Handling POPIA Data Subject Requests | Access, Correction, Deletion | WebFootprint
CRM Integrations POPIA → Data Subject Requests

Handling POPIA Data Subject Requests: Access, Correction, and Deletion on a Tracked SLA

Every data subject access request that lands as an email scramble is a POPIA timeline risk and a staff-hour sink. Identity checks stall, records hide across CRM and email, and the 30-day clock keeps running.

We build the workflow that turns panic into a tracked SLA.

A glass CRM panel and a copper-gold DSAR POPIA Request Handling seal linked by a ribbon of access, correction, and deletion documents in a deep teal night scene
~R25,200
average labour cost per manually fulfilled access or deletion request
18–25 hrs
typical staff time per manual data subject request end to end
30 days
PAIA-aligned response window South African firms use for POPIA access requests
1,355
POPIA complaints received by the Information Regulator in 2024/25
The Problem

Sound Familiar?

These are the exact issues our clients faced before a proper request-handling workflow:

  • A data subject access or correction request lands in a shared inbox and nobody owns the 30-day clock
  • Identity is checked ad hoc, so the team either stalls for days or risks disclosing to the wrong person
  • Finding records means hunting CRM contacts, email threads, and shared drives by hand
  • Access, correction, and deletion requests each get a different improvised process
  • When the Information Regulator asks for proof, there is no signed evidence pack, only scattered emails

The April 2025 POPIA Regulation amendments expand request channels to SMS, WhatsApp, and telephone, while the Information Regulator logged 1,355 POPIA complaints in 2024/25 and has already issued R5 million infringement notices. More channels and harder enforcement make an inbox scramble a liability, not a process.

How It Works

What the Data Subject Request Workflow Actually Does

Request arrives → identity verified → records found → signed response pack. No Friday-afternoon scramble across five inboxes.

1

Request Logged

Access, correction, or deletion opens a ticket with a live 30-day SLA clock

2

Identity Verified

Proof of identity checked before any disclosure or change runs

3

Records Discovered

CRM, email, and drives searched together so nothing is missed

4

Evidence Pack Sent

Signed response to the data subject, with an immutable log for the Regulator

What We Build

Everything You Need for Reliable POPIA Request Handling

Multi-Channel Request Intake

Email, web form, WhatsApp, SMS, and Form 2 style submissions open a tracked ticket with request type, identity status, and a live 30-day SLA clock.

Identity Verification Gate

Confirm the requester is the data subject before any disclosure, correction, or deletion. Pause the clock when more proof is needed, then resume with a clear audit trail.

Multi-System Discovery

Locate matching personal information across CRM, email, shared drives, and connected apps from one search, so nothing is missed under deadline pressure.

Access, Correction, Deletion Paths

Each POPIA request type follows a defined path: disclosure pack, field corrections with confirmation, or deletion with lawful retention exceptions recorded.

SLA Alerts for Information Officers

Day-10 and day-20 warnings, overdue flags, and a single queue view so the Information Officer never discovers a missed deadline after the fact.

Signed Evidence Packs

Exportable packs log what was found, what was disclosed or changed, what was retained and why, and when the response went out, ready for the Regulator.

Systems We've Wired into POPIA Request Workflows

HubSpotPipedriveSalesforceZoho CRMEmail / Google WorkspaceShared drivesCustom CRMs
Client Story

From 20 Hours per Request to 2.5

How an 80-person Gauteng services firm stopped treating every POPIA information request like a fire drill and started closing them inside the 30-day window with evidence packs ready.

Before

The Manual Scramble

  • Information Officer forwarded every request into a shared inbox and chased departments by email
  • Identity checks took days because there was no standard proof checklist
  • CRM, Outlook, and Google Drive were searched separately, and records were often missed
  • Access, correction, and deletion each got a different improvised reply
  • No signed pack existed when a complainant threatened to go to the Regulator
20 hrs/request average staff time burned
After

The Tracked Workflow

  • Every request opens a ticket with type, identity status, and a live 30-day SLA clock
  • Identity gate runs before any disclosure, correction, or deletion
  • One discovery pass covers CRM, email, and shared drives
  • Response packs go out signed, with an immutable log of what was found and changed
  • Information Officer sees day-10 and day-20 alerts instead of discovering overdue work late
2.5 hrs/request review and approve
210+ hours saved per year (12 requests)
100% closed inside the 30-day SLA
R252K+ recovered in staff time (year 1)
8 weeks to full ROI
The Difference

Before vs After Integration

Before
After
Time per request
18–25 hours
2–3 hours review
SLA visibility
Buried in email
Live 30-day clock
Identity verification
Ad hoc, inconsistent
Gated checklist
Record discovery
Manual per system
Multi-system search
Regulator evidence
Scattered emails
Signed evidence pack
Labour cost per request
~R25,200
Under R4,000 review
Getting Started

How It Works

From first conversation to a live request-handling workflow in 3–5 weeks.

01

Map Your Request Paths

How access, correction, and deletion requests arrive today, where personal data lives, and who owns the 30-day clock.

02

Free Scoping Call

30-minute call with your CEO or Information Officer to prioritise intake, identity checks, discovery, and evidence packs.

03

Build and Drill

We wire the DSAR workflow across CRM, email, and drives, then run sample access, correction, and deletion drills with your team.

04

Go Live and Prove It

Staff keep the same tools. Every request gets an SLA clock, a discovery trail, and a signed response pack.

Questions

Frequently Asked Questions

What deadlines apply to POPIA data subject requests?

POPIA section 23 requires access within a reasonable time. Most organisations align to PAIA's 30-day decision window, with one possible further 30-day extension for complex searches. Section 24 correction and deletion requests, under the amended Regulations, require written notice of the action taken within 30 days. Missing that clock is how complaints escalate to the Information Regulator.

How is this different from a full POPIA programme or an erasure-only workflow?

A full POPIA programme covers lawful basis, operator agreements, retention, and safeguards. An erasure workflow focuses on forget-me deletions. This engagement is the full data subject request lifecycle: intake for access, correction, and deletion; identity verification; multi-system discovery; SLA tracking; response packs; and evidence ready for the Regulator.

What does a manual POPIA information request actually cost?

Industry benchmarks put manual fulfilment at roughly 18 to 25 hours of staff time per request. Gartner estimates about US$1,524 per access or deletion request, which is around R25,200 at roughly R16.54 to the dollar. At a dozen requests a year, that is well over R300,000 in labour before any Regulator enquiry.

Which systems does discovery cover?

We typically search the CRM first, then cascade into email platforms, shared drives, support tools, and other apps that hold customer personal information. If a vendor has no API, we still design a tracked manual step with a confirmation receipt so nothing falls off the list under the 30-day clock.

Can requests arrive by WhatsApp or SMS under the new regulations?

Yes. The April 2025 POPIA Regulation amendments expand data-subject channels, including SMS, WhatsApp, and telephone (with recordings). Your intake workflow should accept those channels and still open a tracked ticket with identity checks and an SLA clock, not leave them in someone's personal chat history.

How much does a POPIA DSAR handling workflow cost?

A focused intake-to-evidence workflow for access, correction, and deletion on an existing CRM and two or three connected systems typically starts around R45,000. Broader multi-system discovery with Information Officer dashboards and signed evidence packs usually lands between R65,000 and R120,000. Against R25,000-plus per manual request and R10 million POPIA fine exposure, most mid-market teams see payback inside a handful of requests.

Ready to automate?

Stop Treating Every POPIA Request Like a Fire Drill

If your Information Officer is still chasing CRM, email, and shared drives by hand, you are burning staff hours and betting the 30-day clock on inbox luck.

Tell us how access, correction, and deletion requests arrive today, which systems hold personal information, and what happens when the clock runs down. We will show you exactly how a tracked DSAR workflow would work for your firm.

Chat with us