TL;DR: South Africa’s Information Regulator has moved into an active enforcement phase for 2026-2027, with a new compliance monitoring programme requiring organisations, including universities, to demonstrate POPIA compliance through documentation and governance processes, not just policy statements. For survey and feedback data specifically, that means an Information Officer, a documented lawful basis, and de-identification practices built into the survey workflow itself.
Quick takeaways
- The Information Regulator’s 2026-2027 priorities include a structured compliance monitoring programme, moving beyond reactive complaint handling.
- Research surveys involving personal information need documented compliance under POPIA’s research-specific guidance, developed with ASSAf and endorsed by the ASSAf Council in 2025.
- Surveys involving anyone under 18 require particular care, POPIA classifies children’s data for special protection with explicit parental consent requirements.
- De-identification and pseudonymisation at the survey design stage reduce compliance burden far more effectively than retrofitting it after collection.
Why 2026 is a different compliance environment
POPIA has been fully enforceable since July 2021, but South Africa’s Information Regulator confirmed in March 2026 that it is entering a more structured, proactive enforcement phase for the 2026-2027 financial year, moving from reactive complaint handling to targeted oversight and industry-wide assessments, with a new compliance monitoring programme requiring documented evidence, not just stated policy. For universities running continuous student, staff, and alumni feedback programs, that shift changes what “compliant” needs to mean in practice: documented process, not just good intentions.
Appoint and empower an Information Officer for research data
Every institution processing personal information needs a registered Information Officer, but for survey and research programs specifically, that role needs practical authority over feedback system design, not just policy sign-off after the fact. The Information Officer should be involved when a new survey program is designed, not only when a complaint or breach occurs.
Use the ASSAf POPIA Compliance Framework for research
The Academy of Science of South Africa, working with the Department of Science and Innovation and South African universities, developed a POPIA Compliance Framework for Researchers and Research Institutions specifically because general POPIA guidance didn’t translate cleanly into research contexts. Formally endorsed by the ASSAf Council in May 2025, the framework covers prior authorisation requirements for special personal information, cross-border data sharing limits, and sector-specific interpretation that a general compliance policy typically misses. Universities running feedback and research surveys should map their process directly against this framework rather than relying on a generic corporate POPIA checklist.
Build de-identification into survey design, not analysis
The practical pattern that holds up under audit:
- Classify before you build. Decide at the design stage whether the survey needs to collect any personally identifying field at all, or whether the research question can be answered with de-identified data from the start.
- Separate identity from response. Where identification is needed (for longitudinal tracking, for example), store identifying information separately from response data with restricted access, rather than in the same dataset.
- Pseudonymise for analysis. Analysts working with response data should generally work from pseudonymised records, with the identity key held separately and accessed only when genuinely required.
Special care for surveys involving minors
POPIA applies particular protection to data belonging to children, relevant for any university running outreach surveys with prospective students under 18, open day feedback forms, or school partnership research. Explicit parental consent, clear purpose limitation, and restricted retention windows apply, and these requirements don’t relax just because the survey is framed as informal outreach rather than formal research.
What this looks like at institutional scale
QuestionPro’s work with HEITSA and South African higher education institutions established a data architecture approach built around exactly this kind of documented, auditable compliance model, procurement pathway, governance structure, and technical controls aligned to South African regulatory expectations rather than adapted from a generic global template. As enforcement tightens, institutions without a documented POPIA process for research data face materially higher exposure than those with one already in place.
Talk to us about POPIA-aligned survey infrastructure for your institution.
Frequently asked questions
Does POPIA apply to internal university surveys, not just external research?
Yes. Any processing of personal information, including internal course evaluations, staff pulse surveys, and student feedback, falls under POPIA if the data can identify an individual, regardless of whether the survey is framed as “research” or routine operations.
What changed with POPIA enforcement in 2026?
The Information Regulator introduced a structured compliance monitoring programme for 2026-2027, moving from reactive complaint-based enforcement to proactive, documented oversight, meaning institutions need demonstrable compliance evidence, not just a stated policy.
Do surveys of prospective students under 18 need special handling?
Yes. POPIA classifies children’s personal information for special protection, generally requiring explicit parental or guardian consent, tighter purpose limitation, and shorter retention windows than adult survey data.



