← Research

Compliance

POPIA and the Architecture of Consent

By IGT16 March 2026 at 00:004 minute read

Privacy regulation as an engineering constraint, not a legal afterthought.

Consent is a lifecycle

Consent should not be reduced to a checkbox. A system needs to record what a person agreed to, for which purpose, when, through which notice and how that choice can be changed.

POPIA compliance depends on context and should be reviewed with qualified legal and information-governance professionals. Architecture can support that work by making purposes, records and responsibilities visible.

Separate purposes and permissions

Avoid one broad flag for unrelated processing. Model distinct purposes and connect each one to the data, channel and retention rule it authorises. Make withdrawal effective across operational systems and downstream processors.

Collect only what is needed for the stated purpose. Access controls and audit records should show who used personal information and under which authority.

Design for accountability

Maintain current notices, processing records, retention schedules and incident procedures. Build ways to locate, correct, export or delete information when an authorised process requires it.

Test consent changes as end-to-end workflows. A preference that changes in the interface but not in messaging, analytics or exports is not an effective control.