guide
Sections

Start here

POPIA rights and how to use them

Access, correction and erasure — who at the school can act on a request, what each one actually produces, and the thirty-day review before anything is deleted.

A parent can ask what you hold about their child, ask you to correct it, and ask you to delete it. POPIA gives them that right; this page is about what happens in the system when you act on it.

Who at the school can act

Privacy requests are not an ordinary administrator task. The school nominates a POPIA officer, and only that person can open the privacy screen, start a request, or change the retention policy.

An administrator who is not the nominated officer can see the retention policy — it is useful context for running the school — but cannot change it.

Starting an access request, starting an erasure, and changing the retention policy each additionally require a passkey on the device in front of you at the moment you do it. Being signed in is not enough. These are the actions where a borrowed unlocked laptop would otherwise be sufficient to export or destroy a child’s record.

Every one of these actions is written into your school’s audit trail.

Access: what the export contains

An access request produces a single package for one person: a cover document, the person’s own record, their check-in and check-out history, the audit entries about them, the messages that were sent about them and whether each was delivered, and the messages their family sent in.

The word doing the work there is one person. An access export is the subject’s personal data — it is not a report, and it is not a slice of the school. Three sections of the export were once wrongly scoped, and the result was not an obscure vulnerability: it was the deliberate, audited output of the feature, handed to a member of the public who was entitled to keep it, containing other families’ names, phone numbers, email addresses and the health information in their sick notes.

That is fixed, and it is worth stating in a document about trust rather than quietly. Every section is now resolved from the subject: a learner’s delivery records are the ones sent to that learner’s own guardians, and if a learner has no guardians recorded the answer is an empty list — never everybody.

If any part of the export cannot be assembled, the request fails rather than completing with a section silently missing. An access request is a legal completeness guarantee, so a half-answer marked done is worse than an error.

The finished package is stored encrypted under your school’s own key, and a checksum is recorded over the file the subject actually receives, so you can demonstrate that what you handed over is what was produced.

Correction: a record, not an edit

Logging a correction request records that somebody asked for something to be corrected, what they asked for, and who recorded it. It is stored as a completed, audited entry in the privacy log.

It does not change the underlying record. The actual correction — a misspelled name, a wrong phone number, the wrong class — is made on the person’s own record by school staff in the normal way. The privacy log is the evidence that the request was made and dealt with, which is the part a regulator asks about.

Erasure: thirty days, then step by step

Erasure is the one action in the product designed to be difficult to do by accident.

To start one, the nominated officer states the legal basis, types the word ERASE to confirm, and completes a passkey check. The screen names the person first and asks for confirmation of who they are, because an erasure aimed at the wrong learner is not recoverable.

The request then sits in a thirty-day review period. Nothing is deleted during it. The school can cancel the request at any point in that window — with a stated reason — so if the family withdraws their request, or somebody realises the wrong person was named, nothing is deleted at all. The screen shows when the review period ends.

When the period elapses, the deletion runs one store at a time, and the screen shows the progress under a heading the app calls Deletion steps — each step marked as scheduled, done, failed or skipped.

The reason it is broken into visible steps is the whole point of the design. A learner’s name does not live in one place; it is also on the alert raised about a late pickup, on the nudge sent when they did not arrive, on the delegation naming the adult allowed to collect them, on the rows staged from the last roster upload, and in the encrypted archives of every one of those. An earlier version covered four of those places, missed the rest, and reported the erasure as complete anyway. Asserting completion to a regulator while a child’s name is still readable somewhere is the specific failure the visible steps exist to prevent.

So a request is marked complete only when every step has succeeded. If a step fails, the request stays open and re-runnable, the failed step is named on screen, and nothing claims to be finished. The archives are rewritten last, after the live records they mirror, so the two can never be left disagreeing.

One honest limitation: staff records are not covered by the automatic deletion. A staff member can be named as the subject of a request, but the cascade has no route for staff accounts, so the request will not be marked complete and the deletion has to be handled separately. It fails visibly rather than reporting a success it cannot back up.

The retention policy

Retention is the other half of the same subject: information you no longer need is information you should not be holding.

The nominated officer sets, per school, how long check-in and check-out records are kept, how long audit records are kept, how long messages from parents and delivery records are kept, and how long visitor records are kept. Older records move into an encrypted archive rather than remaining in the live system.

The defaults are a little over a year for check-in and check-out records, and two years for audit and visitor records. Each setting has a floor and a ceiling, so the policy cannot be pushed to something indefensible in either direction. The ceilings reflect a deliberate position — no more than about two years needs to be available at any one time — with visitor records the single documented exception, for schools carrying a longer duty on their register.