Back to Explore
🔒

Records & POPIA

Consent Management

Validity and currency of data-subject consents underpinning processing of personal information.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Consent is only a lawful basis while it remains valid and current

Where processing of personal information relies on consent, POPIA requires that consent be voluntary, specific, informed and capable of withdrawal, and stale or improperly obtained consent collapses the lawful basis for the entire processing activity. Many entities treat consent as a once-off tick rather than a living record. AuditPro Core tracks the validity and currency of data-subject consents so that lapsed, withdrawn or undocumented consents are flagged before they expose the entity to a POPIA complaint.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Active consents

412 000

Expired or withdrawn

37 800

still processed

No consent on record

8 410

Withdrawal requests (mo)

612

Consent withdrawals per month

Processing without valid consent

ServicePurposeSubjectsStatus
SMS billing alertsMarketing21400Consent expired
NewsletterCommunication9800No record
Survey panelResearch6600Withdrawn

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

What makes consent valid

POPIA consent must be a voluntary, specific and informed expression of will. Bundled, pre-ticked or coerced consent fails the test and provides no lawful basis even though a record exists.

Consent is purpose-bound

Consent obtained for one purpose does not authorise processing for another. Where the purpose changes or expands, fresh consent is required, so the scope of each consent must be tracked alongside its existence.

The right to withdraw

A data subject may withdraw consent at any time, and processing must stop accordingly. A consent register that does not capture and act on withdrawals is not a true control.

Currency and re-consent

Consents age, and contact details and circumstances change. Periodic re-consent or refresh keeps the basis current and demonstrates the accountability POPIA expects.

How AuditPro Core Bridges the Gap

  • Consent register: each data-subject consent is recorded with its scope, purpose and date.
  • Validity testing: consents are checked for specificity, currency and the absence of withdrawal.
  • Exception workflow: lapsed, withdrawn or scope-mismatched consents are flagged to halt or re-base the processing.
  • Traceability to source: each processing activity links to the consent that authorises it for audit review.

Key Takeaways

  • POPIA consent must be voluntary, specific, informed and withdrawable to be valid.
  • Consent is purpose-bound; a new purpose needs fresh consent.
  • Capture and act on withdrawals, or the consent register is not a real control.
  • Refresh consents periodically to keep the lawful basis current.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.