NCA & POPIA Compliance Checklist for Legal Collections
A practical National Credit Act (NCA) and Protection of Personal Information Act (POPIA) compliance checklist for South African law firms running debt recovery: Section 129 notices, consent records and audit trails.
By Debtcol Pro · 15 May 2026
General guidance only, not legal advice. Consult your compliance officer or attorney for advice on your specific matters.
This checklist does not imply guaranteed POPIA or NCA compliance and does not replace professional legal or compliance review.
Compliance in legal collections isn't a single checkbox. It's the steady, file-by-file discipline of being able to prove — months or years later — that you followed the National Credit Act (NCA) and protected the debtor's personal information under the Protection of Personal Information Act (POPIA).
Use the checklist below as a quick scan of your current files. Any item you can't answer "yes" to in under 30 seconds is a risk worth fixing this quarter. Debtcol Pro is collections management software for South African law firms and agencies; this checklist is written to help teams evaluate their current operational discipline, whatever platform they use.
Section 129 notice basics
- Notice delivered to the debtor's chosen address per the credit agreement.
- Proof of delivery (registered mail track-and-trace, signed receipt, or e-mail acknowledgement) stored against the matter.
- Notice issued at least 10 business days before summons.
- Wording aligned with the latest case law — not a template last reviewed in 2018.
POPIA: lawful processing of debtor data
- The lawful basis for processing each debtor's data is recorded (usually contract or legal obligation).
- Only data necessary for collection is stored — no over-collection of "nice to have" fields.
- Third-party tracers and credit bureaus are covered by an operator agreement.
- Debtors have a documented channel for access, correction and complaint requests.
Audit trail per matter
- Every letter, SMS and call is logged with a timestamp and operator.
- Document versions are retained — not overwritten — so the trail is reconstructable. Spreadsheet-based files fail this test by default — see the spreadsheets-vs-software comparison.
- Payment allocations and fee entries reconcile to the trust ledger.
- Closed matters are archived with retention periods that match POPIA and Financial Intelligence Centre Act (FICA) rules.
Communication compliance
- Contact attempts respect reasonable hours and frequency.
- Scripts and templates are reviewed annually by compliance, not just by the collections team.
- Recordings or transcripts of debtor calls are stored securely and access-controlled.
Reporting & oversight
- Partners can pull a compliance report per matter in minutes, not days.
- Exceptions (missed notices, overdue follow-ups, complaints) surface automatically.
- A designated Information Officer is registered and accountable.
If any of these are still living in spreadsheets, email threads or "Sarah's head", the firm is carrying risk it doesn't need to. The fix is almost always operational — better systems, not more rules. If that means shortlisting new software, our collections software buyer's guide for South Africa sets out the eight evaluation criteria.
Related guides
All resources →Your next step
Ready to control your collections process?
Book a 30-minute demo and we'll show you exactly where your firm is leaking revenue — and how to plug it.
