← Back to Blog

POPIA Compliance Checklist for Mental Health Practitioners in South Africa

12 September 2026 · Kagiso Ditabo, Founder · 3 min read

If you're a psychologist, counsellor, or social worker in private practice in South Africa, POPIA (the Protection of Personal Information Act) isn't optional reading — it directly governs how you're required to handle every client's session notes, contact details, and health information.

Here's a practical checklist for what POPIA actually requires of your practice, and how to think about each requirement.

1. Know your role: you are the Responsible Party

Under POPIA, whoever determines why and how personal information is processed is the "Responsible Party." In a private practice, that's you — not your notes app, not your billing software. Any tool you use to store client information (like TheraLog) acts as your "Operator," processing data on your instruction and under your responsibility.

This matters practically: you can delegate the technical work of storing data securely, but you can't delegate the legal responsibility for it.

2. Get explicit, documented consent

POPIA sets out several lawful grounds for processing personal information, and consent is only one of them — s32 specifically allows health-care professionals to process health information where necessary for proper treatment, without needing separate consent for that core purpose. What POPIA does require unconditionally is that you notify clients what information you're collecting and why (the s18 notification duty). In practice, most practices handle both at once: clear notification plus documented consent, since it's the simplest way to cover the ground. For a mental health practice, this typically means:

  • A clear intake process that explains what session notes are for and how they're stored
  • Documented consent, not just a verbal agreement
  • A record you can produce if a client asks what you hold on them

3. Use appropriate security safeguards

POPIA requires "appropriate, reasonable technical and organisational measures" to prevent loss, damage, or unauthorised access to personal information. For session notes — some of the most sensitive personal information that exists — this is a high bar.

Concretely, this looks like:

  • Encryption of stored data, not just a password-protected folder
  • A system where even the software provider can't read your clients' notes (true end-to-end encryption, not just "encrypted at rest" on a server the vendor can still decrypt)
  • Audit logs of who accessed what, and when

4. Set — and follow — a data retention policy

POPIA requires that personal information not be kept longer than necessary for the purpose it was collected for, taking into account any other legal retention requirements you're subject to (HPCSA's own record-keeping rules apply here too — see our HPCSA record-keeping guide for the specifics).

A retention policy means deciding, in advance, how long you keep records after a client's file closes, and having a system that actually enforces it rather than just accumulating data indefinitely.

5. Know what happens with third parties

If any part of your workflow touches a third-party service — payment processing, AI transcription, cloud storage — POPIA still holds you responsible for how that data is handled downstream. Know who your sub-processors are and what safeguards they carry.

How TheraLog approaches this

TheraLog was built with these requirements as the starting point, not an afterthought: your session notes are encrypted on your device using AES-256-GCM before they ever leave your browser, with the encryption key derived from your personal PIN using PBKDF2 — a key TheraLog itself never sees or stores. Built-in consent capture, full audit trails, and configurable data retention periods are part of the platform, not a manual process you have to maintain separately.

You can read more about the specific technical safeguards on our security page, or see the Information Regulator's official POPIA guidance for the full legal text.

This article is general information, not legal advice. For guidance specific to your practice, consult the Information Regulator or a legal advisor familiar with POPIA.

Want to see how this works in your own practice? Start a 30-day free trial — no credit card required.

Written by Kagiso Ditabo, Founder of TheraLog. Kagiso Ditabo founded TheraLog to help South African mental health practitioners spend less time on admin and more time with clients.

Start Your 30-Day Free Trial

No credit card required · Cancel any time