Records & POPIA
Consent Management
Validity and currency of data-subject consents underpinning processing of personal information.
Consent is only a lawful basis while it remains valid and current
Where processing of personal information relies on consent, POPIA requires that consent be voluntary, specific, informed and capable of withdrawal, and stale or improperly obtained consent collapses the lawful basis for the entire processing activity. Many entities treat consent as a once-off tick rather than a living record. AuditPro Core tracks the validity and currency of data-subject consents so that lapsed, withdrawn or undocumented consents are flagged before they expose the entity to a POPIA complaint.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Active consents
412 000
Expired or withdrawn
37 800
still processed
No consent on record
8 410
Withdrawal requests (mo)
612
Consent withdrawals per month
Processing without valid consent
| Service | Purpose | Subjects | Status |
|---|---|---|---|
| SMS billing alerts | Marketing | 21400 | Consent expired |
| Newsletter | Communication | 9800 | No record |
| Survey panel | Research | 6600 | Withdrawn |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
What makes consent valid
POPIA consent must be a voluntary, specific and informed expression of will. Bundled, pre-ticked or coerced consent fails the test and provides no lawful basis even though a record exists.
Consent is purpose-bound
Consent obtained for one purpose does not authorise processing for another. Where the purpose changes or expands, fresh consent is required, so the scope of each consent must be tracked alongside its existence.
The right to withdraw
A data subject may withdraw consent at any time, and processing must stop accordingly. A consent register that does not capture and act on withdrawals is not a true control.
Currency and re-consent
Consents age, and contact details and circumstances change. Periodic re-consent or refresh keeps the basis current and demonstrates the accountability POPIA expects.
How AuditPro Core Bridges the Gap
- Consent register: each data-subject consent is recorded with its scope, purpose and date.
- Validity testing: consents are checked for specificity, currency and the absence of withdrawal.
- Exception workflow: lapsed, withdrawn or scope-mismatched consents are flagged to halt or re-base the processing.
- Traceability to source: each processing activity links to the consent that authorises it for audit review.
Key Takeaways
- POPIA consent must be voluntary, specific, informed and withdrawable to be valid.
- Consent is purpose-bound; a new purpose needs fresh consent.
- Capture and act on withdrawals, or the consent register is not a real control.
- Refresh consents periodically to keep the lawful basis current.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
