Digital Business Cards and POPIA: What You Actually Have to Do
The Protection of Personal Information Act applies to any South African business that processes personal information, and a business card is personal information by definition: a name, a phone number, an email address, an employer.
Most people assume this is their software vendor's problem. It is not. The moment somebody fills in their details on your card, you are the responsible party for that record. The vendor is your operator, which makes them accountable to you, and you accountable to the person whose details you now hold.
This is a practical guide to what that means day to day, and what to ask a vendor before you commit. It is not legal advice, and a compliance officer at a large organisation will want more detail than this.
What counts as processing
POPIA defines processing very broadly: collecting, storing, using, sharing and deleting all count. So does simply holding a list.
Practically, a digital business card involves processing at three points, and they have different obligations:
- Your own staff details on the cards you issue. You are processing your employees' information, which you already do for payroll.
- The leads you capture. Someone gives you their name and number through your card. This is the part most businesses handle worst.
- The analytics. Card views and clicks, which are generally not personal information unless tied to an identified person.
Tell people what you are collecting and why
Section 18 is the one that gets skipped. When you collect personal information directly from someone, you have to tell them who is collecting it, why, and whether giving it is voluntary or required.
This does not mean a page of legal text on a form somebody is filling in while standing up at an expo. It means a short, honest line near the field: who you are, what you will use it for, and a link to your privacy policy. "We will use this to follow up on your enquiry" is a legitimate purpose, plainly stated.
What it rules out is collecting an email address to follow up on an enquiry and then adding it to a monthly newsletter. That is a different purpose, and it needs its own consent. Section 69 governs direct marketing specifically, and it is stricter than most South African businesses behave as though it is.
Keep it only as long as you need it
Section 14 says you may not keep personal information for longer than is necessary for the purpose you collected it for. A lead from an expo three years ago that never went anywhere is not something you have a reason to still hold.
The practical version is a retention habit rather than a policy document: review the captured list periodically and delete what is dead. If your card platform lets you delete contacts and export what remains, this takes an afternoon a year.
Secure it, and be able to prove you did
Section 19 requires appropriate, reasonable technical and organisational measures to protect personal information. The Act does not prescribe a specific technology, which is why "appropriate" is doing a lot of work in that sentence.
For a hosted card platform, the questions worth asking are concrete:
- Is the data encrypted in transit and at rest?
- Can anyone read another customer's records? Ask how it is enforced, not whether it is.
- Who inside the vendor can see your data, and is that access logged?
- Are leads captured by your staff visible to other customers of the same platform?
The best answer to the second question is that the database itself refuses the record, rather than the application remembering to filter it. That is the difference between a rule that holds when a page has a bug and one that does not.
Know where the data physically sits
Section 72 restricts sending personal information outside South Africa. This is the question a procurement or compliance reviewer asks first, and most vendors cannot answer it on the spot.
It is not a prohibition. Transfer is permitted where the receiving country's law provides adequate protection substantially similar to POPIA, and separately where the transfer is necessary to perform the contract with the person concerned. The European Union is the jurisdiction that "adequate" is usually measured against, and GDPR is at least as strict as POPIA rather than weaker.
So "our database is in the EU" is a good answer, not an embarrassing one. What matters is that the vendor knows, says so in their privacy policy rather than burying it, and can tell you which sub-processors are involved. Cardtly's database runs in the EU, and the privacy policy names every sub-processor along with the retention periods.
The only version that needs care is a hard data residency requirement, which turns up in public sector tenders. If your tender says the data must stay in South Africa, ask early, because moving a database region is a migration and not a setting.
People can ask for their data, and ask you to delete it
Sections 23 to 25 give a data subject the right to ask what you hold about them and to have it corrected or deleted. Somebody who left their details at your stand can ask you to remove them, and you have to be able to do it.
This is worth testing rather than assuming. Can you find every record for one person, and can you remove it? If the answer involves a spreadsheet somebody downloaded and emailed around, you have a problem that is not about software.
The same right applies to you as a customer of your card platform. Ask whether you can export everything the platform holds about your account, and whether you can delete the account and have the data actually go. Cardtly does both without a support ticket: a single file containing everything held about the account, and a deletion that cascades through leads, cards, teams, organisations and billing.
Have a plan for the day it goes wrong
Section 22 requires notification to the Information Regulator and to the affected people as soon as reasonably possible after a breach. Nobody enjoys this conversation, which is why most businesses have never had it in advance.
Two questions decide whether you can comply at all. Would you know? And could you say what was affected?
The second is the one that turns a bad day into a much worse one. Without a log of who changed what and when, a breach investigation becomes guesswork, and "we cannot determine the scope" is not an answer the Regulator finds reassuring.
What to ask before you sign
A short list you can send a vendor, and which any serious one can answer in a paragraph each:
- Where is the data hosted, and does personal information leave South Africa?
- Who are your sub-processors, and are they named publicly?
- How is one customer's data kept separate from another's, technically?
- Can I export everything you hold about my account, myself?
- Can I delete my account and have the data actually removed, and what is the backup window?
- What are your retention periods?
- Is administrative access to customer data logged?
- What is your breach notification process, and what would you be able to tell me?
The answers matter less than whether they arrive quickly and specifically. A vendor who needs two weeks to find out where their own database is has told you something.
The short version
POPIA is not the obstacle to digital business cards that people assume. A digital card is generally easier to comply with than a paper one, because the records are in one place that can be searched, exported and deleted, rather than in a drawer of cards, a spreadsheet on a laptop and a WhatsApp history.
What you have to do is tell people what you are collecting and why, keep it no longer than you need, secure it, know where it lives, and be able to find and delete it when somebody asks. None of that is exotic. Most of it is a habit rather than a project.
See Cardtly's privacy policy for sub-processors and retention periods, or ask us a specific question if you are working through a tender.
Frequently asked questions
Does POPIA apply to digital business cards?
Yes, because a name, phone number and email address are personal information. The important point is who it applies to: when someone fills in their details on your card, you are the responsible party for that record, and your card platform is your operator. The obligation to tell people what you are collecting and why sits with you, not with the vendor.
Do I need consent to capture a lead on my digital business card?
Consent is one lawful basis but not the only one, and for a genuine enquiry the purpose is usually obvious enough to satisfy the Act. What section 18 does require is that you tell the person who is collecting the information and why, in plain language, near the field. Where consent clearly matters is direct marketing under section 69: using an address you collected to answer an enquiry for a newsletter instead is a different purpose and needs its own permission.
Is it a POPIA problem if the data is hosted outside South Africa?
Not in itself. Section 72 permits cross-border transfer where the receiving jurisdiction provides adequate protection substantially similar to POPIA, and separately where the transfer is necessary to perform the contract. The EU is the benchmark adequacy is usually measured against, and GDPR is at least as strict as POPIA. What matters is that the vendor knows where the data sits, discloses it in their privacy policy, and names their sub-processors. A hard data residency requirement in a public sector tender is a different conversation and worth raising early.
How long can I keep leads I captured at an expo?
Section 14 says no longer than is necessary for the purpose you collected them for, which for a dead enquiry from three years ago is difficult to argue. The practical approach is a retention habit rather than a policy document: review the captured list periodically and delete what has gone nowhere. If the platform lets you export and delete contacts, this is an afternoon a year.
What should I ask a digital business card vendor about POPIA?
Eight questions, and how fast they answer tells you as much as the answers. Where is the data hosted and does it leave South Africa; who are your sub-processors and are they named publicly; how is one customer's data separated from another's technically; can I export everything myself; can I delete my account and have the data removed, and what is the backup window; what are your retention periods; is administrative access logged; and what is your breach notification process. A vendor who needs two weeks to find out where their own database is has told you something.