Back to Explore
๐Ÿ“œ

Records & POPIA

POPIA Operator Agreements

POPIA Section 21 requires a written contract with every operator processing personal information on your behalf โ€” coverage gaps transfer the risk back to you.

๐Ÿ“– 6 min read๐ŸŽฏ Intermediateโœ๏ธ Updated 2026

Why a written operator contract is non-negotiable under POPIA

Where a third party processes personal information on the entity's behalf โ€” a payroll bureau, a hosting provider, an outsourced call centre โ€” Section 21 of POPIA requires a written contract obliging that operator to establish and maintain Section 19 security measures and to process only on instruction. A missing or weak operator agreement leaves the responsible party exposed for the operator's failures, and it is one of the simpler compliance gaps for the Information Regulator to identify. AuditPro Core tracks coverage of operator agreements against the population of processors so that no third party handles personal information without a contract that meets the statutory minimum.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Operators identified

64

With written contract

48

of 64

Missing security clauses

11

Coverage

75%

โ–ฒ 9%

Operators by contract status

Operators without compliant contracts

OperatorServiceGap
SMS gatewayCitizen alertsNo contract
Records scannerDigitisationNo security clause
Debt collectorArrearsNo contract

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Who is an operator

An operator processes personal information for the responsible party without owning the purpose โ€” a bureau, host or outsourced function. Identifying every operator is the first step that is most often skipped.

What the contract must contain

Section 21 requires the operator to maintain Section 19 security safeguards, to process only on the responsible party's authority, and to treat the information as confidential. A generic services contract rarely covers all three.

Breach-notification obligations

The contract should require the operator to notify the responsible party immediately on discovering a compromise, so the entity can meet its own Section 22 notification duty in time.

Coverage as the metric

Compliance is measured by the proportion of operators with a compliant agreement in place, not by whether a template exists somewhere. An unsigned or lapsed agreement counts as a gap.

How AuditPro Core Bridges the Gap

  • Operator register: the platform maintains the population of operators processing personal information for the entity.
  • Agreement coverage: each operator is tracked for a signed, current Section 21-compliant contract, exposing gaps and lapses.
  • Clause assurance: agreements are checked for the security, instruction-only and breach-notification commitments POPIA requires.
  • Audit-ready export: the coverage position supports both internal audit and any Information Regulator enquiry.

Key Takeaways

  • Identify every operator first โ€” that is the step most often missed.
  • A generic services contract rarely meets the Section 21 minimum.
  • Require immediate breach notification so you can meet your own Section 22 duty.
  • Measure coverage of signed, current agreements โ€” not the existence of a template.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ€” every figure traceable to source.