POPIA for crèches & preschools

Your centre holds some of the most sensitive personal information there is — children's records. Here's what POPIA expects, and how Kindi helps you treat that data like it matters.

🔐 Encryption at rest

Sensitive fields — medical details, ID numbers, banking details — are encrypted in the database, not stored as plain text in a spreadsheet on a laptop.

🧾 Access audit trail

Kindi records who viewed and changed children's records, so "who accessed this child's file?" has an answer.

🗑 Deletion requests

Parents can request account deletion from inside Kindi, supporting POPIA's erasure principles without email archaeology.

📄 PAIA manual & consent

Kindi publishes a PAIA manual, uses opt-in analytics consent, and keeps parent communication preferences explicit.

Honest note: Kindi is POPIA-aware tooling, not a compliance certificate — responsibility for your school's compliance stays with you. But good tooling makes the right thing the easy thing.

Frequently asked questions

Does POPIA apply to a small crèche?

Yes. Any organisation processing personal information in South Africa falls under POPIA — and crèches hold especially sensitive data about children and families.

How does Kindi help?

Encryption at rest for sensitive fields, an access audit trail, deletion requests, and a published PAIA manual.

What happens to our data if we leave?

You can request an export of your school's data, and deletion removes personal information in line with POPIA's erasure principles.