The Protection of Personal Information Act (POPIA) has been fully enforceable in South Africa since July 2021. Despite this, the majority of South African small businesses are still not fully compliant. The risks are real: fines up to R10 million, reputational damage, and data subject claims. The good news is that for most SMEs, the compliance requirements are straightforward and achievable without a legal team.

Does POPIA apply to your business?

POPIA applies if your business:

That covers virtually every South African business. There is no size exemption, but the practical requirements are proportionate to your risk profile and the sensitivity of the data you process.

The eight POPIA conditions every business must meet

The practical POPIA checklist for SMEs

1. Register your Information Officer

Go to justice.gov.za and register your Information Officer with the Information Regulator. This is mandatory and free. The Information Officer is legally responsible for your POPIA compliance — for most SMEs, this is the business owner or MD.

2. Publish a privacy policy

Your website and any form that collects personal information must link to a clear privacy policy. It must explain: what you collect, why, how you store it, how long you keep it, and how data subjects can exercise their rights. Don’t copy a template — it must reflect your actual practices.

M.Y Tech Guys builds POPIA-compliant privacy policies and data subject request systems into every website we deliver. If your current site doesn’t have one, let’s fix that →

3. Audit your data collection

List every place your business collects personal information: contact forms, WhatsApp, email, paper, spreadsheets, point-of-sale, HR systems. For each: is there a clear business purpose? Is the data secured? Do you know where it’s stored? How long do you keep it?

4. Secure your data

Technical safeguards required under POPIA include:

5. Handle data subject requests

POPIA gives South Africans the right to: access their personal information, request correction of inaccurate data, object to processing, and request deletion. You need a process to receive and action these requests within a reasonable timeframe (typically 30 days).

6. Manage marketing consent

You may only send marketing communications to people who have consented. Existing customers can receive marketing on the same class of products/services they purchased (opt-out model), but new contacts require explicit opt-in. Keep records of consent.

POPIA and employee data

Employee personal information is also protected under POPIA. This includes payroll data, performance records, health information, and disciplinary records. Key requirements:

The cost of POPIA compliance technology

For most SMEs, the tech cost of POPIA compliance is modest:

Frequently asked questions

What happens if I get a data breach?

Under POPIA, you must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a breach. You should have a breach response plan before this happens — not after. Document the breach, its scope, and your response actions.

Can I use Google Forms or WhatsApp to collect customer data?

Yes, but with caveats. Google Forms data is stored on Google’s servers offshore — you need to ensure this is disclosed in your privacy policy and that Google’s data processing terms are compatible with your POPIA obligations. WhatsApp messages are end-to-end encrypted but WhatsApp/Meta has access to metadata.

Do I need a cookie banner on my South African website?

If your website uses cookies that track personal information (analytics, advertising, session tracking), yes — you need to disclose this and allow visitors to opt out of non-essential cookies. Basic session cookies required for the site to function are exempt.

Is sharing customer data with my accountant a POPIA issue?

Yes. Your accountant is an operator processing personal information on your behalf. You need a data processing agreement with them and should ensure they have adequate security measures in place.

Does POPIA apply to small businesses in South Africa?

Yes. POPIA applies to any person or organisation that processes personal information in South Africa, regardless of size. There is no SME exemption. However, the practical requirements are proportionate — a sole trader collecting customer emails has simpler obligations than a large enterprise handling sensitive health or financial data.

What is the penalty for POPIA non-compliance in South Africa?

The Information Regulator can issue fines of up to R10 million for POPIA violations. Criminal penalties include up to 10 years imprisonment for certain offences such as obstruction or unlawful processing of special categories of personal information. Civil claims from data subjects are also possible.

What is a POPIA Information Officer?

Every organisation that processes personal information in South Africa must have an Information Officer registered with the Information Regulator. For most businesses, this is the CEO, managing director or business owner. The Information Officer is responsible for ensuring POPIA compliance and handling data subject requests.

What does a POPIA-compliant website need?

A POPIA-compliant South African website must have: a privacy policy explaining what data is collected and why, a cookie consent mechanism if cookies track personal data, a clear data subject rights notice (right to access, correct, delete), a contact method for data requests, and secure data handling. Contact forms must not collect more information than necessary.


M.Y Tech Guys builds POPIA compliance into every website and system we deliver — privacy policies, cookie consent, secure data handling, data request workflows. Get a POPIA compliance assessment → or see POPIA tech services →