Blog
What changes when you stop treating the Act as a legal formality
A forty-person manufacturer on the East Rand had a privacy policy on its website, a POPIA clause in its supplier contracts, and no idea who was allowed to open the personnel files in the admin office. That gap is the normal starting point. The Act itself is not the hard part. The hard part is that a workshop generates records all day: clock-in sheets, delivery notes, supplier banking forms, medical certificates, and disciplinary letters that sit in a drawer because nobody decided what else to do with them.
When we run a two-week diagnostic for firms in this size band, we usually find three separate record systems running in parallel. The payroll system holds identity numbers and bank details. A shared drive holds scanned contracts and delivery notes. A filing cabinet holds the signed originals. Each one has a different idea of who can see what, and none of them has a retention rule.
In most owner-managed businesses, the answer is "whoever is in the office that day." That is the first thing to change. We normally recommend a short access list: the operations manager, one HR administrator, and the external payroll provider. Everyone else requests a specific document through a written note, and the request is logged. It sounds bureaucratic until the first time a former employee asks who saw their medical certificate.
The practical version of this is a single locked cabinet for physical files, a restricted folder on the shared drive for scans, and a rule that the two are reconciled at month end. A junior administrator can run that reconciliation in about two hours if the naming convention is consistent.
Delivery notes and proof-of-delivery slips are the records that pile up fastest in logistics and light manufacturing. They carry customer names, addresses, and sometimes signature images. We usually set a retention window tied to the tax and contractual reality: five years for anything that supports a VAT claim or a warranty, then destruction. Anything older than that is a liability with no operational value.
The destruction step is where most firms stall. Someone has to actually shred the paper and delete the scans, and someone has to record that it happened. A one-page destruction log, signed and dated, is enough.
Exit is the moment records handling usually falls apart. The laptop goes back, the access card is cancelled, but the shared drive permissions stay open for months. We build a short exit checklist into the handover: revoke system access on the last working day, move the personnel file to an archive folder, and confirm in writing which records are being kept and for how long.
None of this requires a lawyer on retainer. It requires someone to write down the rules, train the person who will follow them, and check once a month that the rules still match what is actually happening on the floor.
Related reading
Working through the same problem in your own business? Book a 30-minute scoping call.