Guide
Data subject requests under POPIA: rules, deadlines, how to respond
POPIA gives anyone whose personal information you hold four requests they can make of your business: confirmation and access to what you hold (section 23), correction of it, deletion of it (both section 24), and objection to your processing of it (section 11(3)). The deadlines differ by type, and getting them right matters: access requests run on PAIA's 30-day clock with one possible extension, correction and deletion requests must be answered within 30 days under the POPIA Regulations as amended from 17 April 2025, and objections have no fixed statutory period, which makes a reasonable time the standard. Here are the rules, the forms, and a response process that holds up.
This article covers the legal side: which rules apply and by when. For the operational side - intake, identity checks, logging, and templates - see our practical guide to managing data subject requests.
The four request types and where each comes from
- Access (section 23). A data subject may ask you to confirm, free of charge, whether you hold personal information about them, and to provide the record or a description of it, including the identity of third parties who have had access to it. The request follows PAIA's request procedure, and you may charge only the prescribed PAIA fee for the record itself, not for the confirmation.
- Correction (section 24). A data subject may ask you to correct personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.
- Deletion (section 24). The same section covers destruction or deletion, including of records you are no longer authorised to keep under section 14's retention rules.
- Objection (section 11(3)). Where you process without consent, on grounds such as legitimate interest, the data subject may object on reasonable grounds relating to their situation. If the objection stands, section 11(4) is blunt: you may no longer process that personal information.
The prescribed forms
The POPIA Regulations prescribe standard forms for two of the four types: Form 1 for objections under section 11(3), and Form 2 for correction or deletion requests under section 24. Access requests use the PAIA request form instead, the same route as any other PAIA request to a private body.
Three practical points about the forms:
- The regulations were amended with effect from 17 April 2025 and the forms were updated, so blank copies your business saved in 2021 are out of date. Work from the current versions on the Information Regulator's site.
- A request on a form "substantially similar" to the prescribed one counts, and the amended regulations widened the channels: a correction request arriving by email, or an objection made by phone, is still a valid request. If an objection reaches you by phone, the regulations expect you to record it.
- Correction, deletion, and objection requests are free of charge to the data subject. You cannot levy a handling fee for them.
The deadlines, precisely
This is where generic advice gets POPIA wrong, usually by claiming a single blanket 30-day rule. The accurate position has three parts:
- Access requests: 30 days, extendable once. PAIA section 56 gives a private body 30 days to decide and respond. Section 57 allows one extension of up to a further 30 days, but only where the request covers a large number of records, requires a search through a large number of records, or the records sit at another location - and you must notify the requester of the extension, its length, and the reasons within the original 30 days.
- Correction and deletion requests: 30 days. The Act itself says "as soon as reasonably practicable"; the amended regulation 3 makes that concrete, requiring you to notify the data subject in writing of the action taken within 30 days of receiving the request.
- Objections: no fixed statutory period. Neither the Act nor the regulations prescribe a response deadline for a Form 1 objection. That is not a licence to sit on it: you must deal with it within a reasonable time, and if the objection stands, section 11(4) obliges you to stop processing. Treating objections to the same 30-day standard as the other types is the defensible practice.
How to respond: a five-step process
- Date-stamp and log the request on arrival. Every deadline above runs from receipt, so the clock starts whether or not anyone opens the inbox. A request that surfaces three weeks late has already spent most of its response period.
- Verify the requester's identity. Before disclosing, correcting, or deleting anything, confirm you are dealing with the data subject or someone authorised to act for them. Handing personal information to an impostor in response to an access request is itself a breach.
- Classify the request and its deadline. Access, correction, deletion, or objection - the classification decides the clock, the form, and whether a fee may apply. A single letter can contain more than one request; split them.
- Decide, on the right grounds. Access may be refused only on the grounds PAIA allows, applied via section 23(4)(a) - for example legal privilege or another person's privacy - and a refusal must say so. For a correction you dispute, section 24 sets the path: provide credible evidence supporting the information as it stands, or, if you and the data subject cannot agree, attach a note to the record showing a correction was requested but not made.
- Respond in writing and keep the trail. Notify the data subject of the action taken, within the deadline, and keep the request, your identity check, the decision, and the response together. If the Regulator asks about the request a year later, that file is your answer.
Running this without a spreadsheet
POPIAdesk handles the mechanics: each business gets a public request portal where data subjects submit access, correction, deletion, and objection requests, and every submission lands in the requests dashboard already date-stamped and classified. POPIAdesk tracks each request, including objections, against a 30-day deadline and sends reminders as the date approaches, so the response period never runs out unnoticed.
Frequently asked questions
Can we charge a fee for handling a request?
Only in one narrow case. Confirming whether you hold someone's information is free under section 23(1)(a), and correction, deletion, and objection requests are free under the regulations. The one chargeable item is providing the record itself in an access request, at the prescribed PAIA fee.
What if we cannot meet the 30 days on an access request?
PAIA section 57 allows one extension of up to 30 further days, but only for the reasons the section lists, and only if you notify the requester of the extension and its reasons within the original 30 days. An extension claimed after the deadline has passed is a deemed refusal, not an extension.
Can we refuse a request outright?
Sometimes. Access requests may be refused on the grounds PAIA provides, and the refusal must cite them. A disputed correction can be declined if you hold credible evidence supporting the information, with the data subject entitled to have the dispute noted on the record. An objection under section 11(3) turns on whether its grounds are reasonable; where they are, processing stops.
Where to start
Data subject requests are one item on a short list of POPIA duties; our compliance checklist for small businesses covers the full set. To see where your request process and the rest of your compliance stand today, take the free POPIA assessment - it takes about five minutes.
This is general information, not legal advice. For your specific situation, consult an attorney.