POPIA for construction contractors: handling client and claim data
If your business holds client names, addresses, ID numbers, or insurance claim details, POPIA applies to you — regardless of company size. Here's what that means in practice for a contracting business, without the legal jargon.
Most contractors don't think of themselves as handling "personal information" — but a client database with names, contact numbers, site addresses, and (for insurance work) claim numbers and policyholder details is exactly that. Under the Protection of Personal Information Act (POPIA), if you're a "responsible party" processing this data, you have obligations, whether you're a two-person outfit or a fifty-person panel contractor.
This is general information, not legal advice. For your specific obligations, speak to a professional who can assess your business.
What POPIA actually asks of a contractor
- Purpose limitation — only collect data you need for the job or claim, not "just in case"
- Access control — not everyone in the business needs to see every client's ID number or claim history
- Security safeguards — data should be protected against loss, unauthorised access, and leaks — this includes spreadsheets emailed around and WhatsApp groups, not just "the system"
- Retention limits — personal information shouldn't be kept indefinitely once the job or claim is closed and any legal retention period has passed
- Accountability — you need to be able to show what data you hold, why, and who can access it
Practical checklist
- List where client and claimant data actually lives today — CRM, spreadsheets, WhatsApp, email, paper site files
- Set role-based access so site staff see what they need for the job, not the full client or financial record
- Separate claim/policyholder data from general marketing contact lists — these serve different purposes and shouldn't be mixed
- Have a written retention position — how long you keep completed job and claim records, and why
- Know who your Information Officer is (every responsible party needs one, even if it's the owner)
- Have a basic incident process — what happens if a laptop is stolen or an email with client data goes to the wrong person
- Check what your subcontractors and suppliers do with any client data you share with them
Role-based access in practice
A common failure point isn't malicious — it's that everyone in a small business has access to everything because it's simpler to set up. A site supervisor doesn't need to see a client's full financial and claim history to complete a snag list. Office admin doesn't need labour clock-in GPS data to raise an invoice. Separating access by role isn't bureaucracy for its own sake — it limits how much is exposed if one login is compromised, and it's a core POPIA expectation around minimising unnecessary access.
Data separation for insurance-claim work
Panel contractors handling insurance claims carry an extra layer: claimant data (policyholder details, claim numbers, damage assessments) often needs to be treated more carefully than general marketing or lead data, because it's more sensitive and typically shared with a third party (the insurer). Keeping claim records structurally separate from your general marketing database — rather than one big contact list — makes both your POPIA position and your own admin cleaner.
When to get proper advice
This guide is a starting point, not a compliance sign-off. If you're processing claim data at scale, sharing data with multiple insurers, or unsure about your retention obligations, get advice from an attorney or POPIA specialist. Software can help you enforce access rules and keep records tidy — it can't make a legal determination for you.
How SiteCheck fits
SiteCheck is built POPIA-aware, not POPIA-certified — there's no such thing as a "certified" software product under POPIA, and any vendor claiming that is overselling it. What SiteCheck does provide is role-based access control, so office, site, and management users see only what's relevant to their role, and a single structured record per project or claim rather than data scattered across spreadsheets and personal devices. That's a practical foundation for your own POPIA position — the accountability still sits with your business.
FAQ
Does using SiteCheck make my business POPIA compliant?
No single tool makes a business compliant — compliance depends on your policies, processes, and how your team actually works. SiteCheck's role-based access and structured records support good practice; the accountability remains yours.
Do I need an Information Officer if I'm a small contractor?
Yes — every responsible party processing personal information needs a designated Information Officer, even if that's the business owner wearing that hat alongside everything else.
How long should I keep completed claim records?
This depends on your industry, insurer requirements, and legal advice — there's no single universal number. Have a documented position rather than keeping everything indefinitely by default.
Curious how role-based access works in SiteCheck? Book a demo.