Trusted by teams at
SasolGlencoreMSC CruisesUniversity of the Western CapeGivaudanSA Weather ServiceCity of JohannesburgUniversity of South AfricaSol Plaatje UniversityCIPC
Quick Look Course Summary:POPIA for Every Employee: Handling Personal Information Safely (3-hour online masterclass)
  • Next Public Course Date:

  • Length: 1 day(s)

  • Price (at your venue): 1 Person R 8,159 EX VAT 3 Person R 5,295 EX VAT 10 Person R 3,794 EX VAT

  • Certification Type:Non-Accredited

  • Locations & Venues: Live online on Zoom or Microsoft Teams - for one person or a whole organisation, anywhere in South Africa.

Get Free & personalised
Training Advice

    ★★★★★ 4.8 on Google from 770+ reviews


    Free and no obligation. We use your details only to reply to this request.

    POPIA for Every Employee: Handling Personal Information Safely (3-hour online masterclass)

    Every employee who touches personal information – a CV, a customer form, a WhatsApp group, a spreadsheet of ID numbers – knows what POPIA expects of them and what to do the moment something goes wrong.

    A data breach rarely starts in the IT department. It starts with a spreadsheet of ID numbers emailed to the wrong person, a customer form left on a counter, a photo of a staff list shared on WhatsApp. The Protection of Personal Information Act makes the organisation accountable for all of it, and the Information Regulator can investigate complaints, issue enforcement notices and impose penalties. This POPIA masterclass is the three-hour session that gives every employee – not only the information officer – a working understanding of the Act and the habits that keep personal information safe.

    It is a focused cut of BOTI's two-day POPIA training. Delegates learn what counts as personal information and special personal information, who the responsible party, operator and data subject are, and how the eight conditions for lawful processing translate into everyday rules: collect only what you need, say why you are collecting it, keep it accurate, keep it secure, and let people see and correct it. A module on the risky moments covers consent, direct marketing, sharing information with suppliers and operators, and the first hours after a security compromise, including notification of the Regulator and the people affected.

    Short case discussions use South African examples from HR, sales, reception and finance, and an on-screen exercise reviews a real collection form. Delegates leave with a PDF workbook, a one-page 'handle it safely' checklist and a personal action list. The session builds awareness and good practice; it is not legal advice.

    Why this course

    For your organisation

    • Staff at every level who handle personal information lawfully, not only the information officer and the IT team
    • Fewer avoidable breaches caused by everyday mistakes: the wrong attachment, the unlocked file, the oversharing WhatsApp group
    • A record of staff awareness training to show the Information Regulator, auditors and clients
    • Consistent answers when customers, employees or suppliers ask what you hold about them
    • A whole workforce trained in groups of up to 500, without travel or a day off the floor

    For your delegates

    • A plain-language explanation of POPIA and the words it uses
    • The eight conditions turned into daily habits for your own job
    • A simple decision test before you collect, share or keep personal information
    • The first steps to take when a breach happens or is suspected
    • A one-page checklist and a personal action list to keep at your desk

    What delegates will be able to do

    • Explain what POPIA covers, who it protects and who in the organisation is accountable
    • Recognise personal information and special personal information in the records you handle every day
    • Apply the eight conditions for lawful processing to your own collection forms, files and emails
    • Collect, store, share and dispose of personal information in line with purpose and minimality
    • Handle a request from a customer or employee to see, correct or delete their information
    • Check that consent wording and direct-marketing practices meet the Act's rules
    • Share information with suppliers and operators only under proper agreements and basic checks
    • Spot a security compromise early and follow the organisation's breach-notification steps

    Who should attend

    Every employee who handles personal information in any form: HR and payroll staff, receptionists, sales and marketing teams, customer-service agents, finance clerks, IT support, managers who keep team records, and new starters during induction. It also gives information officers and their deputies a ready-made awareness session to roll out across the organisation. No legal background is needed.

    Course outline

    Live session – POPIA in everyday work: what to collect, how to keep it, when to speak up

    Opening: why POPIA is everyone's job
    • Welcome, the three hours ahead and a quick poll: where does personal information live in your work?
    • What POPIA is for, who it applies to and the role of the Information Regulator
    • The words that matter: personal information, special personal information, processing, responsible party, operator and data subject
    • Case discussion: a staff list, a CV and a customer complaint – what is protected here?
    The eight conditions as daily habits
    • Accountability: who answers for the information you hold
    • Processing limitation and purpose specification: collect only what you need, for a reason you can state
    • Further processing limitation and information quality: using it for something new, and keeping it accurate
    • Openness: privacy notices and telling people what you do with their details
    • Security safeguards and data subject participation: locking it down, and letting people see and correct it
    • Exercise: review a collection form on screen against the eight conditions
    The risky moments
    • Consent: when you need it, what valid consent looks like and how to record it
    • Direct marketing by email, SMS and WhatsApp: the opt-in rule and the existing-customer exception
    • Sharing with suppliers, payroll providers and cloud services: operator agreements and basic checks
    • Children's information and special personal information such as health, biometrics and religious belief
    • Everyday leaks: wrong attachments, shared logins, photos of screens and documents left in printers
    • Case discussion: the spreadsheet that went to the wrong client
    When it goes wrong, and your action list
    • What counts as a security compromise, and why speed matters
    • The first steps: contain, report internally, record, and let the information officer notify the Regulator and the people affected
    • Handling a request to see, correct or delete personal information
    • Retention: keeping records only as long as needed, then destroying them properly
    • Personal action list: three changes in your own work this week

    How it is delivered

    Live online on Zoom (or Microsoft Teams), 2.5 to 3 hours – typically 09:00-12:00, or a time that suits the team. From 1 to 500 delegates, which makes it a practical way to train a whole site or company in a few sittings. Electronic handouts: a PDF workbook, a 'handle it safely' checklist and breach-response card, and a one-page summary, all sent before the session. Join a public session, or run it privately for your organisation on a date of your choice using your own privacy notice, collection forms and policies.

    Certificate: Delegates receive a BOTI certificate of attendance by email. This is a non-accredited masterclass; for a credit-bearing route ask us about BOTI's QCTO skills programmes.

    What our clients say

    ★★★★★ 4.8 on Google from 770+ reviews · word-for-word quotes from signed letters of reference

    “All training programmes were delivered in a highly professional manner, with effective coordination and strict adherence to our scheduling requirements. The facilitators demonstrated a commendable level of expertise, and the quality of delivery consistently met our expectations.”

    A national public entity (innovation)Head: HR · Eight programmes 2021-2026, from Customer Service Excellence and… · 2026

    “The facilitator was excellent and took time to ensure that the employee understood the content and was able to apply the learning in order to develop the portfolio of evidence.”

    A construction and renovations companyManager · Taking charge as a Leader & Closing the Gap between Specialist and… · 2026

    “We were particularly impressed by the quality of facilitation and the practical relevance of the content presented. The programme was delivered with professionalism, clarity, and a strong emphasis on real-world application”

    A digital marketing agencyHR Administrator · Conflict Resolution Workshop Training Programme · 2026

    Read what our clients say

    Frequently asked questions

    How many people can join?

    From 1 to 500 delegates on Zoom, so a whole department or company can attend in one or two sittings. Polls and chat questions keep large groups involved.

    Do we get handouts?

    Yes, electronically: a PDF workbook, the 'handle it safely' checklist, a breach-response card and a one-page summary, sent to every delegate before the session.

    Can we run it privately for our team?

    Yes. Pick a date and send us your privacy notice, a few collection forms and your breach procedure, and the facilitator uses them in the exercises so staff see POPIA applied to their own work.

    Is this the right session for our information officer?

    It is an awareness session for the whole workforce, and many information officers attend to see what their colleagues are taught. For the information officer's own duties – registration with the Regulator, the PAIA manual, impact assessments and the compliance framework – book the two-day POPI (Protection of Personal Information Act) Basic Training Course.

    Is this legal advice?

    No. The session explains the Act in plain language and builds good habits. For an opinion on a specific situation, speak to your information officer, an attorney or the guidance published by the Information Regulator.

    Is it accredited?

    No. It is a non-accredited masterclass and delegates receive a BOTI certificate of attendance by email. For a credit-bearing route ask us about BOTI's QCTO skills programmes.

    Related courses

    Realize incredible savings by sending more delegates

    Do you want to save costs by doing training at your premises?

    Save costs by providing own laptop

    Region *

    Please Contact Us Now - We Will Respond in 15 Minutes

      ★★★★★ 4.8 on Google from 770+ reviews


      Free and no obligation. We use your details only to reply to this request.

      Leadership & Management

      Human Resources, Labour & Employment Equity

      Microsoft Office & Computer Skills

      Business Optimization Training Institute (Pty) Ltd · 97 Greenlands Crescent, Sunningdale, 2192, Johannesburg · Reg 2017/286086/07 · VAT 4770208033 · Level 1 B-BBEE Contributor · 011 882 8853 · Facebook · LinkedIn
      © 2026 Business Optimization Training Institute. All rights reserved. · Privacy Policy
      Don’t Wait to Start Training — Contact us Today