HomeBlogYour WhatsApp Messages Are Records You Must Keep for Five Years

Your WhatsApp Messages Are Records You Must Keep for Five Years

Agents sit under POPIA, FICA and the Property Practitioners Act at once. Two of them demand you keep things POPIA would otherwise have you delete.

General information, not legal advice, and not reviewed by a lawyer. FICA and the Property Practitioners Act attach to your registration and are enforced by the Financial Intelligence Centre and the PPRA, so check anything here with your principal or compliance officer before relying on it.

Three clocks, and only one of them is POPIA

Most businesses reading about POPIA are told to delete what they no longer need. A property practitioner who does that enthusiastically can breach two other statutes.

And "property practitioner" is wider than it sounds. The Act's definition reaches well past estate agents to bond originators and brokers, auctioneers, bridging finance providers, home inspectors, commercial brokers, property developers, homeowners' associations, anyone managing property for remuneration, and fractional title and timeshare businesses. If you are in that list, everything below is about you too, even though the page says agents throughout.

You sit under three regimes at once:

  • POPIA, where section 14 says do not keep records longer than necessary for the purpose, unless another law authorises or requires retention.
  • FICA, because a property practitioner is an accountable institution under Schedule 1 of the Financial Intelligence Centre Act. Client due diligence records must be kept for five years.
  • The Property Practitioners Act 22 of 2019, whose section 55 and Regulation 40 require practitioners to keep mandates, mandatory disclosure forms, agreements and marketing material for five years.

The three do not actually conflict, because section 14 anticipates exactly this. But you cannot apply POPIA's instinct to minimise without knowing which records the other two have locked down. Our general guide to how long to keep customer data assumes no sector rule. Yours has two.

The rule almost nobody is complying with

The Property Practitioners Act goes further than mandates and agreements. Regulation 40, read with section 55 of the Act, requires a practitioner to retain copies of all electronic communications sent to or received from members of the public in the course of carrying on business as a property practitioner. Where the firm employs other practitioners, their communications with the public are caught too.

Read that against how the industry actually works. Negotiations happen on WhatsApp. Offers are discussed on WhatsApp. Access arrangements, condition queries, the entire relationship with a buyer or tenant frequently lives in a thread on an agent's personal handset.

Those are electronic communications with members of the public in the course of your business. The obligation does not care that the channel is informal.

Two consequences follow, and they pull against each other:

  • You have a retention problem. When an agent leaves the agency, or changes phone, or clears a chat, business records that a statute requires you to hold for five years have gone.
  • You have a POPIA problem. Those same messages contain a great deal of personal information about buyers, sellers and tenants, sitting on a personal device with no access control, no deletion schedule and no security you can describe under section 19.

The practical answer is a business messaging setup rather than personal handsets, with an export or archive. The regulation expressly permits electronic storage where it meets the requirements of the Electronic Communications and Transactions Act, so an archive is a compliant answer rather than a workaround. It is a real cost, and a smaller one than being unable to produce records to the PPRA. The channel-specific POPIA issues, including why adding clients to a group is a disclosure, are in WhatsApp Business and POPIA.

Your FICA basis is not consent, and this matters

Agencies routinely ask clients to "consent" to FICA verification, and put it on the same form as everything else. That mischaracterises what you are doing.

Section 11 of POPIA lists several grounds for processing, and consent is only one. Where you collect an identity document, proof of address and source of funds because the Financial Intelligence Centre Act obliges you to, your ground is compliance with an obligation imposed by law. Not consent.

The distinction is not academic. Consent under POPIA can be withdrawn at any time. If you told a seller their FICA documents were held on the basis of their consent, and they withdraw it mid-transaction, you have promised something you cannot deliver: you are not permitted to stop holding those records, because FICA requires them for five years.

Say it accurately instead. You collect these documents because the law requires it, you keep them for five years because the law requires that too, and neither is a choice you or the client can make. That is a stronger position and an easier conversation.

Consent still does real work elsewhere in your business, which is the next two sections.

The show day register

Every visitor writes down a name, a phone number and usually an email address. Some agencies then add all of it to a mailing list.

Two separate purposes are being run through one clipboard. Collecting details for access control and security at a show house is straightforward and defensible. Marketing to those people afterwards is direct marketing under section 69, and it needs its own basis.

Someone who wrote their number down to be let into a house has not agreed to a newsletter, and section 13 does not allow you to quietly widen the purpose after the fact. Nor does the existing customer exception in section 69(3) help: a visitor at a show day is not yet a customer, and you did not obtain their details in the context of a sale to them.

The fix is a tick box on the register with its own wording, unticked, that says what you will send and how to stop it. Get that right and the resulting list is worth more anyway, because the people on it chose to be there. See section 69 and direct marketing.

The same applies to enquiries from a portal. A buyer who asked about one property has asked about one property.

Tenant screening

Rental agents run credit checks, and this is one of the few places in an agency where consent is doing the real work rather than a statutory obligation. Credit bureau information sits under the National Credit Act as well as POPIA: a bureau may only release consumer credit information for prescribed purposes, and in practice will require the consumer's permission before running an enquiry. We could not establish that the Act itself spells out a written-consent requirement for tenant screening specifically, so treat written consent as the defensible practice rather than a box the statute names. It is what the bureaux ask for, and under POPIA it is the cleanest ground available to you.

Four things worth doing:

  • Get the consent in writing, specifically for the credit check, and not bundled into a general application-form signature.
  • Collect what the decision needs. An application form asking for marital status, religion, number of children or a photograph is collecting more than a tenancy decision requires, and section 10 is the minimality condition.
  • Be careful what you record about the reason for a refusal. A note on file speculating about someone's circumstances is personal information you created, and they can ask to see it.
  • Delete the unsuccessful applicants. The five year rules above attach to concluded business. A stack of rejected applications with ID numbers and payslips in it is pure liability with no purpose.

Photographs of somebody's home

A listing photograph of an occupied house is not just a picture of a building. Family photographs on the wall, medication on a counter, a child's name on a bedroom door, the make and position of the alarm panel, what is in the garage.

You have a mandate to market the property. That is not the same as authority to publish details about the people living in it, and the seller's permission does not cover the tenant currently in occupation.

Practically: ask before photographing an occupied home, give occupants a chance to move personal effects, and look at the image before it goes up rather than after. This is also plain risk management, since listing photographs are a known reconnaissance tool.

Portals, CRMs and conveyancers

Your systems process a lot of other people's information, and the relationships are not all the same.

  • Your CRM, cloud storage and messaging provider are operators. They process on your behalf, so section 21 requires a written contract with each, obliging them to keep the section 19 safeguards and to tell you about unauthorised access.
  • Much of it is offshore. Property software and cloud storage frequently sit outside South Africa, which makes it a transborder flow under section 72 as well. See cross-border transfers.
  • The conveyancing attorney is a harder question. An attorney exercises independent professional judgement and owes their own duties, which points towards them being a responsible party in their own right rather than your operator. That changes what paperwork is appropriate, so it is worth settling with the firms you work with rather than assuming either answer.

One more, because it is where the money goes missing: sending banking details by email is the single largest fraud risk in this industry, and a compromised mailbox is also a reportable security breach under section 22. Verify account details by voice on a number you already had, every time.

The paperwork you are supposed to have

Two documents that agencies commonly lack:

  • A PAIA manual. Every private body needs one, and an agency is a private body. See PAIA manual requirements.
  • A registered Information Officer. By default the head of the business, registered with the Information Regulator.

Your privacy notice should also say the honest thing about retention: that certain records are kept for five years because FICA and the Property Practitioners Act require it. That is a better answer to "why do you still have my ID copy" than anything vaguer.

A short checklist

  • Where do your agents' client WhatsApp conversations live, and could you produce them in three years?
  • When an agent leaves, do the records leave with them?
  • Does your FICA paperwork describe the basis as legal obligation rather than consent?
  • Does the show day register have its own unticked marketing option?
  • Is credit check consent separate and in writing?
  • Does your tenant application ask for anything the decision does not need?
  • Are unsuccessful applications deleted on a schedule?
  • Do you look at listing photographs for other people's personal information before publishing?
  • Do you have signed operator agreements with your CRM and storage providers?
  • Do you have a PAIA manual and a registered Information Officer?

POPIA Ready generates a privacy policy, a PAIA manual and five other documents customised to your agency, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at September 2026, not legal advice. Property practitioners sit under POPIA, FICA and the Property Practitioners Act at once, non-compliance with the latter two can affect your Fidelity Fund Certificate, and your compliance officer or attorney should confirm anything here against your own procedures.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →

Your Patient Records Sit Under Three Laws, Not One

Read article →