A field service business can hold customer contact details, residential addresses, site photographs, technician locations and job histories across several systems. The practical privacy question is whether the people running the business can explain where that information goes, why it is needed, who can access it and what happens when something changes.
Start with those actual workflows instead of treating a consent checkbox or a software subscription as a complete compliance programme. This guide provides an operational review method for South African service businesses. It links authoritative sources for specific legal points and separates suggested working practices from statutory requirements. Your business still needs decisions appropriate to its activities, contracts and information; a product feature does not make those decisions for you.
Map one job from first enquiry to final archive
Choose a representative job and follow the information through its entire journey. Start with the enquiry, then identify where the customer details are entered, how the technician receives the site information, where photos are stored, how an invoice is sent and what remains after the job closes. Include the channels staff actually use, even if they are outside the official process.
Write down the people and systems involved at each handover. A dispatcher might copy an address from an email into a job card, while a subcontractor receives a message containing an access contact. A customer may then receive a document generated in another application. Each transfer is easier to review when it is visible in the map rather than assumed to be covered by the main software account.
Look for unnecessary duplication. An address saved in the job record, a personal contact list, a spreadsheet and a group chat can be difficult to update consistently. The aim is not to eliminate every copy without understanding its purpose. It is to choose the intended working record and make the exceptions deliberate, controlled and understandable to staff.
Distinguish a processing purpose from a consent checkbox
Section 11 of POPIA provides several possible grounds for processing, including consent and specified alternatives. It is therefore inaccurate to say that every customer or employee processing activity always depends on consent. Identify the applicable basis for the actual activity; a device permission, customer service request or staff acknowledgement should not be treated as a universal legal answer.
For the operational review, describe each purpose in concrete language. “Send the assigned technician to the customer's address” is easier to evaluate than “business purposes”. “Provide a customer with an invoice for this job” describes a different activity from “send a future promotional campaign”. Separating the activities makes it easier to ask the right questions before information is reused.
Keep the explanation staff give people consistent with the process. If a notice says location is used for dispatch, review whether a manager is also using it for a different assessment. If a form requests information that nobody needs for the stated workflow, ask why the field exists. A small, accurate explanation is more useful than a broad statement nobody checks against actual behaviour.
Inventory the information the team handles
Create a working inventory with an owner for each category. Use plain names such as “customer contact details”, “job photos” or “technician location records”. Describe the systems where they are stored and who needs them. The inventory should help an administrator find information and a manager decide what should happen next; it need not become a large technical document before it is useful.
Include less obvious locations. Downloaded reports, exported customer lists, device galleries, email attachments and messages to subcontractors can contain the same information as the main application. Ask staff about their normal exceptions, such as sharing a site address when reception is weak or taking a photo before opening the job. Those details reveal where a written procedure may differ from real work.
| Information category | Useful operational question | Example of a review action |
|---|---|---|
| Customer contact details | Which details are needed for this service relationship? | Remove unnecessary form fields and identify the working record |
| Job-site information | Who needs the address, contact and access arrangements? | Limit distribution to the people involved in the attendance |
| Job photographs | What does each image contribute to the work record? | Review unnecessary people, unrelated rooms and private details |
| Technician location | Which defined activity requires location information? | Review collection states, manager access and staff explanations |
| Financial records | Which accounting obligations and processes apply? | Confirm retention and archive decisions with the responsible adviser |
| Exports and attachments | Where do copies go after leaving the application? | Define approved storage and a cleanup process |
Give each person access appropriate to their work
Review access using real tasks rather than job titles alone. A dispatcher may need to assign work across the team, while a technician needs the site details for their assigned visit. A person preparing invoices may need financial information that another colleague does not. Write down those differences before selecting roles or granting broad administrative access for convenience.
Test the permission with a representative account. Confirm what the user sees in the list, the detail page, search results, downloads and shared links. Hiding a menu item is not the same as restricting access to the underlying record. In a software evaluation, demonstrate both the action the user should perform and a nearby action they should be unable to perform.
Keep account changes part of the normal staff process. Decide who removes access when a person leaves, changes role or stops working on a contract. Include shared devices and exported copies in that discussion. A deactivated account is useful, but it does not automatically retrieve files already copied into a personal folder or a separate communication tool.
Explain technician location use before enabling it
Location information needs a clear operational explanation. Describe what is collected, when collection occurs, which staff can view it and what question the business intends to answer. Separate a technician's site-arrival record from an ongoing location trail, because they can have different functions and different implications for the person being monitored.
Review the technical behaviour on the actual devices and settings. Test clocked-in and clocked-out states, background and foreground operation, device permission changes and loss of connectivity. Do not publish a promise that tracking happens only in one state unless you have verified that behaviour in the deployed setup. Recheck it when the app or device configuration changes.
Discuss the proposed monitoring arrangement with the people affected and obtain appropriate employment and privacy advice for the circumstances. Record how questions, objections and errors will be handled. Avoid presenting one signed form as a permanent answer to every later use of the data. If the business changes the purpose or intensity of monitoring, review the arrangement again rather than relying on an old acknowledgement.
Make job-photo instructions specific and practical
Tell field staff what a useful job photo should communicate. The subject might be a reported defect, an agreed work area or a completed repair. Ask them to include enough context for the next authorised reviewer while avoiding unrelated people, documents, possessions and access details. This is a practical capture standard, not a claim that any particular photograph is automatically lawful or appropriate.
Review the customer-facing selection separately from the internal job record. A picture that helps a technician understand an issue may include information unnecessary for a customer handover or a third-party quotation. Check the intended recipient and purpose before forwarding a complete gallery. Use the application's supported visibility controls where available and verify the resulting view from the recipient's account.
Plan how mistakes are reported. If an image was attached to the wrong job or contains information that should not have been captured, staff need a clear correction route. Record enough context for the responsible person to assess the issue. Quietly renaming a file or deleting a local copy may not address material that has already been uploaded or shared.
Set retention by record category and actual obligation
POPIA section 14 addresses retention and includes circumstances in which records may be kept. It does not prescribe one universal field-service retention period. Avoid publishing a blanket rule such as “all GPS data must be kept for ninety days” or “every job photograph must be retained for three years” without a justified policy for the actual activity. See the Act's retention provisions.
Financial records require their own assessment. SARS describes a common five-year period measured from submission of a return, alongside other situations and extensions. This is not a general instruction to delete every business record after five years, and it does not support a blanket claim that SARS requires seven years for all job records. Use the current SARS record-keeping guidance when preparing the accounting part of your schedule.
Build the schedule with a record category, purpose, applicable obligation, trigger date, review owner and disposal process. Identify exceptions that need a hold or professional review. Treat operational photos, raw location information and financial documents as separate categories unless there is a reason to manage them together. A documented schedule is useful only if someone can explain how it is applied in each system.
Test disposal and backup behaviour before promising it
Ask the supplier what a deletion action actually does. It may remove a record from the active interface while related logs, backups or exported copies follow different processes. Clarify restoration, archive and backup handling before telling a customer that all copies disappear immediately. Record the supplier's documented answer and the parts your own staff control.
Use a synthetic example to test your normal disposal workflow. Identify the record, perform the authorised action and check the relevant application views and access paths. If the system uses soft deletion or a recovery window, understand that distinction. Do not test by removing live customer evidence or financial records merely to see what happens.
Connect disposal to staff routines. An old export left in a downloads folder can outlive the carefully maintained application record. Define who reviews working copies and how exceptions are handled. Where a legal, accounting or dispute-related question affects disposal, escalate it to the appropriate person before taking an irreversible action.
Review suppliers and information handovers
List the services involved in the customer journey, including hosting, email, file storage, messaging, payments and analytics where relevant. Ask what each service receives and which functions depend on it. A work-order platform may coordinate the process while several providers handle particular parts. Your review should reflect that arrangement rather than assuming every item remains inside one database.
For processing performed by an operator, POPIA section 21 addresses written contractual security requirements. Cross-border transfers are separately addressed in section 72. Use those statutory provisions to inform a supplier review with appropriate advice. Hosting in South Africa alone does not establish complete compliance, and an overseas service is not assessed solely by the presence of a foreign address.
Prepare questions the supplier can answer concretely. Request the applicable agreement, subprocessors or service dependencies, support contact and explanation of access, deletion and incident handling. Record which answers are documented and which are still assumptions. A marketing phrase such as “secure cloud” is not a substitute for understanding the service you plan to use.
Keep service messages and marketing workflows separate
Create a clear internal distinction between messages needed to manage a job and messages intended to promote future business. A booking update, quotation discussion and promotional campaign can use similar channels but have different purposes. Do not let a convenient export of service contacts silently become the default audience for every campaign.
POPIA section 69 contains specific rules and exceptions for unsolicited electronic direct marketing. Review that section and the Information Regulator's POPIA resources before defining a campaign process. A past customer relationship does not justify ignoring the applicable conditions, and a simple statement that all marketing always needs fresh consent would also miss the statutory detail.
Operationally, keep the source and status of a marketing preference understandable. Make it clear who updates it and how an objection or unsubscribe reaches the relevant sending systems. Test the process with an internal example. Stopping a campaign in one tool is insufficient if a separate list is later imported with the old preference unchanged.
Create a usable process for information requests
Choose a monitored contact route for privacy-related questions and make sure the staff receiving them know where to send them internally. A customer might ask for a correction during an ordinary support conversation rather than using the exact wording of a formal request. The team needs to recognise the issue and preserve it for the responsible person.
Practise locating a synthetic customer's information across the systems in your map. Include linked jobs, contacts, invoices, photos and relevant correspondence. Check the requester's identity and authority through an appropriate process before disclosing records. The exercise should reveal where information is duplicated or associated with another person, not encourage indiscriminate export of everything that matches a name.
Record the handling decision and who made it. Some material may involve another individual, an accounting obligation or a restriction that needs review. Staff should not promise immediate deletion or release of every file without checking the circumstances. A repeatable handover to the responsible person is more reliable than leaving each technician or administrator to improvise a response.
Prepare an incident response before a device is lost
Choose who coordinates the first response when a phone is lost, a document is sent to the wrong recipient or an account appears compromised. Keep that contact accessible to field staff. Ask them to report what happened, when they noticed it and which job or account may be involved, without requiring them to decide the legal significance first.
The Information Regulator's security-compromise guidance explains the responsible party's notification role, including compromises at an operator. Use its current guidance and reporting process when assessing an incident. Do not copy a generic foreign deadline into your POPIA procedure or wait for perfect information before consulting the appropriate responsible person.
Practise containment steps that are safe for your setup: removing a lost device's account access, preserving relevant records and contacting the supplier through the agreed channel. Document what was actually done and verified. Avoid destroying potential evidence during an improvised cleanup or assuming a password change has recalled documents already downloaded elsewhere.
Use a small review register with clear ownership
Turn the findings into actions with an owner, a next step and evidence of the outcome. Start with the issues that expose the wrong records, leave former staff with access or make incident reporting unreliable. Give each action a concrete finish condition. “Improve privacy” is difficult to verify; “confirm a disabled technician cannot retrieve the previous customer's photos” is testable.
| Review area | Practical evidence to collect | Person to assign |
|---|---|---|
| Data map | One complete job journey with systems and recipients | Operations lead |
| Access | Role-based trial results and staff-change procedure | Account administrator |
| Photos and location | Written purposes and observed device behaviour | Field operations lead |
| Retention | Reviewed category schedule and documented exceptions | Information officer with relevant advisers |
| Suppliers | Applicable agreements and written service answers | Business owner or procurement lead |
| Requests and incidents | A practised intake, escalation and response workflow | Designated privacy contact |
Evaluate software against the process you intend to run
Use separate dispatcher, technician and customer-facing accounts in a trial. Check the records each account can list, open, download and update. Include one reassignment, a disabled account and a wrongly addressed sharing attempt using synthetic data. Verify the behaviour rather than relying on a feature label or a screenshot of a permission setting.
WorkOrderPro can be evaluated as part of this wider operating process. Review its security information, privacy notice, job-photo workflow and the access behaviour of the actual product. Ask for clarification on requirements that are not demonstrated. Do not describe a trial, consent control or private-file feature as a certification of your business's compliance.
Frequently asked questions
Does buying field-service software make our business POPIA compliant?
No. Software can support access, records and operational controls, but the business still needs decisions and practices suited to its processing. Evaluate the product alongside your purposes, staff training, supplier arrangements, retention decisions and response procedures. Avoid treating a vendor's general assurance as proof that every business workflow is appropriate.
Does technician GPS tracking always require consent?
Do not assume one legal basis applies to every monitoring arrangement. Review the particular activity, employment context and applicable requirements with appropriate advice. Explain the actual collection and use clearly, test device behaviour and provide a route for questions. A phone permission prompt is not a complete assessment of the arrangement.
Is there a universal ninety-day rule for GPS records?
This guide does not propose one. Decide and document retention for the actual purpose and obligations, then verify the system's behaviour. Keep raw trails distinct from information needed in an enduring job record. Do not promise automated deletion after a fixed period without confirming the deployed process and its exceptions.
Must we keep every job photograph for the same period as an invoice?
Treat the categories separately during review. They can have different purposes, obligations and risks. Establish a justified schedule and identify cases needing a hold or professional assessment. An invoice retention rule should not automatically become a reason to retain every unrelated image captured during the same visit.
Are job photos harmless if they do not show a face?
Review the full context. An image linked to a residential address or customer record may reveal private details even without a visible person. Give staff practical capture instructions and review the recipient-facing selection. The absence of a face is not a reliable shortcut for deciding whether material needs careful handling.
Can technicians use a shared login?
Individual accounts make it easier to manage role access, remove a departing person's access and understand who performed a recorded action. If a shared device is necessary, test account switching and local-data handling. Avoid treating a shared password as the default solution to a device or subscription planning problem.
What should happen when a customer asks for their information?
Route the request to the designated person, verify identity and authority appropriately, and locate the relevant records through your documented process. Review material involving other people or competing obligations before responding. Keep a record of the handling decision instead of asking field staff to improvise an export from their phones.
What is a useful first step for a small service company?
Map one real job journey, using a synthetic copy for tests, and identify where customer and technician information is stored or shared. Assign owners to the clearest gaps. This produces a practical starting point for supplier questions, staff instructions and professional advice without pretending that one checklist completes the whole compliance exercise.