Features How it works Pricing FAQ The Bursar's Handbook
Compliance

POPIA for the Bursar's Office: What Independent Schools Must Do

Fee accounts, banking details, medical notes and family records all pass through the bursar's office. POPIA is not a compliance exercise for the legal team to file; it is a practical discipline for the office that holds the data.

Photograph of a man signing a school policy document at an office desk
On this page

    The Protection of Personal Information Act (POPIA, Act 4 of 2013) regulates how any person or organisation collects, uses, stores and shares personal information in South Africa. It has been fully in force since 1 July 2021, and it has teeth: administrative fines run to millions of rand. For an independent school, the obligations land hardest not in the principal's office but in the bursar's office, because that is where the sensitive data lives.

    Why POPIA is a bursar problem

    Think about what crosses the finance desk in a single enrolment cycle: parents' names and ID numbers, home addresses, banking details, salary information on fee-concession applications, medical notes in support of a fee waiver, and a running record of who pays on time and who does not. All of it is protected. Some of it - medical notes above all - falls into the special categories POPIA treats most strictly, but banking details and payment histories are exactly the records a fraudster wants, so the whole file deserves careful handling.

    That data is exactly what a data breach would cost the school dearly, both in fines and in reputation. A school that loses a parent's bank details does not get to explain it away over coffee. POPIA is how the school proves it can be trusted with that data in the first place.

    What POPIA actually asks

    POPIA's eight conditions for lawful processing, in plain language, are:

    1. Accountability. The school must actually run its data-handling this way, and be able to show it.
    2. Processing limitation. Collect and use personal information lawfully, and collect only what is needed.
    3. Purpose specification. Collect for a specific, lawful purpose and do not quietly repurpose it later.
    4. Further processing limitation. If you use the data for a new purpose, make sure it is compatible with the original one.
    5. Information quality. Keep it accurate, complete and up to date.
    6. Openness. Document what you hold and why, and tell people you collect it.
    7. Security safeguards. Protect it against loss, damage and unlawful access.
    8. Data subject participation. Let parents see their information, correct it, and object when appropriate.

    That is the whole Act, essentially. The rest of this guide turns those eight conditions into the specific jobs that sit in the bursar's office.

    Step 1: Map where personal information lives

    You cannot protect data you do not know you have. Before changing anything else, do a morning's honest inventory:

    • The fee system. Names, bank details, fee histories, arrears notes.
    • Enrolment and admissions records. Paper and electronic copies of every form ever completed.
    • Spreadsheets. The classic offender. If a spreadsheet with parent data exists anywhere outside the fee system, name it, log it, and decide whether it should exist.
    • Email and messaging. Bank details sent by parents, fee correspondence, payment confirmations - all of it is stored personal information.
    • Paper. Filing cabinets, boxes, withdrawal files, old levy slips waiting for shredding.

    Write the list down. This list becomes the basis of your school's records register, and it is the single most useful compliance document you will produce.

    Step 2: Collect only what you need

    The collection condition is the one that saves you the most future pain. For every field on every form, ask the question a child would ask: why do you need this?

    • Bank details - needed to collect fees and refunds. Clear.
    • ID numbers - needed for some financial and legal processes. Make sure the form says why.
    • Medical information - needed only where it genuinely affects the child's schooling or a fee decision. If you hold it, you must secure it more tightly and justify it.
    • Anything optional - drop it. Every unnecessary field is a field that can leak.

    The enrolment form is the right place to ask once, clearly, what the school needs and why. A short privacy notice at enrolment - what we collect, why we collect it, who we share it with - turns a legal requirement into something parents actually appreciate.

    Step 3: Secure what you keep

    Security safeguards are the practical heart of POPIA, and they are mostly common sense:

    • Access control in the fee system. Only the people who need to see arrears, bank details or concession records should be able to. A simple role-based permission list is a huge step.
    • Passwords and devices. Strong passwords, screen locks, and encryption on the laptop that holds the fee export. Encryption does not make a lost laptop disappear from the incident log - it is evidence you report that unauthorised access was unlikely, not a reason to stay quiet.
    • Keep it out of shared spaces. No fee lists on the office network share, no parent data in group WhatsApp messages, no printed arrears lists on the counter.
    • Paper discipline. Locked cabinets, and a shredding routine that actually runs.
    • Backups. Backed up and tested, because the backup is also a copy of the data and it needs the same protection.

    Notice that almost all of this is behaviour, not paperwork. POPIA compliance in the bursar's office is mostly about how the office runs every day.

    Step 4: Put your operators in writing

    Any third party that processes personal information on the school's behalf is an "operator" under POPIA: your payment gateway, SMS and email providers, fee-collection software, debt-collection agencies, auditors and IT support. The school must have a written agreement with each operator covering how the data is handled, secured and returned or destroyed.

    In practice this is a short addendum to the contracts you already have: "This supplier will process the personal information we share with it only for the purposes we specify, will protect it, and will not use it for its own benefit." Many reputable suppliers now have standard operator agreements they are happy to sign. Ask for them.

    Step 5: Handle data subject requests

    Parents have rights over their information, and the school needs a simple way to respond:

    • Access. "What do you hold on us?" - you must be able to produce the fee account, enrolment form and correspondence, promptly and in plain form.
    • Correction. "Our surname changed / that address is wrong." - update it in the system, not just in your head.
    • Objection. To direct marketing or other processing - honour it, and log it.
    • Complaints. A parent can escalate to the Information Regulator, which is why handling the first request well matters.

    Most of these requests are rare and simple. What matters is that the school does not fumble the rare one, because a fumbled request becomes a regulator complaint.

    Step 6: Know what to do in a breach

    POPIA requires the school to notify the Information Regulator of security compromises as soon as reasonably possible, and the Regulator's guidance is to report them irrespective of how serious they first appear - it assesses the risk, not the school. Data subjects must be notified too where the compromise could result in harm, unless the Regulator directs otherwise. The route is: identify what happened, assess the harm, notify, then fix the gap.

    What that means for the bursar's office:

    • Have a one-page breach process before you need it. Who decides, who contacts the Regulator, what you tell parents.
    • Err on the side of acting quickly. The fine is for failing to notify; it is not for the breach itself. The school that reports a real incident promptly is behaving exactly as the Act wants.
    • Learn from it. Most breaches trace back to a habit: an unlocked cabinet, a shared password, a laptop left in a car. Fix the habit.

    The roles the school must have in place

    POPIA requires every private body, including a school, to designate an Information Officer - normally the head of the school - who is accountable for compliance. The designation is registered with the Information Regulator. The school should also have a PAIA manual in place, which is the document that tells people how to ask for information held by the school.

    The Information Officer does not have to do the data work personally, but they own it. In most independent schools, the practical day-to-day responsibility for the data in the finance office sits with the bursar. Make sure both people know which is which.

    Make it an annual routine

    POPIA is not a once-off project. Fold it into the calendar like month-end:

    • Each year, re-run the data inventory. It takes an hour now that it exists.
    • Check the operator agreements whenever a supplier contract renews.
    • Review retention. Fee records you are legally obliged to keep (audit and tax records, for example) stay; duplicate or obsolete copies go to the shredder.
    • Confirm the Information Officer designation is current after any leadership change.

    If you build a proper compliance calendar for the year, POPIA sits naturally alongside your other obligations. Our annual compliance checklist lists the recurring jobs so nothing quietly lapses.

    Sources & further reading

    This page is general information, not legal advice. POPIA obligations depend on your school's specific processing activities. Confirm the requirements that apply to your school with the Information Regulator's guidance or a qualified legal advisor.