Provara Group · Compliance Insights

Practical privacy guidance. Governance made workable.

POPIA Operators and Third Parties: A Practical Guide for South African SMMEs


Provara Group · Compliance Insights · Last reviewed 4 September 2026

A supplier contract is not the same as operator governance.

South African businesses rely on payroll providers, cloud platforms, recruitment agencies, IT support companies, marketing technology and other external service providers. The POPIA challenge is not simply knowing that a supplier exists. It is understanding the supplier's privacy role, what personal information it processes, what safeguards apply and whether the relationship is governed appropriately.

s1
Role classification
ss20–21
Operator duties
s19
Security safeguards
s72
Foreign transfers

Most SMMEs do not operate alone.

A payroll provider may process employee information. A cloud platform may store customer records. An IT provider may have privileged system access. A recruitment agency may handle candidate information. A marketing platform may process contact details and campaign activity.

Each relationship can create privacy dependencies.

But POPIA does not say that every supplier or third party is automatically an operator.

The correct starting point is therefore not: “Do we have a supplier contract?” It is: “What role does this organisation actually play in relation to the processing?”

Operator governance in simple terms

First understand the role. Then understand the processing, assess the safeguards, govern the contract and keep evidence that the relationship is being managed.

Where this fits in the POPIA implementation journey

Start with the broader governance architecture in What Does a POPIA Compliance Framework Actually Require?

Use your processing inventory to identify external parties through ROPA Under POPIA: A Practical Guide for South African Businesses .

Where supplier processing introduces privacy risk, connect the assessment to PIIA Under POPIA: A Practical Privacy Risk Guide for South African SMMEs .

The key principle

Do not classify the supplier by its job title or contract label. Classify the role by what the supplier actually does with the personal information.

01
Role classification

What is an operator under POPIA?

POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that responsible party.

POPIA defines a responsible party as a public or private body or other person which, alone or together with others, determines the purpose of and means for processing personal information.

The distinction therefore turns on the actual processing relationship.

The role test
Who determines why the information is processed? And who determines the means by which that processing is carried out?

A supplier which processes information for your business under a contract or mandate, without coming under your direct authority, may be acting as your operator.

A third party which determines its own purposes and means for particular processing may instead be a responsible party in its own right.

The same organisation can also perform different privacy roles for different processing activities. The role should therefore be assessed in relation to the specific processing, rather than assigned once to the supplier for every purpose.

May be an operator
Processing on your behalf A payroll bureau, hosted software platform or outsourced service provider may act as an operator where it processes personal information for your business under the relevant contract or mandate.
May be responsible party
Processing for its own purposes A service provider may be a responsible party in its own right where it independently determines the purpose and means of the particular processing.
Mixed relationship
Different roles for different purposes A supplier can potentially process some information on your behalf while processing other information for purposes it determines independently.
Do not classify by supplier category alone The fact that an organisation is a cloud provider, accountant, lawyer, recruitment provider or software vendor does not by itself answer the POPIA role question. The actual processing arrangement must be considered.
02
Supplier visibility

Map the processing before you assess the contract

Supplier governance becomes difficult when the organisation begins with a list of legal entities rather than a picture of the information flow.

Your processing inventory or ROPA should make relevant external processing visible.

For each material supplier relationship involving personal information, establish the facts first.

01
Service What service is the supplier actually providing?
02
Information What personal information can the supplier collect, receive, store, access or otherwise process?
03
Data subjects Whose information is involved — employees, applicants, customers, suppliers, visitors or others?
04
Purpose Is the supplier processing for your purposes, its own purposes, or potentially both?
05
Location Where is the information stored, supported and otherwise processed?
06
Other providers Does the supplier involve other service providers in delivering the service?
07
Access Which people or teams can access the information, and for what reason?
Practical governance tool
An operator register can be an efficient way to maintain this visibility. POPIA does not prescribe a document with that title or a statutory operator-register format. It is a practical governance mechanism.
03
Statutory duties

What do sections 20 and 21 actually require?

Once the supplier is acting as an operator, sections 20 and 21 become central.

Section 20
Authorised processing & confidentiality

An operator, or anyone processing personal information on behalf of a responsible party or operator, must process the information only with the knowledge or authorisation of the responsible party.

Personal information coming to their knowledge must also be treated as confidential and must not be disclosed unless required by law or in the proper performance of their duties.

Section 21
Written contract & security

The responsible party must, through a written contract with the operator, ensure that the operator establishes and maintains the security measures referred to in section 19.

Section 21 also creates the operator's immediate security-compromise notification obligation to the responsible party.

Accountability does not disappear when processing is outsourced
Section 8 requires the responsible party to ensure that POPIA's lawful-processing conditions and the measures giving effect to them are complied with when the purpose and means of processing are determined and during the processing itself. Outsourcing an activity therefore does not remove the responsible party's governance responsibility for the processing.
04
Contract governance

What must a POPIA operator contract contain?

POPIA's express section 21(1) requirement is precise.

There must be a written contract between the responsible party and the operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19.

POPIA does not prescribe a document title, standard template or a document that must be called a “Data Processing Agreement”.

The required written provisions can therefore form part of an appropriate broader agreement or addendum, provided that the statutory requirement is properly addressed.

Statutory minimum vs practical contract design

Section 21(1) expressly requires the written contract to ensure that the operator establishes and maintains the section 19 security measures. POPIA does not prescribe the longer processor-clause list found in some other privacy regimes.

A well-designed operator agreement will nevertheless often address additional operational matters so that sections 20, 21 and the wider POPIA framework can be managed in practice.

Scope & purpose Describe the processing the operator is expected to perform and the relevant service.
Authorised processing Define how the operator is authorised to process the information and how changes are controlled.
Confidentiality Reinforce the confidentiality requirement arising from section 20.
Security safeguards Address the appropriate technical and organisational measures required for the processing.
Incident escalation Give effect to the operator's immediate section 21(2) notification obligation.
Other providers Establish visibility and contractual controls around relevant onward service providers.
International processing Address foreign processing and transfer requirements where they arise.
End of service Establish appropriate arrangements for return, deletion, destruction or lawful continued retention.
Assurance Define proportionate information, review or assurance mechanisms where appropriate.
Legal precision The additional clauses listed above are practical contract-governance measures. They should not be represented as a statutory prescribed clause list under POPIA. Section 21(1)'s express written-contract requirement relates to ensuring that the operator establishes and maintains the section 19 security measures.
05
Security assurance

A signed contract does not prove that the safeguards are adequate

Section 19 requires the responsible party to take appropriate, reasonable technical and organisational measures to protect the integrity and confidentiality of personal information.

Those measures include identifying reasonably foreseeable internal and external risks, establishing appropriate safeguards, regularly verifying that those safeguards are effectively implemented and updating them in response to new risks or deficiencies.

Where an operator processes information for the business, section 21 connects the operator directly to those section 19 safeguards.

A proportionate supplier-security review can therefore provide practical evidence that the organisation has considered whether the operator can support the safeguards required for the relevant processing.

Proportionate supplier review

Ask for evidence that matches the processing risk

□  What information will the operator process?
□  What access controls protect it?
□  How is information protected during storage and transmission where appropriate?
□  How are privileged users and support access controlled?
□  What security monitoring and incident-detection capability exists?
□  How are vulnerabilities, patching and material security weaknesses managed?
□  What backup, recovery and resilience arrangements apply?
□  Where is the information processed and supported?
□  Which other providers are materially involved?
□  What independent assurance or certifications are available, where relevant?
Keep it proportionate
POPIA does not prescribe a document called a “vendor due-diligence assessment”. The depth of supplier review can be proportionate to the information, processing, access and potential risk involved.
Certification is evidence — not the entire assessment A recognised certification or assurance report can provide useful evidence about a provider's controls. It should not automatically be treated as proof that every aspect of the specific POPIA processing arrangement is compliant.
06
Incident escalation

What happens when the security compromise occurs at the operator?

This is one area where the statutory roles are particularly clear.

Under section 21(2), the operator must notify the responsible party immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by an unauthorised person.

Section 22 then places the relevant notification responsibilities on the responsible party where the section 22 requirements are met.

01
Operator discovers Reasonable grounds exist to believe unauthorised access or acquisition occurred.
02
Notify immediately The operator immediately notifies the responsible party under section 21(2).
03
Responsible party acts Containment, assessment and required section 22 notification are managed by the responsible party.
04
Evidence & remediation The parties cooperate to establish scope, remediate weaknesses and retain the necessary record.
Current Regulator position
The Information Regulator's current security-compromise fact sheet states that POPIA does not provide a low-risk threshold for reporting security compromises. Where the statutory security-compromise requirements apply, the responsible party should not rely on an internal “low risk” rating as a reason not to notify.
Contract design matters here Do not give an operator a contractual incident-notification period that undermines section 21(2)'s requirement to notify the responsible party immediately. An effective process can provide for immediate initial escalation followed by updated information as the investigation develops.
07
International processing

What if the operator processes information outside South Africa?

Cloud and outsourced services frequently introduce an international element.

Information may be hosted outside South Africa, supported by overseas teams or passed to another service provider in another country.

Those facts should be mapped so that the organisation can determine whether the arrangement involves a transfer of personal information to a third party in a foreign country within the scope of section 72.

Section 72(1) provides that a responsible party in South Africa may not transfer personal information about a data subject to a third party in a foreign country unless one of the statutory bases in that section applies.

01
Adequate protection The recipient is subject to a law, binding corporate rules or binding agreement providing the level of protection contemplated in section 72(1)(a), including substantially similar further-transfer protection.
02
Consent The data subject consents to the transfer.
03
Data-subject contract The transfer is necessary for performance of a contract between the data subject and responsible party, or for pre-contractual measures taken in response to the data subject's request.
04
Contract in the data subject's interest The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the responsible party and a third party.
05
Benefit of the data subject The transfer benefits the data subject, it is not reasonably practicable to obtain consent, and the data subject would likely consent if obtaining consent were reasonably practicable.
Onward processing matters

If the organisation relies on section 72(1)(a), the required adequate protection also includes substantially similar provisions relating to further transfers from the recipient to third parties in foreign countries. Supplier mapping should therefore look beyond the first contracting entity where onward transfers are relevant.

Do not overlook prior authorisation
Section 57(1)(d) must also be considered where special personal information or children's personal information is transferred to a third party in a foreign country that does not provide an adequate level of protection as referred to in section 72. Where the statutory conditions are met and no applicable section 57(3) qualification applies, the prior-authorisation regime must be addressed before the relevant processing proceeds.
“Sub-operator” is practical terminology POPIA does not define a statutory role called a “sub-operator”. Organisations may use that term operationally for another provider engaged in the processing chain, but the actual parties and transfers should still be analysed under POPIA's applicable definitions and requirements.
08
Ongoing governance

Operator governance should continue after the contract is signed

Supplier governance is often strongest during procurement and weakest afterwards.

The contract is signed, the platform goes live and the privacy assessment is filed. Meanwhile, the service changes.

New functionality appears. Hosting locations change. Different support teams obtain access. Additional service providers are introduced. Processing volumes increase.

A practical operator-governance process should therefore cover the relationship from onboarding through termination.

01
Identify Determine whether personal information will be involved.
02
Classify Determine the supplier's role for the relevant processing.
03
Assess Review privacy and security considerations proportionate to the processing.
04
Contract Put the required written arrangements and practical controls in place.
05
Monitor Reassess material changes and outstanding remediation.
06
Exit Address access, information return, deletion, destruction and any lawful continuing retention.
The SMME approach
You do not need the same review process for every supplier. A provider with no access to personal information does not warrant the same privacy scrutiny as a payroll platform containing your entire employee population. Prioritise according to the processing and risk.
Practical example

Your SMME appoints a cloud payroll provider

Assume the business appoints an external payroll platform to process employee information, salary data, deductions, banking information and related payroll records.

Where that provider processes the information for the employer under the service contract, it may be acting as an operator for that processing.

The practical assessment should then move through several questions.

Role Is the provider processing payroll information for the employer, or does it have any separate purposes of its own?
Information What employee and payroll information can the provider process?
Contract Does the written contract properly address the section 19 security safeguards?
Security Are the safeguards proportionate to the sensitivity and volume of payroll information?
Location Where is the payroll information hosted, supported and otherwise processed?
Other providers Does the payroll provider rely on additional cloud, support or infrastructure providers?
Incident Can the provider immediately escalate unauthorised access or acquisition of employee information?
Exit What happens to the information and access rights when the service ends?

The objective is not to create procurement paperwork. It is to make the external processing visible and govern the risks that matter.

Operator governance health check

Can you answer these ten questions?

01
Do we know which suppliers process personal information?
02
Have we classified their privacy role for the relevant processing?
03
Do we know what personal information each material operator processes?
04
Is the required written contract in place?
05
Have we considered whether the security safeguards are appropriate?
06
Can the operator immediately escalate a security compromise?
07
Do we know where the information is processed?
08
Have applicable section 72 transfers been assessed?
09
Do we know when a material supplier change requires reassessment?
10
Do we have evidence that material gaps have been remediated?
Frequently asked questions

POPIA operators and third parties: practical questions

What is an operator under POPIA?

An operator is a person who processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that responsible party.

Is every supplier an operator?

No. The role depends on what the supplier actually does with the personal information. A supplier processing information on behalf of the responsible party may be an operator. A party determining its own purpose and means for particular processing may be a responsible party in its own right.

Does POPIA require an operator agreement?

Section 21(1) requires a written contract between the responsible party and operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19.

Does the agreement have to be called a Data Processing Agreement?

No. POPIA does not prescribe that title. The important issue is whether an appropriate written contract exists and gives effect to the statutory requirements.

Does POPIA prescribe a supplier due-diligence questionnaire?

No. A supplier or operator assessment is a practical governance method for evaluating the processing and relevant safeguards. Its depth can be proportionate to the particular processing and risk.

Who reports a security compromise if it happens at the operator?

Section 21(2) requires the operator to notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. The responsible party then carries the applicable section 22 notification responsibilities.

Can an operator be located outside South Africa?

POPIA's operator definition is not limited to South African providers. Where the arrangement involves a transfer of personal information from a responsible party in South Africa to a third party in a foreign country, the applicable requirements of section 72 must be assessed.

Does POPIA use the term sub-operator?

POPIA does not define a role called a sub-operator. Businesses may use the term as practical shorthand for other providers in the processing chain, but the relevant parties, processing and transfers still need to be assessed under POPIA.

From supplier list to governance

Know who processes your information — and why

Third-party privacy governance does not need to become an enterprise procurement programme for a smaller business.

It does need enough structure to identify the suppliers that matter, understand their processing role, put the appropriate contractual safeguards in place, manage security and international processing, and respond when the relationship changes.

For an SMME, the objective is not to assess every stationery supplier as if it were a payroll platform.

It is to focus governance effort where external parties actually create privacy dependencies.

Do not just keep a supplier list. Understand the processing relationship behind it.

Need a structured way to govern operators?

Identify the relationship. Assess the risk. Govern the processing.

The Provara Group POPIA Compliance Programme gives South African SMMEs a structured implementation pathway for processing records, operator identification, third-party assessments, contractual controls, cross-border review, security governance, remediation and retained compliance evidence.

Regulatory basis

This guide has been reviewed for alignment, as at 4 September 2026, with the Protection of Personal Information Act 4 of 2013, including the definitions in section 1; the accountability requirement in section 8; the security safeguards in sections 19 to 22; Chapter 9 and section 72 relating to transfers of personal information outside the Republic; and, where relevant, the prior-authorisation provisions in sections 57 and 58.

POPIA defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate without coming under the direct authority of that party. A responsible party is a public or private body or other person which, alone or together with others, determines the purpose of and means for processing personal information. Supplier roles should therefore be assessed against the actual processing relationship.

Section 20 requires an operator, or anyone processing personal information on behalf of a responsible party or operator, to process the information only with the knowledge or authorisation of the responsible party and to treat personal information coming to their knowledge as confidential, subject to the statutory qualifications.

Section 21(1) requires a written contract between the responsible party and operator through which the responsible party ensures that the operator establishes and maintains the security measures referred to in section 19. POPIA does not prescribe a separate document called a Data Processing Agreement, a statutory operator-contract template or the extended practical clause list described in this guide.

Section 21(2) requires an operator to notify the responsible party immediately where there are reasonable grounds to believe that personal information of a data subject has been accessed or acquired by an unauthorised person. Section 22 places the applicable regulatory and data-subject notification duties on the responsible party. Current Information Regulator guidance states that POPIA does not provide a low-risk reporting threshold for security compromises.

Section 72 applies where a responsible party in the Republic transfers personal information about a data subject to a third party in a foreign country. The existence of offshore hosting, foreign support or access should therefore be mapped so that the organisation can determine whether and how section 72 applies to the particular arrangement.

Where special personal information referred to in section 26 or personal information of children referred to in section 34 is transferred to a third party in a foreign country that does not provide an adequate level of protection as referred to in section 72, the prior-authorisation provisions in section 57(1)(d) should also be assessed, together with the other applicable provisions of sections 57 and 58.

References in this guide to operator registers, supplier-risk tiers, due-diligence questionnaires, review cycles, assurance evidence, audit mechanisms, onward-provider controls and exit checklists describe practical governance approaches. They are not presented as statutory document names, prescribed assessment formats or mandatory POPIA clauses unless expressly identified as such.

POPIA does not define a statutory role called a “sub-operator”. Where that terminology is used operationally, the organisation should still assess the actual parties, processing, contractual arrangements and applicable international transfers.

Depending on the organisation, supplier and processing activity, additional requirements may arise from special-personal-information or children's-information provisions, applicable codes of conduct, sector-specific legislation, the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026, regulatory authorisations, contractual obligations or other laws.

Important: This article provides general compliance information and practical governance guidance. It is not legal advice, does not constitute a legal opinion and does not guarantee compliance. POPIA compliance depends on the organisation's actual processing activities, supplier relationships, applicable authorisations, transfer arrangements, operating environment, controls, sector requirements and implementation.