If you're a psychologist, counsellor, or social worker in private practice in South Africa, POPIA (the Protection of Personal Information Act) isn't optional reading — it directly governs how you're required to handle every client's session notes, contact details, and health information.
Here's a practical checklist for what POPIA actually requires of your practice, and how to think about each requirement.
1. Know your role: you are the Responsible Party
Under POPIA, whoever determines why and how personal information is processed is the "Responsible Party." In a private practice, that's you — not your notes app, not your billing software. Any tool you use to store client information (like TheraLog) acts as your "Operator," processing data on your instruction and under your responsibility.
This matters practically: you can delegate the technical work of storing data securely, but you can't delegate the legal responsibility for it.
2. Get explicit, documented consent
POPIA sets out several lawful grounds for processing personal information, and consent is only one of them — s32 specifically allows health-care professionals to process health information where necessary for proper treatment, without needing separate consent for that core purpose. What POPIA does require unconditionally is that you notify clients what information you're collecting and why (the s18 notification duty). In practice, most practices handle both at once: clear notification plus documented consent, since it's the simplest way to cover the ground. For a mental health practice, this typically means:
- A clear intake process that explains what session notes are for and how they're stored
- Documented consent, not just a verbal agreement
- A record you can produce if a client asks what you hold on them
3. Use appropriate security safeguards
POPIA requires "appropriate, reasonable technical and organisational measures" to prevent loss, damage, or unauthorised access to personal information. For session notes — some of the most sensitive personal information that exists — this is a high bar.
Concretely, this looks like:
- Encryption of stored data, not just a password-protected folder
- A system where even the software provider can't read your clients' notes (true end-to-end encryption, not just "encrypted at rest" on a server the vendor can still decrypt)
- Audit logs of who accessed what, and when
4. Set — and follow — a data retention policy
POPIA requires that personal information not be kept longer than necessary for the purpose it was collected for, taking into account any other legal retention requirements you're subject to (HPCSA's own record-keeping rules apply here too — see our HPCSA record-keeping guide for the specifics).
A retention policy means deciding, in advance, how long you keep records after a client's file closes, and having a system that actually enforces it rather than just accumulating data indefinitely.
5. Know what happens with third parties
If any part of your workflow touches a third-party service — payment processing, AI transcription, cloud storage — POPIA still holds you responsible for how that data is handled downstream. Know who your sub-processors are and what safeguards they carry.
How TheraLog approaches this
TheraLog was built with these requirements as the starting point, not an afterthought: your session notes are encrypted on your device using AES-256-GCM before they ever leave your browser, with the encryption key derived from your personal PIN using PBKDF2 — a key TheraLog itself never sees or stores. Built-in consent capture, full audit trails, and configurable data retention periods are part of the platform, not a manual process you have to maintain separately.
You can read more about the specific technical safeguards on our security page, or see the Information Regulator's official POPIA guidance for the full legal text.
This article is general information, not legal advice. For guidance specific to your practice, consult the Information Regulator or a legal advisor familiar with POPIA.
Want to see how this works in your own practice? Start a 30-day free trial — no credit card required.
