Compliance
The POPIA consent form, and what it has to capture.
Most consent forms in circulation are a paragraph and a tick-box. That is not a consent record — it is a hope. Here is what has to be on it, and why each part is there.
Consent is not always what you need
Worth saying before the template: POPIA provides several grounds for lawfully processing personal information, and consent is only one of them. Processing that is necessary to perform a contract, or to comply with a legal obligation, does not need separate consent — and asking for it anyway creates a record you then have to honour when someone withdraws it.
Use consent where consent is genuinely the basis. Direct marketing to people who are not existing customers is the clearest case.
What the form has to capture
A consent record that is worth relying on captures seven things:
- Who is asking
- The responsible party by registered name, not a trading name — plus contact details for the Information Officer.
- What is being collected
- The actual fields. "Your personal information" is not a specification; "full name, ID number, email address, physical address" is.
- Why
- The specific purpose. POPIA requires purpose specification, so a consent record that says "for business purposes" does not evidence much.
- Who else sees it
- Any operator or third party the data is shared with, including offshore processors — this is where transborder flow gets decided.
- How long it is kept
- A retention period tied to the stated purpose.
- How to withdraw
- A route to withdraw consent that is as easy as giving it, and what happens to the data when they do.
- Proof of the moment
- When consent was given, by whom, and through what channel. A tick-box with no timestamp and no record of the wording shown is difficult to rely on later.
The part that is an IT problem
The wording is a legal question. Everything after someone signs it is an infrastructure question, and it is the half that usually fails:
- Where the signed records are stored, and whether that store is itself secured to the section 19 standard.
- Whether withdrawal actually propagates — to the CRM, the mailing list, the backups and the third party you exported to last year.
- Whether you can produce a specific person's consent record on request, within a reasonable time, without a manual search.
- Whether retention is enforced by a process or merely stated on the form.
A consent form the business cannot honour operationally is worse than no consent form, because it documents an undertaking you are visibly not meeting.
The template
Not yet published
The downloadable template is pending review. It will be published here as a plain document, free, with no email gate and no form to fill in first — you should not have to trade your own personal information for a POPIA form.
In the meantime, the seven items above are the checklist. If you need the consent records themselves secured, retained and searchable, that part we can help with directly.
Related
- POPIA and your IT environment — section 19 and section 22 read as infrastructure.
- Penetration testing — evidence that your safeguards are effectively implemented.
This page is written as infrastructure guidance by an IT company, not as legal advice. The wording of a consent form, and whether consent is the right lawful basis for your processing, are questions for a lawyer.
Secure the records, not just the form.
Book a free security assessment — it covers where personal information lives, who can reach it, and whether your backups and access controls would survive a question from the Regulator.