Compliance Guide

POPIA & SA ID Number Validation

A guide to validating the structure of South African ID numbers with the Protection of Personal Information Act (POPIA) in mind.

What is POPIA?

The Protection of Personal Information Act (POPIA) is South Africa's data protection law that came into full effect on 1 July 2021. It regulates how organizations collect, process, store, and share personal information.

Key POPIA Principles

Accountability: Organizations must take responsibility for compliance
Processing Limitation: Only process personal information with consent or legal basis
Purpose Specification: Clearly define why you collect personal information
Further Processing: Don't use data for purposes beyond what was originally intended
Information Quality: Keep personal information accurate and up to date
Openness: Be transparent about how you handle personal information
Security Safeguards: Protect personal information from unauthorized access
Data Subject Rights: Respect individuals' rights over their data

ID Numbers Under POPIA

Important

South African ID numbers are classified as personal information under POPIA. They can be used to identify an individual and extract sensitive information like date of birth, gender, and citizenship status.

When you validate ID numbers, you are processing personal information and must comply with POPIA's requirements. This applies whether you're verifying employee IDs, customer information, or any other use case.

How SA ID Checker Supports Your POPIA Obligations

SA ID Checker is designed with privacy and POPIA in mind. We validate the structure of an ID number and decode the date of birth, age, gender and citizenship status carried in the number itself. Here's how we handle data:

We Never Store ID Numbers

ID numbers are validated and the number itself is not written to our database. We also do not store the decoded personal details (date of birth, age, gender or citizenship) read from the number. The validation result is returned to you in milliseconds.

Privacy-Safe Usage Metadata Only

To run your account we keep minimal usage metadata such as whether a check passed, the time it ran and the feature used (for example single check, bulk CSV or API). This metadata contains no ID number and no decoded demographic details.

No Selling of Your Data

Because we never store ID numbers or decoded personal details, there is no such data to sell or share with third parties. We do not trade the privacy-safe usage metadata we keep to operate your account.

Secure Infrastructure

All communications are encrypted using TLS/SSL. Our infrastructure is regularly audited and follows security best practices.

Your POPIA Responsibilities

While SA ID Checker is designed with POPIA in mind, you also have responsibilities when validating ID numbers. Here's what you need to consider:

1Obtain Proper Consent

Before validating someone's ID number, ensure you have:

  • Obtained consent from the data subject, OR
  • A valid legal basis for processing (contract, legal obligation, etc.)
  • Informed the person why you need to validate their ID

2Limit Data Collection

Only collect and process ID numbers when necessary:

  • Don't collect ID numbers "just in case"
  • Only extract the information you actually need
  • Delete ID numbers when no longer needed

3Secure Your Data

If you store validation results or ID numbers in your own systems:

  • Encrypt data at rest and in transit
  • Implement access controls
  • Regularly audit who has access to personal information
  • Have a data breach response plan

4Respect Data Subject Rights

Be prepared to handle requests from individuals to:

  • Access their personal information
  • Correct inaccurate information
  • Delete their personal information
  • Object to processing

Common Use Cases

πŸ‘”

Employee Onboarding

Validate employee ID numbers during hiring with their consent as part of the employment contract, as one input into your onboarding checks.

🏦

Customer KYC

Validate the ID number as one step of your Know Your Customer process, with clear disclosure of purpose. It does not replace full identity verification.

🏠

Tenant Applications

Check tenant ID numbers during lease applications with consent included in the application form.

πŸ”ž

Age Checks

Read the date of birth and age decoded from the ID number for age-restricted products, with minimal data collection.

POPIA Compliance Checklist

Use this checklist before validating ID numbers:

  • I have a lawful basis to process this ID number (consent, contract, legal obligation)
  • I have informed the data subject why I need to validate their ID
  • I am only collecting the minimum information necessary
  • I have appropriate security measures in place for any data I store
  • I have a process to handle data subject requests
  • I know how long I will retain this information
  • I will not use this information for purposes beyond what was disclosed

Ready to Validate SA ID Numbers?

Start using SA ID Checker to validate the structure of SA ID numbers, with privacy and POPIA in mind.

Try Free Validator