POPIA compliance checklist for small business

POPIA is not just for banks and hospitals. If you hold customer names, email addresses, staff records or supplier details - and every business does - the Act applies to you. Here is what compliance actually looks like for a small South African business, without the consultant fog.

Who POPIA applies to

The Protection of Personal Information Act applies to anyone who processes personal information in South Africa: companies, sole traders, NPOs, landlords, schools. "Processing" means almost anything - collecting, storing, emailing, sharing, even deleting. If you have a customer list, an employee file or a WhatsApp group of client numbers, you are processing personal information and POPIA applies. There is no small-business exemption.

The regulator is the Information Regulator, which handles complaints, investigates breaches and can issue enforcement notices and fines. Serious offences carry criminal liability. In practice, the Regulator's attention lands first on businesses that leak data or spam people who opted out.

The practical checklist

Realistic first steps

Do not try to do everything in one weekend. A sensible order for a small business: map your data, publish a privacy policy and PAIA manual, register the information officer, then clean up your marketing lists and tighten passwords and access. That covers the visible obligations and the highest-risk gaps. Ongoing compliance after that is mostly discipline: collect only what you need, keep it only as long as you need it, and honour opt-outs immediately.

Frequently asked questions

Does POPIA apply to small businesses?

Yes. POPIA applies to any business that processes personal information, regardless of size. A one-person consultancy with a client list has the same core duties as a corporate: lawful processing, a privacy policy, an information officer and reasonable security.

What documents do I need for POPIA compliance?

At minimum: a privacy policy, a PAIA manual, consent wording for marketing, and POPIA clauses in contracts with service providers who handle your data. Larger or higher-risk businesses add internal policies for retention, security and breach response.

Do I need to register with the Information Regulator?

You register your information officer, not the business as such. The information officer (by default the owner or CEO) must be registered on the Information Regulator's portal before performing their duties. Registration is free and done online.

What are the penalties for breaching POPIA?

The Regulator can issue enforcement notices, and offences can lead to fines or, for the most serious offences, imprisonment. The more immediate costs are practical: reputational damage after a breach, complaints from spammed customers, and remediation under Regulator scrutiny.

Get the documents done for you

The POPIA Starter pack gives you the privacy policy, PAIA manual and information officer setup for a flat R890.

View the POPIA Starter

Keep exploring

Free tools are estimates. Packs are templates and guidance, not legal or financial advice.