Records & POPIA
Special Personal Information
Health, biometric and criminal data are prohibited from processing under POPIA unless a Section 27-33 authorisation applies.
Why special personal information attracts a higher bar
Sections 26 to 33 of POPIA prohibit the processing of special personal information — health, biometric, religious, criminal and similar categories — unless a specific authorisation applies, reflecting the heightened harm that misuse of such data can cause. Public-sector entities routinely hold exactly this data: employee health records, biometric access data, criminal-record checks for SCM and HR. AuditPro Core maps where special categories are processed and confirms the authorising ground and the controls around them, so the entity can demonstrate it meets the stricter regime rather than treating sensitive data as ordinary personal information.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Special-info stores
18
With authorisation
13
of 18
Over-broad access
6
Biometric systems
4
Special-info stores by category
Stores with authorisation gaps
| Store | Category | Authorisation |
|---|---|---|
| Clinic records | Health | Implied only |
| Biometric access | Biometric | None |
| Vetting files | Criminal | Expired |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The general prohibition
Section 26 starts from a prohibition: special personal information may not be processed at all unless an exception in Sections 27 to 33 specifically permits it. The default is no, not yes.
Category-specific grounds
Each category — health, biometric, criminal record — has its own authorising conditions. Consent, legal obligation and the specific carve-outs differ by category and must be matched correctly.
Heightened security expectation
Because misuse causes greater harm, the technical and organisational safeguards around special information should exceed those for ordinary data — tighter access, stronger encryption, closer logging.
Minimisation and retention
Special information should be collected only where genuinely necessary and disposed of as soon as the purpose ends. Holding criminal-check or biometric data longer than needed is itself a compliance failure.
How AuditPro Core Bridges the Gap
- Special-data mapping: the platform locates where special categories are processed across HR, SCM and access systems.
- Authorisation recording: the Section 27-33 ground relied upon is captured per processing activity, exposing any without a basis.
- Elevated-control tracking: access, encryption and logging status for special-data stores are monitored against a higher baseline.
- Retention exception workflow: special information held beyond its purpose is flagged for disposal review.
Key Takeaways
- Processing special information starts from prohibition — you need a specific authorisation.
- Authorising grounds differ by category; match each correctly.
- Apply stronger safeguards to special data than to ordinary personal information.
- Dispose of special data as soon as its purpose ends — over-retention is a failure.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
