PayrollOne — South African payroll bureau software← Back to home
Legal · Data protection

POPIA Privacy Notice

How PayrollOne collects, processes, stores and protects personal information under the Protection of Personal Information Act 4 of 2013 (POPIA).

Effective 1 June 2026 · Republic of South Africa

1

Who we are and our role

PayrollOne (“PayrollOne”, “we”, “us”) supplies a multi-tenant payroll administration platform to South African accounting firms and payroll bureaus, who in turn administer payroll for their employer clients.

For the payroll data captured on the platform, the employer (our client, or our accounting-firm partner’s client) is the responsible party as defined in POPIA. PayrollOne acts as an operator, processing personal information on the employer’s behalf, on their instruction, and only for the purposes set out in this notice.

For information we collect directly — such as trial applications, prospect enquiries, billing records and platform login credentials — PayrollOne is the responsible party.

2

Personal information we process

Depending on your relationship with us, we process the following categories:

  • ▸Employee identity data: full names, ID or passport number, date of birth, gender, nationality, marital status, tax reference number.
  • ▸Contact and address data: residential and postal addresses, email addresses, telephone numbers.
  • ▸Employment data: employee code, job title, appointment and termination dates, pay frequency, cost centre, leave balances and leave taken.
  • ▸Remuneration data: basic salary, wages, overtime, allowances, bonuses, commission, benefits, deductions, garnishee and maintenance orders, loan balances.
  • ▸Statutory data: PAYE, UIF, SDL and ETI calculations, UIF declaration codes, COID earnings, medical-aid dependants for tax-credit purposes.
  • ▸Banking data: bank name, branch code, account number, account holder and account type, used solely to produce payment files and payslips.
  • ▸Platform account data: user name, email address, role, hashed password, session and audit logs, IP address and timestamps.
  • ▸Commercial data: firm or bureau name, registration number, contact person, billing tier, invoices and payment history.

Some of this information is special personal information or relates to children (for example medical-aid dependants). We process it only where POPIA permits — principally because processing is necessary to comply with an obligation imposed by law on the employer, such as the Income Tax Act, the Unemployment Insurance Contributions Act, the Skills Development Levies Act, the Basic Conditions of Employment Act and COIDA.

3

Purpose of processing

Personal information is processed for the following explicitly defined purposes only:

  • ▸Calculating remuneration, PAYE, UIF, SDL, ETI and other statutory amounts.
  • ▸Producing payslips, payroll registers, variance reports and management reports.
  • ▸Producing statutory submissions and files — EMP201, EMP501, IRP5/IT3(a), UI-19, UIF electronic declarations and COID returns.
  • ▸Generating bank payment batches and salary payment instructions.
  • ▸Providing employer and employee self-service access to their own payroll documents.
  • ▸Maintaining an audit trail of who captured, approved or changed payroll data.
  • ▸Administering platform accounts, authentication, support requests and service notifications.
  • ▸Billing, invoicing, credit control and reseller commission calculation.
  • ▸Detecting and preventing fraud, misuse and security incidents, and complying with legal obligations.

We do not sell personal information, and we do not use payroll data for direct marketing or for automated decision-making that has legal consequences for a data subject.

4

Lawful basis for processing

We rely on the following grounds in section 11 of POPIA:

  • ▸Compliance with an obligation imposed by law on the responsible party — SARS, UIF, SDL, COID and labour-law reporting.
  • ▸Performance of a contract to which the data subject is a party — the employment relationship and our service agreement.
  • ▸Legitimate interests of the responsible party, the data subject or a third party — securing the platform, preventing fraud, recovering fees.
  • ▸Consent — where we rely on consent (for example optional marketing communications), it is voluntary, specific and informed, and may be withdrawn at any time.
5

Where the information comes from

Most payroll information is supplied to us by the employer or by the accounting firm acting for the employer — through direct capture on the platform, spreadsheet or CSV import, or migration from a previous payroll system. Employees may also submit or update their own details through the client portal. Where information is not collected directly from the data subject, the employer remains responsible for having notified its employees in terms of section 18 of POPIA; this notice supports that obligation.

6

Our duties as an operator

In terms of sections 20 and 21 of POPIA, PayrollOne undertakes that it will:

  • ▸Process personal information only with the knowledge and authorisation of the responsible party.
  • ▸Treat all personal information that comes to its knowledge as confidential and not disclose it unless required by law or in the proper performance of its duties.
  • ▸Establish and maintain the security measures referred to in section 19 of POPIA.
  • ▸Notify the responsible party immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.
  • ▸Impose equivalent written obligations on any sub-operator it engages.
  • ▸Return or securely delete personal information on termination of the service, subject to lawful retention requirements.
7

Sharing and disclosure

We disclose personal information only to:

  • ▸The employer and the accounting firm or bureau that administers that employer's payroll.
  • ▸Statutory authorities where the employer submits returns — SARS, the Unemployment Insurance Fund, the Compensation Fund and bargaining councils.
  • ▸Banks and payment providers, strictly to execute salary and third-party payment instructions.
  • ▸Our infrastructure, hosting, database and transactional-email providers, acting as sub-operators under written contract.
  • ▸Professional advisers, auditors, or a court or regulator, where we are legally compelled.
8

Security safeguards

We apply generally accepted information-security practices appropriate to the sensitivity of payroll data, including encryption of data in transit over TLS, encryption at rest on our database clusters, hashed and salted passwords, role-based access control that segregates admin, accounting-firm, employer and reseller users, strict tenant isolation so that no client can access another client’s data, immutable audit logging of privileged actions, least-privilege administrative access, and regular backups. We continually review and update these safeguards in response to new risks and deficiencies.

9

Retention and deletion

Payroll and tax records are retained for at least five years from the date of the last entry, as required by the Tax Administration Act and the Basic Conditions of Employment Act, and longer where a dispute, audit or investigation is pending. Trial applications and prospect enquiries that do not convert are deleted or de-identified within 24 months. Platform audit logs are retained for the life of the account. Once a lawful retention period expires, records are securely deleted or de-identified in a manner that prevents reconstruction.

10

Your rights as a data subject

Subject to POPIA, you have the right to:

  • ▸Be notified that your personal information is being collected, or has been accessed without authorisation.
  • ▸Request confirmation of whether we hold personal information about you, and request a record or description of it.
  • ▸Request correction, deletion or destruction of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained.
  • ▸Object, on reasonable grounds, to the processing of your personal information.
  • ▸Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
  • ▸Not be subject to unsolicited direct electronic marketing.
  • ▸Submit a complaint to the Information Regulator, and to institute civil proceedings for a breach of POPIA.

Because PayrollOne is an operator for payroll data, requests relating to your employment records should be directed to your employer, who is the responsible party. We will assist the employer in giving effect to any valid request. Access requests may be subject to the prescribed form and fee, and to verification of your identity.

11

Cookies and platform telemetry

The platform sets only the cookies and local-storage tokens necessary to keep you signed in, maintain session security and remember basic interface preferences. We do not use third-party advertising or cross-site tracking cookies. Server logs record IP address, user agent and request metadata for security and diagnostic purposes.

12

Data Residency and International Transfers (Section 72 POPIA Disclosure)

By using this service, you acknowledge and agree that your personal information may be transferred to, stored, and processed outside of the Republic of South Africa. Our application infrastructure is hosted on secure, enterprise-grade cloud environments, including Amazon Web Services (AWS) and Microsoft Azure, primarily located in the United Kingdom and the United States.

All database records are managed via MongoDB Atlas on these secure clusters. We take rigorous steps to ensure that our international infrastructure providers adhere to data protection standards (including the UK GDPR and US Data Privacy Frameworks) that provide a level of protection substantially similar to the conditions for the lawful processing of personal information as required by the Protection of Personal Information Act (POPIA). These transfers are necessary for the technical performance, security, and maintenance of the service.

13

Changes to this notice

We may update this notice from time to time to reflect changes in law, our infrastructure or our services. The current version is always published on this page with its effective date. Material changes will be communicated to account holders by email or in-platform notice.

Bureau-grade compliance

Payroll data you can defend in an audit.

Tenant isolation, immutable audit trails and SARS-ready outputs — on every cycle, for every client.

Start your free trial →