference, contact history, and workflow controls into the product.
Common questions
Frequently asked questions
Does POPIA prohibit payment reminders?
No blanket rule prohibits legitimate payment reminders. The business must still have a lawful purpose and basis, process information proportionately, keep it secure and accurate, and respect applicable data-subject rights.
Is every payment reminder direct marketing?
Not necessarily. A message about an existing account can have an operational collection purpose. Adding promotional content may change the analysis, so keep collection and marketing purposes separate.
Who is responsible for customer data when using reminder software?
The business normally determines why and how its customer data is used and remains responsible for its POPIA duties. A software provider generally processes the data as an operator on documented instructions.
Evidence
Sources
- Protection of Personal Information Act 4 of 2013 — South African Government. Accessed 28 July 2026.
- Guidance Note on Direct Marketing under POPIA — Information Regulator South Africa. Accessed 28 July 2026.
- Regulations relating to POPIA as amended in 2025 — Information Regulator South Africa. Accessed 28 July 2026.