
It’s Sunday evening and you’re finally catching up on session notes. Some are in a notebook in your bag. Some are voice notes on your phone. A new client’s intake form is sitting in your WhatsApp chats, next to a photo of your nephew’s birthday cake. Somewhere in the back of your mind a voice says: isn’t there a law about this?
There is. The Protection of Personal Information Act, or POPIA, applies to registered counsellors, life coaches, reiki practitioners and doulas alike. The good news is that POPIA for practitioners doesn’t have to mean hiring a lawyer or drowning in policy documents. For most solo and small practices, it comes down to a handful of habits done consistently.
This guide explains what POPIA expects of you in plain language, with a practical checklist you can work through this month. It’s general information, not legal advice, so speak to a qualified adviser about your specific situation.
The short answer
If you collect clients’ names, contact details, session notes or health information, POPIA applies to you. You need a lawful reason and clear consent to collect it, you must keep it secure, only use it for the purpose you collected it for, delete it when you no longer need it, register an Information Officer, and report any breach to the Information Regulator.
Why POPIA matters more for wellness practitioners
You handle something more sensitive than most small businesses: what people tell you when they’re at their most vulnerable.
POPIA treats some information as “special personal information”. Section 26 says a responsible party may not process personal information concerning a person’s “religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information” unless one of the exceptions in section 27 applies.
Think about a typical intake form or session note. Mental and physical health, relationships, spiritual beliefs, trauma. Much of what you record falls into that special category. The main exception you’ll rely on is in section 27(1)(a): processing “carried out with the consent of a data subject”. That means your consent process matters a lot.
The stakes are real. Under section 109, the Information Regulator can issue an administrative fine that may “not exceed R10 million”. More importantly, a leak of a client’s session notes is a breach of trust that’s very hard to repair.
Free: The Wellness Practice Growth Guide. A 12-point self-check, seven practical chapters and a 90-day plan to help you fill your diary without burning out.
The eight POPIA conditions, translated for your practice
POPIA is built around eight conditions for lawful processing. Here’s what each one looks like in a coaching, counselling or holistic practice.
- Accountability. You, as the practice owner, are responsible for compliance. You can’t hand that responsibility to your booking software or your admin assistant.
- Processing limitation. Only collect what you actually need, with consent or another lawful reason. If you don’t need a client’s ID number, don’t ask for it.
- Purpose specification. Know why you’re collecting each piece of information and tell your client. “To provide coaching sessions and send invoices” is a purpose. “Just in case” is not.
- Further processing limitation. Don’t use information for something unrelated. Adding every client to your newsletter without asking is a common slip.
- Information quality. Keep records accurate and up to date, especially contact details and emergency contacts.
- Openness. Be transparent. A short, plain-language privacy notice on your website and intake form covers most of this.
- Security safeguards. Protect records against loss, damage and unauthorised access, whether they’re on paper or in the cloud.
- Data subject participation. Clients have the right to ask what you hold about them and to ask for corrections or deletion.
POPIA for practitioners: a client record keeping checklist
1. Register your Information Officer
Every responsible party has an Information Officer. The Information Regulator’s guidance note says that for a sole proprietor, this is the natural person who carries on the business or profession, or someone they authorise. For a company, it’s the CEO or equivalent. In a one-person practice, that’s almost certainly you. The guidance says registration with the Regulator is “a compulsory requirement”, and you can register online through the Regulator’s portal.
2. Get clear, informed consent at intake
Your intake process should explain, in plain words, what you collect, why, who can see it, how long you keep it and how clients can ask for access or deletion. Ask for explicit consent to process health information. Keep a record of that consent. If you work with minors, you’ll need consent from a parent or guardian.
3. Get your notes out of WhatsApp
WhatsApp is convenient, but it’s a poor filing cabinet. Messages sync to personal phones, backups and sometimes shared devices. Move intake forms, notes and anything sensitive into one secure system, then delete the copies from chats and camera rolls.
4. Lock down your devices and accounts
- Use a strong password or PIN on your phone and laptop, and turn on automatic screen lock.
- Turn on two-factor authentication for your email and practice software.
- Don’t share a login with a partner, family member or admin helper. Give them their own access, limited to what they need.
- Keep paper records in a locked cabinet, not a box in the boot of your car.
- Keep backups secure too; a random USB stick isn’t a backup plan.
5. Check your operators
Any service that stores or processes client information on your behalf, such as booking software, cloud storage, email marketing tools or a bookkeeper, is an “operator” under POPIA. You should have a written agreement with each one confirming they’ll keep the information secure and confidential. For most software, that’s in the terms of service or a data processing agreement. Read it.
6. Set a retention period and stick to it
POPIA says you shouldn’t keep records longer than you need them, unless a law or your professional body requires it. If you’re registered with the HPCSA, its guidelines on patient records say records should be stored for “at least a minimum of six (6) years as from the date that a patient health record has become dormant”, with longer periods for minors (at least until their 21st birthday) and for people who are mentally incapacitated. If you belong to another professional body, check its guidance and write your chosen period into your privacy notice.
7. Separate marketing from care
Booking reminders and invoices are part of the service. Newsletters and promotions aren’t. Ask clients to opt in to marketing separately, and make it easy to opt out. Our guide to marketing for therapists and counsellors shows how to build a mailing list the respectful way.
What to do if something goes wrong
Imagine your laptop is stolen from your car in Durban, or you send a client’s notes to the wrong email address. Under section 22, that’s a security compromise, and you must report it.
The Information Regulator’s fact sheet on security compromises says you should notify the Regulator “as soon as it is reasonably sure that a security compromise has occurred”, without waiting to finish your investigation. Notifications to the Regulator must be logged through the eServices portal on its website. There’s no minimum threshold; the Regulator’s position is that security compromises must be reported.
You’ll also need to tell affected clients, by email, letter or another suitable method, what happened, what you’re doing about it and what they can do to protect themselves.
POPIA compliance for small business: keep it simple
You don’t need a 40-page manual. For a solo practice, a sensible POPIA pack looks like this:
- A one-page privacy notice on your website and in your intake form
- A consent section in your intake form, with separate marketing opt-in
- Your Information Officer registration confirmation
- A short list of your operators (software, storage, bookkeeper) and their agreements
- A written retention period and a diary reminder to review old records once a year
- A simple breach plan: who you’ll call, how you’ll notify clients, where the Regulator’s portal is
The biggest practical win is reducing the number of places client information lives. When records are scattered across a notebook, WhatsApp, Google Drive, email and a spreadsheet, it’s almost impossible to keep them secure or to answer a client’s access request. Consolidating into one system is also one of the easiest ways to cut admin, as we discussed in our piece on what practice management software wellness practitioners actually need. If you’re still weighing up whether going digital is worth it, this look at the future of wellness practice management is a useful starting point.
That’s part of why we built zenconnekt’s practice tools the way we did: bookings, intake, client records and invoicing sit in one place, with access tied to your own login, so you’re not copying sensitive details between apps.
Key takeaways
- POPIA applies to every practitioner who collects client information, regulated or not.
- Health, beliefs and sex life are special personal information; you’ll usually rely on explicit client consent to process them.
- Register yourself as your practice’s Information Officer with the Information Regulator.
- Move sensitive records out of WhatsApp and personal camera rolls into one secure system.
- Set and document a retention period; HPCSA guidance is at least six years after a record becomes dormant.
- Report any security compromise to the Regulator through its eServices portal and tell affected clients.
If you’d like your bookings, intake forms and client records in one secure place, create your zenconnekt practitioner profile. Founding profiles are free with the code ZEN100 until 31 October 2026, so you can set things up properly before the busy season.
Frequently asked questions
Does POPIA apply to life coaches and holistic practitioners?
Yes. POPIA applies to anyone who processes personal information in the course of their work, not only regulated health professionals. If you keep client names, contact details, intake forms or session notes, you’re a responsible party under POPIA and need to meet its conditions, including security, consent and registering an Information Officer.
Do I need to register as an Information Officer if I work alone?
The Information Regulator’s guidance says registration is compulsory. For a sole proprietor, the Information Officer is the person who carries on the business or profession, or someone they authorise. In a one-person practice that is usually you. You can register online through the Regulator’s website.
How long should I keep client records under POPIA?
POPIA says records shouldn’t be kept longer than needed unless a law or professional body requires it. HPCSA guidelines say health records should be kept at least six years after they become dormant, and longer for minors. Choose a period that fits your professional body’s rules and state it in your privacy notice.
Can I keep client notes on WhatsApp or my phone?
It isn’t specifically banned, but it’s hard to keep secure. Chats back up to cloud accounts, sync to other devices and sit alongside personal messages. POPIA requires reasonable security safeguards, so move sensitive notes into one protected system, turn on device locks and two-factor authentication, and delete the stray copies.
Sources
- Information Regulator: Fact sheet on handling of security compromises (2025)
- Information Regulator: Guidance note on Information Officers and Deputy Information Officers
- POPIA section 26: Prohibition on processing of special personal information
- POPIA section 27: General authorisation concerning special personal information
- POPIA section 109: Administrative fines
- HPCSA: Guidelines on patient recordkeeping (2022)