POPIA for Crèches: What You Must Do, Plus a Parent Consent Form (South Africa)
If your crèche or ECD centre keeps children's records, POPIA applies to you. This plain-language guide explains what the law expects and gives you a parent consent form you can adapt today.
Updated August 2026 · General information, not legal advice. Adapt the template to your centre and check with a professional or the Information Regulator if you are unsure.
Does POPIA apply to crèches and ECD centres?
Yes. POPIA (the Protection of Personal Information Act 4 of 2013) applies to any crèche, preschool or ECD centre in South Africa that collects and stores personal information about children, parents and staff. Because you handle children's and health information, POPIA asks for extra care, clear consent and secure record-keeping. The Act has been fully enforceable since 1 July 2021.
Why does POPIA give children's and health information extra protection?
Children's personal information gets special protection under sections 34 and 35 of POPIA, and health or medical details are special personal information under section 26. A crèche holds both, so the law treats your records as high-risk. As a rule you may not process this information without a lawful basis, such as the written consent of the child's parent or guardian.
Under POPIA a child is anyone under 18 who cannot act on their own behalf without help, and a competent person is the parent or legal guardian entitled to consent for that child. That is why consent for a crèche comes from a parent or guardian, not the child.
What must a crèche do to comply with POPIA?
POPIA sets eight conditions for handling personal information lawfully. In practice a crèche must have a lawful basis (usually consent), collect only what it needs, use the information only for the stated purpose, keep it accurate, be open about what it does, store it securely, delete it when it is no longer needed, and respect parents' rights over their child's data.
The eight conditions in the Act are:
- Accountability — someone in the centre is responsible for POPIA compliance.
- Processing limitation — collect lawfully, minimally, and with a proper basis such as consent.
- Purpose specification — collect for a clear, stated reason and do not keep records longer than needed.
- Further processing limitation — do not later use the information for something unrelated.
- Information quality — keep records accurate and up to date.
- Openness — tell parents what you collect and why.
- Security safeguards — keep the information safe.
- Data subject participation — let parents see, correct and delete their child's information.
What is your lawful basis for collecting a child's information?
Your main lawful basis is the prior written consent of a competent person — the parent or legal guardian entitled to consent for the child. Under POPIA, consent must be voluntary, specific and informed, so a parent should know exactly what you collect, why, and who you share it with. Keep the signed consent on file for as long as you hold the records.
Consent is not the only possible basis. Some processing is allowed because it is needed to meet a legal duty — for example, records you must keep for the Department of Social Development or Department of Basic Education. Even then, being open with parents is good practice.
How much information can a crèche collect?
Only collect what you genuinely need to care for the child and run the centre — no more. POPIA's minimality rule means every field on your enrolment form should have a clear purpose. Collect the child's details, health and emergency information, and parent contacts. Avoid gathering extra data just in case you might use it one day.
How should a crèche store and secure children's records?
POPIA (section 19) requires appropriate, reasonable technical and organisational measures to keep records safe. In a small centre that means locking paper files in a cabinet, password-protecting phones and laptops, limiting who can see records, and backing up your data. If you use software, choose a provider that encrypts and backs up information. Review your safeguards regularly as risks change.
Practical daily habits that help:
- Keep enrolment files locked away, not on an open shelf or reception desk.
- Use a password or PIN on any device that holds children's information.
- Only give staff access to the records they actually need.
- Never share children's details over WhatsApp groups or social media.
- Shred old paper records instead of throwing them in an open bin.
How long can a crèche keep a child's information?
Keep records only as long as you need them for the purpose you collected them, or as long as another law requires. When a child leaves and there is no legal reason to keep the file, delete or destroy it so it cannot be reconstructed. Set a simple retention rule — for example, review and clear old files a set period after a child exits.
Who can a crèche share a child's information with?
Share children's information only with people who have a lawful reason to see it, and tell parents up front who that is. Typical recipients include your own staff, the Department of Social Development or Basic Education, and emergency medical services. Do not post photos or share a child's details publicly or with any third party without specific consent from the parent.
What rights do parents have over their child's information?
Acting for their child, parents can ask what information you hold, request corrections, and ask you to delete information you no longer need. They can withdraw consent and complain to the Information Regulator. Respond to these requests within a reasonable time, and keep a short note of the request and how you resolved it.
What must a crèche do if children's data is lost or leaked?
If records are lost, stolen or accessed unlawfully — a stolen laptop, a hacked account, a misplaced file — POPIA (section 22) says you must notify the Information Regulator and the affected parents as soon as reasonably possible. Tell them what happened, the likely consequences, what you are doing about it, and what they can do to protect themselves.
Does a crèche need an Information Officer?
Yes. Every organisation has an Information Officer, and by default it is the head of the centre — usually the owner or principal. You must register your Information Officer with the Information Regulator before they act, using the Regulator's registration portal. This person makes sure the centre follows POPIA and handles parents' requests and any complaints.
Parent consent form template for a crèche (POPIA)
Below is a plain-language POPIA consent clause a small centre can add to its enrolment form. It covers the child's and parents' information, health and medical details, photographs, and emergency contacts, with separate opt-ins for photos. Adapt the wording to your centre and, where you can, have it checked by a professional before you use it.
Protection of Personal Information (POPIA) consent
[Centre name] ("the Centre") collects and uses personal information about your child and your family in order to enrol and care for your child, keep them safe and healthy, communicate with you, meet our legal duties, and administer fees. We keep this information secure, use it only for these purposes, and do not share it with anyone else without your consent, unless the law requires it.
Information we collect: your child's full name, date of birth, ID or birth-certificate number, home address and photograph; your child's health, medical, allergy and dietary information; the names, contact numbers, ID numbers and addresses of parents or guardians; and the names and numbers of nominated emergency contacts and authorised pick-up persons.
Your consent
By signing below, I confirm that I am the parent or legal guardian of the child named in this form, and that I am entitled to give consent on the child's behalf. I have read and understood how the Centre will use this information, and I give my voluntary, specific and informed consent to the following:
- ☐ I consent to the Centre collecting and storing my child's and my family's personal information for the purposes described above.
- ☐ I consent to the Centre collecting and using my child's health, medical, allergy and dietary information to care for my child and respond to emergencies.
- ☐ I consent to the Centre contacting my nominated emergency contacts and releasing my child only to the authorised persons I have listed.
- ☐ I consent to the Centre sharing relevant information where required by law or with medical personnel in an emergency.
Photographs and media (please tick each choice)
The Centre sometimes takes photographs or short videos of activities. Your choices here are optional and will not affect your child's place at the Centre.
- ☐ I consent to photographs/videos of my child being used inside the Centre (for example, classroom displays and your child's own progress record).
- ☐ I consent to photographs/videos of my child being shared privately with me (for example, on a parent app or private group).
- ☐ I consent to photographs/videos of my child being used in the Centre's marketing, including its website and social media.
- ☐ I do not consent to any photographs or videos of my child being used.
Your rights
You may ask to see the information we hold about your child, ask us to correct or delete it, or withdraw your consent at any time by contacting our Information Officer at [name, email, phone]. Withdrawing consent will not affect processing we have already done, or information we must keep by law. You may also complain to the Information Regulator of South Africa.
Child's full name: [__________________________]
Parent/guardian name: [__________________________]
Signature: [________________] Date: [____________]
Zande is South African software built by a crèche owner. Its online enrolment captures POPIA consent at sign-up, keeps learner records, health notes and emergency contacts in one place, and stores everything securely with encrypted backups — so the consent, the minimal-data habit and the secure storage this guide describes are built into how you run the day, from R99/month. This article is general information, not legal advice; adapt the template to your centre and check with a qualified professional or the Information Regulator if you are unsure.