Data Privacy and POPIA
What POPIA means for the customer data you store in the CRM, and what to know about your responsibilities.
What POPIA is
The Protection of Personal Information Act is South Africa's data protection law, governing how businesses collect, store, and use personal information about identifiable people — which includes the contacts, deals, and customer details you store in a CRM.
Why it matters for CRM use
The moment you store a customer's name, email, phone number, or address — which is the basic function of any CRM — you're processing personal information under POPIA, and your business (as the "responsible party") carries obligations around how that data is protected and used, regardless of which software you use to store it.
When this is relevant
From the moment you add your first real contact. This isn't a one-time setup step — it's an ongoing responsibility tied to how you collect and use customer data day to day.
What Allsorts CRM does, and what remains your responsibility
- Data is stored on infrastructure operated for this purpose, with encrypted storage of sensitive fields like SMTP credentials, and access controlled by your organization's team roles.
- POPIA compliance itself is a responsibility of your business, not something a software tool can fully hand you — using this CRM doesn't automatically make your business POPIA-compliant. You're responsible for things like having a lawful basis to collect a contact's information, honoring data subject requests, and your own data-handling policies.
- If POPIA compliance is a significant concern for your business, it's worth a conversation with a professional familiar with South African data protection law rather than relying on any single vendor's claims — including ours.