Questions to ask about POPIA before handing over customer data
Ask your data-capture provider these POPIA questions before handing over customer records. Learn what good answers sound like and spot compliance gaps.
If you're about to hand customer data to a virtual assistant or data-capture provider, POPIA compliance isn't optional—it's your legal responsibility, and theirs. The difference between a provider who treats it seriously and one who skips it shows up in how they answer your questions. Here's what to ask and why.
"How do you handle personal information once the job is done?"
This question cuts straight to whether they understand data minimisation and secure disposal. A solid answer acknowledges that they'll delete or return data once the work is complete—and explains how they'll verify that's happened. They should mention secure deletion tools or procedures, not just "we'll throw away the USB drive." If they sound vague about what happens to your customer records after invoicing, that's a red flag. Some providers assume you're comfortable with them keeping copies "just in case." Push back. A good provider will give you a signed confirmation of deletion and explain their retention policy upfront.
Why it matters: POPIA requires that personal information be deleted or destroyed when it's no longer needed. If your provider holds onto customer data indefinitely, you're the one exposed to liability if there's a breach later.
"What's your security setup, and can you share a summary in writing?"
Don't accept "We're secure" as an answer. Ask specifically: Do they use encrypted cloud storage or password-protected devices? Are access logs maintained? What's their password policy? Can they show you a basic security document—even a one-pager—that outlines their practices? A professional provider will have thought this through and be willing to document it. If they resist or say "that's confidential," walk away.
A good response sounds like: "We use encrypted end-to-end storage, access is logged, two-factor authentication is mandatory, and devices are encrypted. I can email you our data security summary." An evasive one sounds like: "We keep everything safe" or "We use standard security measures" with no detail.
Why it matters: POPIA requires appropriate technical and organisational measures to protect personal data. Vague promises don't satisfy that. You need to know enough to defend your choice if a breach happens—and providers who take it seriously are happy to explain.
"Who at your end can access the data, and how is that controlled?"
This reveals whether they've thought about limiting exposure. A tight answer: "Only the team member assigned to your project has access, and they're trained on POPIA requirements." Loose answer: "Our whole office can see it if needed" or "I'll share it with my team to speed things up." The first shows containment; the second shows negligence. Ask if there's a data processing agreement or contract that spells out access restrictions. Reputable providers offer one without being asked.
Why it matters: The fewer people touching your customer data, the lower the breach risk. POPIA assumes you've vetted who can see what.
"What's your process if there's a data breach?"
They should have a breach response plan, even if it's simple: notify you immediately, identify what was exposed, and report to the Information Regulator if required. If they've never thought about it—"We've never had a breach, so no plan"—that's confidence born of luck, not preparation. A confident provider acknowledges the possibility and has steps ready.
Why it matters: Breaches happen. Your provider's response speed and transparency can mean the difference between damage control and legal headache.
These aren't hostile questions; they're routine in any professional data-handling relationship. A provider who answers them clearly and offers documentation is signalling respect for POPIA and for your customers. One who dodges or dismisses them is telling you they don't take compliance seriously. Use these answers to filter candidates before you commit to handing over anything sensitive. On Strove, verified data-capture and virtual assistance providers can show you their approach in their profiles and respond to these specifics during your vetting conversations.
Common questions
- Do I need a written data processing agreement with a virtual assistant or data-capture provider?
- Yes. POPIA expects you to have a formal agreement in place that outlines how the provider will handle personal data, security measures, access restrictions, and deletion procedures. Ask for one; reputable providers have a template ready. Even a simple signed contract showing the terms is better than nothing.
- What happens if my provider has a data breach and doesn't tell me?
- You're liable. POPIA requires you to notify affected individuals and the Information Regulator within a reasonable time. If your provider breaches data and hides it, you're the one facing complaints and potential sanctions. Always include a clause in your contract requiring immediate breach notification.
- Can I ask my provider to sign a confidentiality agreement about POPIA requirements?
- Absolutely. A non-disclosure agreement is separate from a data processing agreement and protects your business interests. Professional providers expect both and won't object to signing them.
- How long can a provider keep customer data after the job is done?
- No longer than necessary for the work. Agree upfront on a specific deletion timeline—often within 30 days of invoice. Get written confirmation once it's deleted. Keeping data "just in case" or for your own records beyond the agreed period violates POPIA.
Find a verified provider on Strove
Compare vetted data capturing providers, check their credentials, and book or request a quote — all in one place.
Find a Business