GUIDE

How to register an Information Officer.

Who it is, when to register, and the steps on the Information Regulator's portal.

Last reviewed: 7 October 2026

Who is the Information Officer?

Every business has one automatically. For a private business it is the head of the business: the chief executive, managing director, owner or equivalent. You do not choose whether to have one. You choose only whether the role stays with the head or is given to someone else.

The head can authorise another person to act as Information Officer. The Information Regulator's guidance is that this should be someone at management level inside the business. Deputy Information Officers can be designated in writing to share the work.

When must they be registered?

Before they take up their duties. Section 55(2) of POPIA says an Information Officer may only start once registered with the Information Regulator. If your business handles personal information and nobody is registered, do it now.

What to have ready

  • The registered name, registration number and type of business
  • Physical and postal addresses
  • The Information Officer's full name, role, phone number and email address
  • The same details for each deputy, if you are designating any
  • A signed authorisation, if the Information Officer is not the head of the business

The steps

  1. Go to the Information Regulator's website, inforegulator.org.za, and open the eServices portal.
  2. Create a profile for the business and verify the email address.
  3. Choose Information Officer registration.
  4. Complete Part A with the Information Officer's details and Part B for any deputies.
  5. Submit, then download the registration certificate and keep it with your compliance records.

Registration is free. The portal's layout changes from time to time; this is the sequence as at October 2026.

What the Information Officer has to do

  • Encourage and monitor the business's compliance with POPIA
  • Put a compliance framework in place and keep it working
  • Carry out a personal information impact assessment
  • Make sure the PAIA manual exists, is published and stays current
  • Set up a way to handle requests for access, correction and deletion
  • Run internal awareness sessions
  • Work with the Information Regulator during any investigation

After registering

  • Add the Information Officer's contact details to your PAIA manual and privacy notice.
  • Update the registration when the person or their details change.
  • Submit the annual PAIA report on the same portal. The window runs from 1 April to 30 June each year.
  • Work through the rest of the POPIA checklist.

This is practical guidance, not legal advice. For a legal opinion on a specific situation, speak to an attorney.

All guides

Free POPIA readiness assessment

A 60-minute, no-obligation review of your IT and compliance posture, with a written summary you keep — whether you work with us or not.

Book your assessment