Handling POPIA Data Subject Requests: Access, Correction, and Deletion on a Tracked SLA
Every data subject access request that lands as an email scramble is a POPIA timeline risk and a staff-hour sink. Identity checks stall, records hide across CRM and email, and the 30-day clock keeps running.
We build the workflow that turns panic into a tracked SLA.

Sound Familiar?
These are the exact issues our clients faced before a proper request-handling workflow:
- A data subject access or correction request lands in a shared inbox and nobody owns the 30-day clock
- Identity is checked ad hoc, so the team either stalls for days or risks disclosing to the wrong person
- Finding records means hunting CRM contacts, email threads, and shared drives by hand
- Access, correction, and deletion requests each get a different improvised process
- When the Information Regulator asks for proof, there is no signed evidence pack, only scattered emails
The April 2025 POPIA Regulation amendments expand request channels to SMS, WhatsApp, and telephone, while the Information Regulator logged 1,355 POPIA complaints in 2024/25 and has already issued R5 million infringement notices. More channels and harder enforcement make an inbox scramble a liability, not a process.
What the Data Subject Request Workflow Actually Does
Request arrives → identity verified → records found → signed response pack. No Friday-afternoon scramble across five inboxes.
Request Logged
Access, correction, or deletion opens a ticket with a live 30-day SLA clock
Identity Verified
Proof of identity checked before any disclosure or change runs
Records Discovered
CRM, email, and drives searched together so nothing is missed
Evidence Pack Sent
Signed response to the data subject, with an immutable log for the Regulator
Everything You Need for Reliable POPIA Request Handling
Multi-Channel Request Intake
Email, web form, WhatsApp, SMS, and Form 2 style submissions open a tracked ticket with request type, identity status, and a live 30-day SLA clock.
Identity Verification Gate
Confirm the requester is the data subject before any disclosure, correction, or deletion. Pause the clock when more proof is needed, then resume with a clear audit trail.
Multi-System Discovery
Locate matching personal information across CRM, email, shared drives, and connected apps from one search, so nothing is missed under deadline pressure.
Access, Correction, Deletion Paths
Each POPIA request type follows a defined path: disclosure pack, field corrections with confirmation, or deletion with lawful retention exceptions recorded.
SLA Alerts for Information Officers
Day-10 and day-20 warnings, overdue flags, and a single queue view so the Information Officer never discovers a missed deadline after the fact.
Signed Evidence Packs
Exportable packs log what was found, what was disclosed or changed, what was retained and why, and when the response went out, ready for the Regulator.
Systems We've Wired into POPIA Request Workflows
From 20 Hours per Request to 2.5
How an 80-person Gauteng services firm stopped treating every POPIA information request like a fire drill and started closing them inside the 30-day window with evidence packs ready.
The Manual Scramble
- Information Officer forwarded every request into a shared inbox and chased departments by email
- Identity checks took days because there was no standard proof checklist
- CRM, Outlook, and Google Drive were searched separately, and records were often missed
- Access, correction, and deletion each got a different improvised reply
- No signed pack existed when a complainant threatened to go to the Regulator
The Tracked Workflow
- Every request opens a ticket with type, identity status, and a live 30-day SLA clock
- Identity gate runs before any disclosure, correction, or deletion
- One discovery pass covers CRM, email, and shared drives
- Response packs go out signed, with an immutable log of what was found and changed
- Information Officer sees day-10 and day-20 alerts instead of discovering overdue work late
Before vs After Integration
How It Works
From first conversation to a live request-handling workflow in 3–5 weeks.
Map Your Request Paths
How access, correction, and deletion requests arrive today, where personal data lives, and who owns the 30-day clock.
Free Scoping Call
30-minute call with your CEO or Information Officer to prioritise intake, identity checks, discovery, and evidence packs.
Build and Drill
We wire the DSAR workflow across CRM, email, and drives, then run sample access, correction, and deletion drills with your team.
Go Live and Prove It
Staff keep the same tools. Every request gets an SLA clock, a discovery trail, and a signed response pack.
Frequently Asked Questions
What deadlines apply to POPIA data subject requests?
POPIA section 23 requires access within a reasonable time. Most organisations align to PAIA's 30-day decision window, with one possible further 30-day extension for complex searches. Section 24 correction and deletion requests, under the amended Regulations, require written notice of the action taken within 30 days. Missing that clock is how complaints escalate to the Information Regulator.
How is this different from a full POPIA programme or an erasure-only workflow?
A full POPIA programme covers lawful basis, operator agreements, retention, and safeguards. An erasure workflow focuses on forget-me deletions. This engagement is the full data subject request lifecycle: intake for access, correction, and deletion; identity verification; multi-system discovery; SLA tracking; response packs; and evidence ready for the Regulator.
What does a manual POPIA information request actually cost?
Industry benchmarks put manual fulfilment at roughly 18 to 25 hours of staff time per request. Gartner estimates about US$1,524 per access or deletion request, which is around R25,200 at roughly R16.54 to the dollar. At a dozen requests a year, that is well over R300,000 in labour before any Regulator enquiry.
Which systems does discovery cover?
We typically search the CRM first, then cascade into email platforms, shared drives, support tools, and other apps that hold customer personal information. If a vendor has no API, we still design a tracked manual step with a confirmation receipt so nothing falls off the list under the 30-day clock.
Can requests arrive by WhatsApp or SMS under the new regulations?
Yes. The April 2025 POPIA Regulation amendments expand data-subject channels, including SMS, WhatsApp, and telephone (with recordings). Your intake workflow should accept those channels and still open a tracked ticket with identity checks and an SLA clock, not leave them in someone's personal chat history.
How much does a POPIA DSAR handling workflow cost?
A focused intake-to-evidence workflow for access, correction, and deletion on an existing CRM and two or three connected systems typically starts around R45,000. Broader multi-system discovery with Information Officer dashboards and signed evidence packs usually lands between R65,000 and R120,000. Against R25,000-plus per manual request and R10 million POPIA fine exposure, most mid-market teams see payback inside a handful of requests.
Stop Treating Every POPIA Request Like a Fire Drill
If your Information Officer is still chasing CRM, email, and shared drives by hand, you are burning staff hours and betting the 30-day clock on inbox luck.
Tell us how access, correction, and deletion requests arrive today, which systems hold personal information, and what happens when the clock runs down. We will show you exactly how a tracked DSAR workflow would work for your firm.