POPIA compliance checklist for small business
POPIA is not just for banks and hospitals. If you hold customer names, email addresses, staff records or supplier details - and every business does - the Act applies to you. Here is what compliance actually looks like for a small South African business, without the consultant fog.
Who POPIA applies to
The Protection of Personal Information Act applies to anyone who processes personal information in South Africa: companies, sole traders, NPOs, landlords, schools. "Processing" means almost anything - collecting, storing, emailing, sharing, even deleting. If you have a customer list, an employee file or a WhatsApp group of client numbers, you are processing personal information and POPIA applies. There is no small-business exemption.
The regulator is the Information Regulator, which handles complaints, investigates breaches and can issue enforcement notices and fines. Serious offences carry criminal liability. In practice, the Regulator's attention lands first on businesses that leak data or spam people who opted out.
The practical checklist
- 1. Know what you hold. List the personal information in the business: customers, staff, suppliers, marketing lists, CCTV, website analytics. You cannot protect what you have not mapped, and this list drives everything else.
- 2. Privacy policy. A plain-language notice telling people what you collect, why, who you share it with, and how they can access or correct it. It belongs on your website and in your onboarding paperwork. It must describe what you actually do, not what a template imagines you do.
- 3. PAIA manual. A separate document required under the Promotion of Access to Information Act, describing your business and how someone can request records from it. Every private body must have one available; the Regulator publishes a template format.
- 4. Information officer. By default this is the business owner or CEO. The information officer must be registered with the Information Regulator through its registration portal before the business starts hiding behind "we didn't know". Registration is free.
- 5. Consent for direct marketing. Electronic marketing (email, SMS, WhatsApp) to new prospects requires consent, and every message needs a working opt-out. Existing customers may be marketed to about similar products, but the opt-out rule still applies. Bought lists are where most POPIA trouble starts.
- 6. Security safeguards. Reasonable measures for your size: password management, access limits, backups, POPIA clauses in contracts with anyone who processes data for you (your bookkeeper, your email platform, your IT support).
- 7. Breach procedure. If personal information is accessed or acquired by an unauthorised person, you must notify the Information Regulator and the affected people as soon as reasonably possible. Decide now who does that and how, because a breach is the wrong day to start planning.
Realistic first steps
Do not try to do everything in one weekend. A sensible order for a small business: map your data, publish a privacy policy and PAIA manual, register the information officer, then clean up your marketing lists and tighten passwords and access. That covers the visible obligations and the highest-risk gaps. Ongoing compliance after that is mostly discipline: collect only what you need, keep it only as long as you need it, and honour opt-outs immediately.
Frequently asked questions
Does POPIA apply to small businesses?
Yes. POPIA applies to any business that processes personal information, regardless of size. A one-person consultancy with a client list has the same core duties as a corporate: lawful processing, a privacy policy, an information officer and reasonable security.
What documents do I need for POPIA compliance?
At minimum: a privacy policy, a PAIA manual, consent wording for marketing, and POPIA clauses in contracts with service providers who handle your data. Larger or higher-risk businesses add internal policies for retention, security and breach response.
Do I need to register with the Information Regulator?
You register your information officer, not the business as such. The information officer (by default the owner or CEO) must be registered on the Information Regulator's portal before performing their duties. Registration is free and done online.
What are the penalties for breaching POPIA?
The Regulator can issue enforcement notices, and offences can lead to fines or, for the most serious offences, imprisonment. The more immediate costs are practical: reputational damage after a breach, complaints from spammed customers, and remediation under Regulator scrutiny.
Get the documents done for you
The POPIA Starter pack gives you the privacy policy, PAIA manual and information officer setup for a flat R890.
View the POPIA StarterKeep exploring
Free tools are estimates. Packs are templates and guidance, not legal or financial advice.