Home / Guides / WhatsApp and POPIA for law firms
WhatsApp and POPIA: what South African law firms may and may not do
POPIA does not prohibit a law firm from using WhatsApp with clients. It requires that you process what arrives there lawfully — which in practice means a written operator agreement with any vendor handling those conversations (section 21), reasonable security safeguards (section 19), a defensible position on special personal information (section 26), and a retention and deletion policy that you actually follow. Most firms fail on the operator agreement and on retention.
This is practice-management commentary, not legal advice. You are the lawyers; take your own view, and where a matter is genuinely contested, take counsel's.
Ask a room of South African attorneys whether WhatsApp is POPIA-compliant and you get two wrong answers. The first is "no, we shouldn't be using it" — usually from a firm that is using it constantly anyway, on personal handsets, with no policy. The second is "yes, it's encrypted" — which answers a question nobody asked.
The Act is not interested in the app. It is interested in what your firm does with personal information, wherever that information arrives. WhatsApp is simply the doorway through which a great deal of it now arrives unannounced, often carrying detail a client would never have put in a first email.
Why a first WhatsApp enquiry is a harder problem than an email
Consider what actually lands. A prospective client messages your firm's number at 22:40 and, in three messages, discloses: their name and number, that they were arrested on a specific date, the charge, the fact that they are on chronic medication, and their employer. Nobody has opened a file. No mandate exists. No consent has been obtained for anything.
You are now processing personal information — including special personal information under section 26, which covers health and criminal behaviour among other categories — for a person who is not yet your client, on a platform your practice does not control, quite possibly on an attorney's personal phone.
That is not a reason to abandon WhatsApp. It is a reason to have decided in advance how the firm handles it.
The four obligations that actually bite
1. Section 21 — the operator agreement
This is the one firms miss, and it is the least ambiguous provision in the Act. If a third party processes personal information on your behalf, without coming under your direct authority, it is an operator. POPIA requires a written contract between you and that operator, obliging it to establish and maintain the security measures set out in section 19.
"On your behalf" is broader than firms assume. It captures your intake or chatbot vendor, your CRM, your cloud practice-management provider, your transcription service, your outsourced switchboard. If a supplier can read your client conversations, you need the agreement. There is no de minimis exception and no version of this satisfied by clicking "I accept" on American terms of service drafted around GDPR.
The operator also has a standing duty to notify you immediately where it has reasonable grounds to believe personal information has been accessed by an unauthorised person. Your contract should say how, and how fast.
Practical test: list every supplier that can see a client conversation. For each, can you produce a signed operator agreement today? For most firms the honest answer is one or two out of six.
2. Section 19 — reasonable security safeguards
Section 19 requires appropriate, reasonable technical and organisational measures. The organisational half is where firms are weakest, because the technical half feels handled — WhatsApp encrypts messages in transit, so the box gets ticked.
The organisational questions are harder and more mundane:
- Whose phone is it? If intake runs through a candidate attorney's personal handset, the firm's client conversations leave when they do. A firm number, controlled by the firm, is the fix.
- Who can read the history? A shared business handset in reception means everyone reads everything, including the matters they have no business seeing.
- What happens on loss or resignation? Can you revoke access to two years of client chats within a day?
- Are cloud backups on? Automatic WhatsApp backup to a personal Google or iCloud account moves client information into a store the firm neither controls nor can wipe.
3. Section 26 — special personal information
Section 26 prohibits processing special personal information — including a person's health or sex life, religious or philosophical beliefs, race or ethnic origin, political persuasion, trade union membership, biometric information, and criminal behaviour — unless a section 27 authorisation applies.
For law firms the workable authorisations are usually consent, or that processing is necessary for the establishment, exercise or defence of a right or obligation in law. That second one covers a great deal of legitimate practice — it is, after all, the business you are in. But note when it starts applying. During pure intake, before a mandate exists and before you have decided to take the matter, the ground is thinner than it will be once you are on record.
The practical answer is not to interrogate a prospective client at 22:40. It is to collect only what intake needs — practice area, urgency, whether a deadline runs, the parties — and to leave the medical history for the consultation, where it belongs and where the basis for processing is clear.
4. Retention, and actually deleting things
POPIA requires that records not be retained longer than necessary for the purpose, subject to the statutory and professional retention obligations that apply to a legal practice. Two failure modes are common.
The first: the enquiry that went nowhere. Somebody messaged in March 2024, you never took the matter, and the conversation is still on a handset. There is no purpose being served, and no retention rule requiring it.
The second: the conversation that is part of the file but lives only on WhatsApp. If a client's instruction was given by message, that message is part of the record. It should be in the matter file, not in an app, where it is discoverable, auditable, and survives the phone.
What about privilege and confidentiality?
Legal professional privilege attaches to the communication, not the medium. Advice given over WhatsApp is no less privileged than advice given by letter. Your duty of confidentiality under the Legal Practice Act and the Legal Practice Council's Code of Conduct is likewise channel-agnostic.
What changes is the practical risk of losing control of the communication. The realistic threats are dull: a handset left in a car, a screen visible on a shared device, a chat forwarded to the wrong group, a departing employee walking out with the history. Privilege survives all of these. Confidentiality does not.
One point that deserves attention: the prospective client who is never taken on. Confidentiality obligations can attach to information received during an approach even where no mandate follows — which is exactly the material sitting in an unmanaged intake inbox. It is also precisely the material a conflict check later needs.
A compliance checklist you can work through this week
- Move intake off personal devices onto a firm-controlled business number.
- List every supplier that can read client conversations. Get a signed operator agreement for each, or stop using them.
- Turn off personal cloud backups on any device carrying client chats.
- Write a two-page WhatsApp policy: which number, who has access, what gets copied to the file, what gets deleted, what never goes on the platform.
- Set a retention rule for dead enquiries and enforce it — a date, not an intention.
- Copy substantive instructions into the matter file as a matter of routine.
- Confirm your Information Officer is registered with the Information Regulator.
- Limit what intake asks for. The best defence against holding special personal information you cannot justify is not collecting it at 22:40.
Where the penalties sit
POPIA carries administrative fines of up to R10 million and, for certain offences, imprisonment of up to ten years. In practice the realistic exposure for a mid-sized practice is not a headline fine — it is a data subject complaint, a Regulator enquiry that consumes a partner's month, and the professional embarrassment of explaining to a client that their conversation was on a former employee's phone.
The Regulator has shown it is willing to act, including against very large platforms. Firms that can produce a policy, a signed set of operator agreements and a retention rule are in an entirely different position from firms that can produce a shrug.
Automated intake makes this easier, if you contract it properly
There is a reasonable argument that a properly configured intake tool is more defensible than the status quo of chats on personal handsets. It runs on a firm number, applies the same collection limits to every enquiry, keeps a single auditable record, and lets you delete on a schedule rather than on a good intention.
That argument only holds if the vendor is contracted as an operator, tells you where the data sits, does not use your conversations to train public models, and lets you delete permanently. Ask for all four in writing. A vendor that hesitates on any of them has answered your question.
Intake that collects less, and files it properly
247clerk runs on your firm's own WhatsApp number, asks only what intake needs, files every conversation in one place you control, and will sign an operator agreement under POPIA on request.
Or read how to evaluate an AI receptionist for a SA practice.