Most SMMEs do not operate alone.
A payroll provider may process employee information. A cloud platform may store customer records. An IT provider may have privileged system access. A recruitment agency may handle candidate information. A marketing platform may process contact details and campaign activity.
Each relationship can create privacy dependencies.
But POPIA does not say that every supplier or third party is automatically an operator.
The correct starting point is therefore not: “Do we have a supplier contract?” It is: “What role does this organisation actually play in relation to the processing?”
First understand the role. Then understand the processing, assess the safeguards, govern the contract and keep evidence that the relationship is being managed.
Start with the broader governance architecture in What Does a POPIA Compliance Framework Actually Require?
Use your processing inventory to identify external parties through ROPA Under POPIA: A Practical Guide for South African Businesses .
Where supplier processing introduces privacy risk, connect the assessment to PIIA Under POPIA: A Practical Privacy Risk Guide for South African SMMEs .
Do not classify the supplier by its job title or contract label. Classify the role by what the supplier actually does with the personal information.
A practical operator-governance framework for SMMEs
What is an operator under POPIA?
POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that responsible party.
POPIA defines a responsible party as a public or private body or other person which, alone or together with others, determines the purpose of and means for processing personal information.
The distinction therefore turns on the actual processing relationship.
A supplier which processes information for your business under a contract or mandate, without coming under your direct authority, may be acting as your operator.
A third party which determines its own purposes and means for particular processing may instead be a responsible party in its own right.
The same organisation can also perform different privacy roles for different processing activities. The role should therefore be assessed in relation to the specific processing, rather than assigned once to the supplier for every purpose.
Map the processing before you assess the contract
Supplier governance becomes difficult when the organisation begins with a list of legal entities rather than a picture of the information flow.
Your processing inventory or ROPA should make relevant external processing visible.
For each material supplier relationship involving personal information, establish the facts first.
What do sections 20 and 21 actually require?
Once the supplier is acting as an operator, sections 20 and 21 become central.
An operator, or anyone processing personal information on behalf of a responsible party or operator, must process the information only with the knowledge or authorisation of the responsible party.
Personal information coming to their knowledge must also be treated as confidential and must not be disclosed unless required by law or in the proper performance of their duties.
The responsible party must, through a written contract with the operator, ensure that the operator establishes and maintains the security measures referred to in section 19.
Section 21 also creates the operator's immediate security-compromise notification obligation to the responsible party.
What must a POPIA operator contract contain?
POPIA's express section 21(1) requirement is precise.
There must be a written contract between the responsible party and the operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19.
POPIA does not prescribe a document title, standard template or a document that must be called a “Data Processing Agreement”.
The required written provisions can therefore form part of an appropriate broader agreement or addendum, provided that the statutory requirement is properly addressed.
Section 21(1) expressly requires the written contract to ensure that the operator establishes and maintains the section 19 security measures. POPIA does not prescribe the longer processor-clause list found in some other privacy regimes.
A well-designed operator agreement will nevertheless often address additional operational matters so that sections 20, 21 and the wider POPIA framework can be managed in practice.
A signed contract does not prove that the safeguards are adequate
Section 19 requires the responsible party to take appropriate, reasonable technical and organisational measures to protect the integrity and confidentiality of personal information.
Those measures include identifying reasonably foreseeable internal and external risks, establishing appropriate safeguards, regularly verifying that those safeguards are effectively implemented and updating them in response to new risks or deficiencies.
Where an operator processes information for the business, section 21 connects the operator directly to those section 19 safeguards.
A proportionate supplier-security review can therefore provide practical evidence that the organisation has considered whether the operator can support the safeguards required for the relevant processing.
Ask for evidence that matches the processing risk
What happens when the security compromise occurs at the operator?
This is one area where the statutory roles are particularly clear.
Under section 21(2), the operator must notify the responsible party immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by an unauthorised person.
Section 22 then places the relevant notification responsibilities on the responsible party where the section 22 requirements are met.
What if the operator processes information outside South Africa?
Cloud and outsourced services frequently introduce an international element.
Information may be hosted outside South Africa, supported by overseas teams or passed to another service provider in another country.
Those facts should be mapped so that the organisation can determine whether the arrangement involves a transfer of personal information to a third party in a foreign country within the scope of section 72.
Section 72(1) provides that a responsible party in South Africa may not transfer personal information about a data subject to a third party in a foreign country unless one of the statutory bases in that section applies.
If the organisation relies on section 72(1)(a), the required adequate protection also includes substantially similar provisions relating to further transfers from the recipient to third parties in foreign countries. Supplier mapping should therefore look beyond the first contracting entity where onward transfers are relevant.
Operator governance should continue after the contract is signed
Supplier governance is often strongest during procurement and weakest afterwards.
The contract is signed, the platform goes live and the privacy assessment is filed. Meanwhile, the service changes.
New functionality appears. Hosting locations change. Different support teams obtain access. Additional service providers are introduced. Processing volumes increase.
A practical operator-governance process should therefore cover the relationship from onboarding through termination.
Your SMME appoints a cloud payroll provider
Assume the business appoints an external payroll platform to process employee information, salary data, deductions, banking information and related payroll records.
Where that provider processes the information for the employer under the service contract, it may be acting as an operator for that processing.
The practical assessment should then move through several questions.
The objective is not to create procurement paperwork. It is to make the external processing visible and govern the risks that matter.
Can you answer these ten questions?
POPIA operators and third parties: practical questions
What is an operator under POPIA?
An operator is a person who processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that responsible party.
Is every supplier an operator?
No. The role depends on what the supplier actually does with the personal information. A supplier processing information on behalf of the responsible party may be an operator. A party determining its own purpose and means for particular processing may be a responsible party in its own right.
Does POPIA require an operator agreement?
Section 21(1) requires a written contract between the responsible party and operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19.
Does the agreement have to be called a Data Processing Agreement?
No. POPIA does not prescribe that title. The important issue is whether an appropriate written contract exists and gives effect to the statutory requirements.
Does POPIA prescribe a supplier due-diligence questionnaire?
No. A supplier or operator assessment is a practical governance method for evaluating the processing and relevant safeguards. Its depth can be proportionate to the particular processing and risk.
Who reports a security compromise if it happens at the operator?
Section 21(2) requires the operator to notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. The responsible party then carries the applicable section 22 notification responsibilities.
Can an operator be located outside South Africa?
POPIA's operator definition is not limited to South African providers. Where the arrangement involves a transfer of personal information from a responsible party in South Africa to a third party in a foreign country, the applicable requirements of section 72 must be assessed.
Does POPIA use the term sub-operator?
POPIA does not define a role called a sub-operator. Businesses may use the term as practical shorthand for other providers in the processing chain, but the relevant parties, processing and transfers still need to be assessed under POPIA.
Know who processes your information — and why
Third-party privacy governance does not need to become an enterprise procurement programme for a smaller business.
It does need enough structure to identify the suppliers that matter, understand their processing role, put the appropriate contractual safeguards in place, manage security and international processing, and respond when the relationship changes.
For an SMME, the objective is not to assess every stationery supplier as if it were a payroll platform.
It is to focus governance effort where external parties actually create privacy dependencies.
Do not just keep a supplier list. Understand the processing relationship behind it.
Identify the relationship. Assess the risk. Govern the processing.
The Provara Group POPIA Compliance Programme gives South African SMMEs a structured implementation pathway for processing records, operator identification, third-party assessments, contractual controls, cross-border review, security governance, remediation and retained compliance evidence.
This guide has been reviewed for alignment, as at 4 September 2026, with the Protection of Personal Information Act 4 of 2013, including the definitions in section 1; the accountability requirement in section 8; the security safeguards in sections 19 to 22; Chapter 9 and section 72 relating to transfers of personal information outside the Republic; and, where relevant, the prior-authorisation provisions in sections 57 and 58.
POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that party. A responsible party is a public or private body or other person which, alone or together with others, determines the purpose of and means for processing personal information. Supplier roles should therefore be assessed against the actual processing relationship.
Section 20 requires an operator, or anyone processing personal information on behalf of a responsible party or operator, to process the information only with the knowledge or authorisation of the responsible party and to treat personal information coming to their knowledge as confidential, subject to the statutory qualifications.
Section 21(1) requires a written contract between the responsible party and operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19. POPIA does not prescribe a separate document called a Data Processing Agreement, a statutory operator-contract template or the extended practical clause list described in this guide.
Section 21(2) requires an operator to notify the responsible party immediately where there are reasonable grounds to believe that personal information of a data subject has been accessed or acquired by an unauthorised person. Section 22 places the applicable regulatory and data-subject notification duties on the responsible party. Current Information Regulator guidance states that POPIA does not provide a low-risk reporting threshold for security compromises.
Section 72 applies where a responsible party in the Republic transfers personal information about a data subject to a third party in a foreign country. The existence of offshore hosting, foreign support or access should therefore be mapped so that the organisation can determine whether and how section 72 applies to the particular arrangement.
Where special personal information referred to in section 26 or personal information of children referred to in section 34 is transferred to a third party in a foreign country that does not provide an adequate level of protection as referred to in section 72, the prior-authorisation provisions in section 57(1)(d) should also be assessed, together with the other applicable provisions of sections 57 and 58.
References in this guide to operator registers, supplier-risk tiers, due-diligence questionnaires, review cycles, assurance evidence, audit mechanisms, onward-provider controls and exit checklists describe practical governance approaches. They are not presented as statutory document names, prescribed assessment formats or mandatory POPIA clauses unless expressly identified as such.
POPIA does not define a statutory role called a “sub-operator”. Where that terminology is used operationally, the organisation should still assess the actual parties, processing, contractual arrangements and applicable international transfers.
Depending on the organisation, supplier and processing activity, additional requirements may arise from special-personal-information or children's-information provisions, applicable codes of conduct, sector-specific legislation, the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026, regulatory authorisations, contractual obligations or other laws.
Important: This article provides general compliance information and practical governance guidance. It is not legal advice, does not constitute a legal opinion and does not guarantee compliance. POPIA compliance depends on the organisation's actual processing activities, supplier relationships, applicable authorisations, transfer arrangements, operating environment, controls, sector requirements and implementation.