The Protection of Personal Information Act (POPIA) has been fully enforceable in South Africa since July 2021. Despite this, the majority of South African small businesses are still not fully compliant. The risks are real: fines up to R10 million, reputational damage, and data subject claims. The good news is that for most SMEs, the compliance requirements are straightforward and achievable without a legal team.
Does POPIA apply to your business?
POPIA applies if your business:
- Collects names, email addresses, phone numbers or any other personal information from customers or employees
- Stores personal information on computers, servers, cloud systems or even paper files
- Uses personal information for marketing, service delivery or HR purposes
That covers virtually every South African business. There is no size exemption, but the practical requirements are proportionate to your risk profile and the sensitivity of the data you process.
The eight POPIA conditions every business must meet
- Accountability — Appoint an Information Officer and register with the Information Regulator (free, takes 10 minutes online at justice.gov.za).
- Processing limitation — Only collect personal information you actually need for a clear, lawful purpose.
- Purpose specification — Tell people why you’re collecting their data at the time of collection.
- Further processing limitation — Don’t use data for a purpose that’s incompatible with why you collected it.
- Information quality — Keep personal information accurate and up to date.
- Openness — Have a privacy policy and notify people of what you do with their data.
- Security safeguards — Protect personal information with reasonable technical and organisational measures.
- Data subject participation — Allow people to access, correct or request deletion of their personal information.
The practical POPIA checklist for SMEs
1. Register your Information Officer
Go to justice.gov.za and register your Information Officer with the Information Regulator. This is mandatory and free. The Information Officer is legally responsible for your POPIA compliance — for most SMEs, this is the business owner or MD.
2. Publish a privacy policy
Your website and any form that collects personal information must link to a clear privacy policy. It must explain: what you collect, why, how you store it, how long you keep it, and how data subjects can exercise their rights. Don’t copy a template — it must reflect your actual practices.
M.Y Tech Guys builds POPIA-compliant privacy policies and data subject request systems into every website we deliver. If your current site doesn’t have one, let’s fix that →
3. Audit your data collection
List every place your business collects personal information: contact forms, WhatsApp, email, paper, spreadsheets, point-of-sale, HR systems. For each: is there a clear business purpose? Is the data secured? Do you know where it’s stored? How long do you keep it?
4. Secure your data
Technical safeguards required under POPIA include:
- HTTPS on your website (SSL certificate)
- Strong password policies and two-factor authentication for systems with personal data
- Encrypted storage for sensitive categories (health, financial, biometric data)
- Access controls — staff should only access data they need for their role
- A data breach response plan (who you notify, how quickly — POPIA requires notification within a reasonable time)
5. Handle data subject requests
POPIA gives South Africans the right to: access their personal information, request correction of inaccurate data, object to processing, and request deletion. You need a process to receive and action these requests within a reasonable timeframe (typically 30 days).
6. Manage marketing consent
You may only send marketing communications to people who have consented. Existing customers can receive marketing on the same class of products/services they purchased (opt-out model), but new contacts require explicit opt-in. Keep records of consent.
POPIA and employee data
Employee personal information is also protected under POPIA. This includes payroll data, performance records, health information, and disciplinary records. Key requirements:
- Employee contracts should reference POPIA and explain how their data is used
- Payroll systems must have appropriate access controls
- Health information (sick notes, medical aid claims) must be stored separately with restricted access
- CCTV footage is personal information if individuals can be identified — retention policies required
The cost of POPIA compliance technology
For most SMEs, the tech cost of POPIA compliance is modest:
- POPIA compliance website build: R8,000 – R30,000 (privacy policy, cookie consent, data request forms, secure contact forms)
- HR system with POPIA controls: included in MYWorkSuite Business at R1,750/month
- POPIA audit and gap assessment: R8,000 – R20,000 once-off
Frequently asked questions
What happens if I get a data breach?
Under POPIA, you must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a breach. You should have a breach response plan before this happens — not after. Document the breach, its scope, and your response actions.
Can I use Google Forms or WhatsApp to collect customer data?
Yes, but with caveats. Google Forms data is stored on Google’s servers offshore — you need to ensure this is disclosed in your privacy policy and that Google’s data processing terms are compatible with your POPIA obligations. WhatsApp messages are end-to-end encrypted but WhatsApp/Meta has access to metadata.
Do I need a cookie banner on my South African website?
If your website uses cookies that track personal information (analytics, advertising, session tracking), yes — you need to disclose this and allow visitors to opt out of non-essential cookies. Basic session cookies required for the site to function are exempt.
Is sharing customer data with my accountant a POPIA issue?
Yes. Your accountant is an operator processing personal information on your behalf. You need a data processing agreement with them and should ensure they have adequate security measures in place.
M.Y Tech Guys builds POPIA compliance into every website and system we deliver — privacy policies, cookie consent, secure data handling, data request workflows. Get a POPIA compliance assessment → or see POPIA tech services →