Labour Link
All blogs
SolutionsData protection

Your workers' data is in a WhatsApp group, and in 2026 POPIA makes that a R10-million problem

POPIA enforcement went proactive in 2026. If a farm's worker data lives in a chat group and a spreadsheet, that is now the exposure.

LL
Labour Link
July 6, 2026 7 min read
A hand holding a smartphone showing a busy generic group chat at a South African farm office desk, a stack of worker files and photocopied IDs beside it, an orchard through the window in morning light

What holding worker data properly protects you from, and what a chat group costs

Good practice with worker data does not feel like much on a normal day. Every worker's ID, bank details, and contract sit in one place that only the people who need them can open. When a worker asks what you hold on him, you can show him in a minute. When one leaves, his file is closed and, in time, deleted. And if a laptop is ever stolen, you know exactly whose information was on it and what to do next. It is quiet, and quiet is the point.

The version most farms run is louder and more exposed than it looks. The workforce lives in a WhatsApp group and a spreadsheet. ID photographs, bank confirmations, and copies of contracts have been sent around the group and now sit on a dozen personal phones, including the phones of workers who left two seasons ago. The spreadsheet is emailed to whoever asks. Nobody can say for certain who holds what. In 2026, in South Africa, that is no longer just untidy. It is a POPIA problem with a number attached, and the number is up to R10 million.

The Protection of Personal Information Act, POPIA, has been in force for years. What changed this year is enforcement, and the change is exactly the kind that catches a business that is not paying attention.

What changed in 2026

For most of POPIA's life, the Information Regulator acted on complaints. Someone reported you, and it looked into it. That is no longer the whole picture. In its plan for 2026 and 2027, presented to Parliament in May 2026, the Regulator set out a shift to proactive compliance assessments, running its own checks rather than waiting to be tipped off, and a monitoring programme that expects you to be able to show your homework: the documents, the controls, the processes.

Be clear about one thing, because the honest version is more useful than the scary one. The sectors the Regulator has named as first priorities are the big data holders, finance, insurance, health, retail, telecoms, and government. Farming is not on that list. What has changed is not that inspectors are heading for the packhouse. It is that the direction of travel is set, the fines are real, the Regulator's first penalty was R5 million, and “nobody has complained yet” is no longer a safe place to sit. The exposure a farm carries is the same exposure whether or not anyone is looking this month.

Where a farm's worker data actually lives

A cluttered South African farm office desk with a smartphone showing generic grey chat bubbles, a loose stack of photocopied identity documents with illegible details, and an open handwritten ledger, papers spilling across the desk
Be honest about what you hold and where. It is almost always more than it feels like, and some of the most sensitive kind.

Start by being honest about what you hold and where it is, because it is almost always more than it feels like. A farm processes a lot of personal information, and some of the most sensitive kind.

On every worker you keep an ID number and a copy of the document, a bank account for wages, a home address and next of kin, often a photograph, and increasingly a fingerprint or face scan for clocking. Some of that, the biometrics and anything about a worker's health, is what POPIA calls special personal information, which carries the highest protection of all. And where does it live? On paper in an unlocked drawer, in a spreadsheet on a shared laptop, in emails, and in the WhatsApp group where the day is run. Spread across all of those, copied and forwarded, with no single answer to the question “who can see this”.

Why a WhatsApp group and a spreadsheet fail POPIA

A smartphone left face-up and unattended on the dusty dashboard of a farm bakkie, keys and a worn cap beside it, an orchard blurred through the windscreen in afternoon light
A foreman's phone with the staff group on it, lost or sold with the chats still on it, is a data breach you are legally required to report.

POPIA does not ban WhatsApp or spreadsheets. It asks one practical question of wherever you keep personal information, and a chat group answers it badly.

The question comes from section 19 of the Act: have you taken reasonable steps to keep this information secure, against loss and against people who should not see it. A WhatsApp group fails on the plain facts. The data sits on personal phones you do not control. It is copied every time it is forwarded. There is no access list, no record of who opened what, and no way to pull it back from a worker who has left. A shared spreadsheet is the same story with a different icon.

Then there is the part almost no farm has thought about. Under section 22, if personal information is accessed by someone who should not have it, you must report it, to the Information Regulator and to every affected worker, in writing. A foreman's phone with the staff WhatsApp group on it is lost at a taxi rank, or sold with the chats still on it. That is a data breach you are legally required to notify. Most farms would not even know the clock had started.

POPIA does not ban WhatsApp. It asks whether you can keep worker data safe, and a group chat cannot.

What holding it properly looks like

A tidy South African farm office, a hand turning a key to lock a metal filing cabinet, a single closed laptop on a clean desk beside it, soft morning light through a window with an orchard behind
Mostly a matter of consolidation: bring worker data into one place, and control who can reach it.

The fix is not complicated, and it is mostly about consolidation. Bring the worker data into one place, and control who reaches it.

One record, not ten copies. Each worker's information in a single system, not scattered across phones and inboxes. Access by role. Only the people who need a worker's details can open them, and you can see who did. A purpose and a retention limit. You hold the data to run the employment, and when a worker has been gone long enough that you no longer need it, it goes. Real safeguards. A password and a locked cabinet, not an open drawer and a group chat. And if you use an outside provider to process the data for you, POPIA expects a written agreement that binds them to keep it safe. None of this is a burden a farm cannot carry. It is mostly deciding that worker data lives in one controlled place, and keeping it there. The same BCEA record-keeping discipline you already owe applies to how those records are held, not only to what is in them. It runs alongside the pre-hire checks that put the data in the file in the first place.

A POPIA data-handling check for the farm office

A clean South African farm office desk with a single sheet holding a short handwritten checklist, a pen resting on it, a mug and a closed folder to the side, calm morning light through the window
One page over how you hold worker information. Tick it, and a proactive assessment holds no surprises.

One page to run over how your farm holds worker information. If you can tick it, a proactive assessment holds no surprises. Pin it in the office.

POPIA data-handling check
Know what you hold
  • A list of the personal information you keep on workers: ID, bank, address, next of kin, photographs, biometrics, any health notes.
  • The special personal information (biometrics, health) identified and flagged for the highest protection.
  • One answer to “where does each of these live”, and it is not “several places”.
Control who reaches it
  • Worker data held in one system, not spread across phones, spreadsheets, and the WhatsApp group.
  • Access limited to the people who need it, with a record of who can open what.
  • ID copies and sensitive files kept out of the day-to-day WhatsApp group entirely.
Be ready if it goes wrong
  • A retention rule: how long a former worker's data is kept before deletion, and someone who does it.
  • A written agreement with any outside provider who processes worker data for you.
  • A simple breach plan: who you notify (the Regulator and the workers) and how fast.

Labour Link's Workforce Control gives a farm the one controlled place this article keeps pointing at: worker records held at hr.labourlinksoftware.co.za with access by role, a retention rule, and the ID copies and biometrics kept out of the group chat where they were never safe. A tool that runs your workforce through WhatsApp cannot solve a WhatsApp problem. Holding worker data properly is not extra admin. In 2026 it is the difference between a quiet office and a R10-million one.

Found this useful?