South Africa
POPIA compliant practice software: what to check
POPIA puts duties on the practice and on the software company. Here is how to tell whether a system helps you meet yours, and where Reach + Within stands.
Updated 4 October 2026.
Information, not legal advice. This page is a practical overview for practices. It is not a substitute for advice on your own contracts, insurance or registration.
Search for “POPIA compliant EHR” or “POPIA compliant clinical notes software” and you will find many badges. A badge is not the point. POPIA puts duties on the practice, as the responsible party, and on the software company, as the operator that processes records on the practice’s behalf. Good software makes those duties easier to meet. No software meets them for you. This page is a checklist for what to ask, and it says plainly where Reach + Within stands.
This is information, not legal advice. Read the Act and the Information Regulator’s guidance for your own situation.
Who is responsible for what
Under POPIA, the practice decides why and how client information is processed. That makes the practice the responsible party. A software provider that stores and processes the record for you is an operator. The Act expects the operator to process the information only with the practice’s authorisation, to keep it confidential, and to have security measures in place under a written contract (sections 20 and 21). The practice still answers for the record.
Health information is special personal information under the Act (section 26). The rules on special personal information, and the authorisations for health professionals, are in sections 27 and 32. In everyday terms: the people who see the record should be the people treating the client, and you should be able to explain why anyone else could.
The checklist
Ask any vendor these questions, including us. Ask for the answers in writing.
- Where is client data hosted? Is that a single country, or does it move?
- If it leaves South Africa, what is the lawful basis for the transfer under section 72?
- Is there a written operator agreement, and does it describe security measures?
- Which sub-processors handle client data, such as transcription, email or hosting?
- Can admin and finance staff work without opening the clinical note?
- Is there an audit trail of who viewed or changed a record, and when?
- How are breaches reported to you, so you can notify the Regulator and the client under section 22?
- Can you export a full client record, and can you delete one when your retention period ends?
- What does the vendor claim about certification, and who issued it?
- Which security features are live today, and which are on a roadmap?
Question 9 matters because, as far as we know, the Information Regulator does not certify software products as “POPIA compliant”. If a vendor shows a certificate, ask who issued it and what it covered.
How Reach + Within answers
- Hosting: client data is hosted in the EU (Netherlands) for South African customers. The EU has data protection law that is relevant to the section 72 adequacy test. Your notice should still tell clients that their record is stored outside South Africa.
- Operator agreement: we act as your operator. A data processing agreement and our sub-processor list are available on request from info@reachwithin.app.
- Roles: PA, admin and accounts users can book and bill. They cannot open clinical notes.
- Audit trail: a record of who viewed or changed what, and when.
- Recording consent: the client’s recording choice is kept on their file, and recording follows it. Without consent, you write the note yourself.
- Family updates: a secure family report link shares an approved report, not the session note.
- Coming soon: sign-in with a second factor. It is not available yet, and we do not describe it as live.
- Certification: we do not claim a POPIA or HPCSA certification. Reach + Within is built to help you meet your obligations. Compliance also depends on how the practice uses it.
What stays with the practice
Software cannot write your privacy notice, choose your retention period or decide who may receive a report. Those decisions are yours.
- Register your information officer with the Information Regulator. In a solo practice, that is usually you.
- Tell clients in plain words what you record, why, where it is stored and who may see it.
- Record consent to any session recording separately from consent to therapy.
- Set a retention period that matches HPCSA Booklet 9. The figures quoted in the text we read are in how long to keep therapy records.
- Close a leaver’s login on their last day.
- Know who could export the record if the practitioner were suddenly unavailable.
The longer practical guide is POPIA and therapy notes. If you are choosing software for the whole practice, therapy practice management software in South Africa covers the wider job.
Price
Reach + Within is from R500 a month per clinician for therapists and group practices. Admin, finance and management users are free. Rehabs and treatment centres are quoted. Details are on South Africa pricing.
Related reading
POPIA software questions
Can software make a practice POPIA compliant?
No. Software can separate roles, log access and keep one secure record. Your notice, consent forms, retention period and habits are what make the practice compliant.
Is Reach + Within POPIA certified?
No, and we do not claim a certification. You remain the responsible party and we act as your operator. Client data is hosted in the EU (Netherlands).
Can client records be stored outside South Africa?
POPIA section 72 allows transfers in certain cases, including where the recipient is subject to law that gives adequate protection. Tell clients where the record is stored, and take advice on your own situation.
Try it with demo clients.
30 days free for therapists and group practices. No card needed. Move to real clients once the data agreement and consent are in place.