POPIA for construction contractors: handling client and claim data

If your business holds client names, addresses, ID numbers, or insurance claim details, POPIA applies to you — regardless of company size. Here's what that means in practice for a contracting business, without the legal jargon.

Most contractors don't think of themselves as handling "personal information" — but a client database with names, contact numbers, site addresses, and (for insurance work) claim numbers and policyholder details is exactly that. Under the Protection of Personal Information Act (POPIA), if you're a "responsible party" processing this data, you have obligations, whether you're a two-person outfit or a fifty-person panel contractor.

This is general information, not legal advice. For your specific obligations, speak to a professional who can assess your business.

What POPIA actually asks of a contractor

Practical checklist

Role-based access in practice

A common failure point isn't malicious — it's that everyone in a small business has access to everything because it's simpler to set up. A site supervisor doesn't need to see a client's full financial and claim history to complete a snag list. Office admin doesn't need labour clock-in GPS data to raise an invoice. Separating access by role isn't bureaucracy for its own sake — it limits how much is exposed if one login is compromised, and it's a core POPIA expectation around minimising unnecessary access.

Data separation for insurance-claim work

Panel contractors handling insurance claims carry an extra layer: claimant data (policyholder details, claim numbers, damage assessments) often needs to be treated more carefully than general marketing or lead data, because it's more sensitive and typically shared with a third party (the insurer). Keeping claim records structurally separate from your general marketing database — rather than one big contact list — makes both your POPIA position and your own admin cleaner.

When to get proper advice

This guide is a starting point, not a compliance sign-off. If you're processing claim data at scale, sharing data with multiple insurers, or unsure about your retention obligations, get advice from an attorney or POPIA specialist. Software can help you enforce access rules and keep records tidy — it can't make a legal determination for you.

How SiteCheck fits

SiteCheck is built POPIA-aware, not POPIA-certified — there's no such thing as a "certified" software product under POPIA, and any vendor claiming that is overselling it. What SiteCheck does provide is role-based access control, so office, site, and management users see only what's relevant to their role, and a single structured record per project or claim rather than data scattered across spreadsheets and personal devices. That's a practical foundation for your own POPIA position — the accountability still sits with your business.

FAQ

Does using SiteCheck make my business POPIA compliant?

No single tool makes a business compliant — compliance depends on your policies, processes, and how your team actually works. SiteCheck's role-based access and structured records support good practice; the accountability remains yours.

Do I need an Information Officer if I'm a small contractor?

Yes — every responsible party processing personal information needs a designated Information Officer, even if that's the business owner wearing that hat alongside everything else.

How long should I keep completed claim records?

This depends on your industry, insurer requirements, and legal advice — there's no single universal number. Have a documented position rather than keeping everything indefinitely by default.

Curious how role-based access works in SiteCheck? Book a demo.