NewRevised White Paper on immigration: what is policy and what is already law.

Read the guide
A corridor of black server racks with blue patch cables in a clean data centre
Pexels (free licence)
POPIA and PAIA

POPIA Compliance Checklist for Small Businesses (2026)

A practical POPIA compliance checklist for South African small businesses. The 12 things you need to actually do, not just the 200 things big consultants will sell you.

POPIA, the Protection of Personal Information Act, has been fully in force since 1 July 2021. The Information Regulator has been actively issuing enforcement notices since 2023. For small businesses, the question is no longer "should we comply?" but "what do we actually need to do?"

The honest answer: most small businesses can become genuinely POPIA-compliant in two to three weeks of effort, not the multi-month "compliance projects" that large consultancies sell. Here's a practical checklist of what actually matters.

What POPIA actually requires

POPIA applies to anyone who processes personal information of identifiable people. "Processing" includes collecting, storing, using, disclosing, and destroying information. "Personal information" includes obvious things (names, ID numbers, contact details) and less obvious things (IP addresses, employment history, medical conditions, biometric data, opinions about people).

The Act sets out 8 conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Every condition has practical implications. Below are the 12 things most small businesses actually need to do.

The checklist

1. Designate an Information Officer (and register them)

By default, the Information Officer is the head of your organisation: the CEO, MD, or sole director. You can delegate the function to someone else (your COO, your legal counsel, an external service provider), but the responsibility legally remains with the head.

Action: Decide who your Information Officer is. Register them with the Information Regulator at inforegulator.org.za. Registration is free and takes 10 minutes. Without registration, you fail the first condition (accountability).

2. Map your personal information

You need to know what personal information you hold, where it's held, who has access, and why. Most small businesses haven't done this exercise.

Action: List every system, file, spreadsheet, email folder, and physical record where personal information lives. For each, note: what data, whose data, why you have it, who has access, and how long you keep it. This becomes your data inventory.

A practical shortcut: your data inventory typically includes customer records, employee records, supplier records, financial records, marketing lists, and analytics.

3. Publish a privacy policy

Your privacy policy is the public-facing document that tells data subjects what you collect, why, how long, and their rights. It must be accessible (typically a link in the footer of every webpage) and written in plain language.

Action: Publish a POPIA-aligned privacy policy. Don't copy a US/EU template; POPIA has SA-specific requirements (Information Officer details, complaint procedure to the Information Regulator, specific data subject rights). We provide a customised website privacy policy for R299.

4. Set up consent capture

Where you rely on consent for processing (typically marketing communications, sometimes profile data) you need to capture that consent in a way that proves it later. Pre-ticked checkboxes don't work. Bundled consent (one checkbox for "marketing AND analytics AND service updates") doesn't work.

Action: Audit every form on your website where you collect personal information. For each, decide whether the processing requires consent (marketing usually does) or relies on another lawful basis (contract, legal obligation, legitimate interest). Update the form copy and capture mechanism accordingly. Store consent records, typically in your CRM or marketing automation tool, with timestamp and version of the consent text.

5. Set up subject access request handling

Data subjects have the right to ask you to confirm, free of charge, whether you hold personal information about them, and to request the record or a description of that information, subject to any prescribed fee (section 23). They can also ask you to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or to destroy a record you are no longer allowed to keep (section 24). POPIA does not give a general right to have everything erased on demand. They have the right to object to certain processing. You have 30 days to respond to a request.

Action: Document the process for handling subject access requests. Who receives them (typically info@yourdomain or a dedicated email), how they're routed, who fulfils them, what the timeline is, and how the response is delivered. For most small businesses, a one-page internal SOP is sufficient. You may receive very few requests, but you must be able to respond when they come.

6. Set up breach response

Section 22 of POPIA sets no harm threshold. Where there are reasonable grounds to believe that personal information has been accessed or acquired by any unauthorised person, you must notify the Information Regulator, and the affected data subjects unless a data subject cannot be identified, "as soon as reasonably possible". POPIA doesn't define a hard deadline (unlike GDPR's 72 hours) but courts will look at what's reasonable.

Action: Document a breach response procedure. Who do you notify internally? How do you assess severity? What's the communication template? Who signs off on notifying the Regulator and data subjects? Again, a one-page SOP is fine. Most breaches you'll experience will be minor (a misdirected email, a lost laptop) but you need a process in place.

7. Set retention rules

You can only keep personal information as long as necessary for the original purpose, unless retention is required by another law (FICA, SARS retention rules, sector regulators). After that, you must delete or anonymise.

Action: For each data category in your inventory, set a retention period. Common defaults: accounting records, annual financial statements and company registers: seven years (Companies Act 71 of 2008, section 24); records of time worked and remuneration: three years from the date of the last entry (BCEA, section 31); marketing lists: until the data subject opts out; analytics: 12 months. If you are an accountable institution listed in Schedule 1 to FICA, section 23 of that Act requires the related records to be kept for at least five years from the date the business relationship ends or the transaction is concluded. Tax records are governed separately under the Tax Administration Act, so confirm the SARS position for your entity. Set calendar reminders or automate the deletion where possible.

8. Lock down access

POPIA requires you to take "reasonable" technical and organisational measures to protect personal information. The standard is contextual: what's reasonable for a R5m turnover business is different from what's reasonable for a R5bn turnover business.

Action minimum baseline: Use HTTPS on your website (Let's Encrypt is free). Use strong passwords plus 2-factor authentication for any system holding personal data. Encrypt laptops and mobile devices that may contain personal information. Limit access to personal data on a need-to-know basis. Use cloud services that publish their security certifications (ISO 27001, SOC 2). For most small businesses, this is sufficient for "reasonable" compliance.

9. Vendor and processor agreements

When you use third-party services that process personal data on your behalf (your CRM, your email marketing tool, your cloud accounting software), POPIA requires you to have a written agreement (Data Processing Agreement, or DPA) with them. Most major providers (Google Workspace, Xero, MailChimp, Cloudflare) publish their DPAs at standard URLs you simply accept.

Action: List every third-party service that handles personal data. For each, find and accept their DPA. Document this in your data inventory. For small unknown providers without published DPAs, ask them, and if they don't have one, switch providers.

10. Train your team

If you have staff who handle personal information, they need to know what POPIA requires of them. This doesn't mean a 4-hour seminar. It means a 30-minute briefing, a one-page summary they can refer to, and a process for asking questions when something unusual comes up.

Action: Brief your team. Cover: what counts as personal information, the basic rules (don't share unless authorised, don't keep beyond the retention period, escalate breaches immediately), how to handle a subject access request, who the Information Officer is. Repeat annually.

11. Marketing-specific rules

POPIA has specific rules for direct marketing by electronic means (email, SMS, automated calling). Section 69(3) lets you market to an existing customer about your own similar products or services without separate consent, but only if you obtained their contact details in the context of a sale and you gave them a reasonable opportunity to object, free of charge, both when you collected the details and on every marketing message since. For everyone else you need prior consent, with one narrow exception: section 69(2) allows you to approach a person once to ask for that consent, provided they have not previously withheld it, and the request must be made in the manner and form prescribed in the POPIA Regulations.

Action: Audit your marketing list. Confirm that everyone on it either consented to marketing or is an existing customer being marketed about similar products. Confirm your unsubscribe mechanism works. Confirm your privacy policy describes your marketing practices accurately.

12. PAIA Manual

Section 51(1) of the Promotion of Access to Information Act requires the head of every private body to compile a PAIA Manual. A private body includes a natural person carrying on a trade, business or profession in that capacity, a partnership, and any juristic person. The Minister did previously exempt many smaller private bodies from this duty, but that exemption ran only until 31 December 2021. The Information Regulator's PAIA Guide states that from 1 January 2022 every private and public body must have its PAIA Manual available. There is no turnover threshold.

Action: Compile a PAIA Manual and make it available on your website, at your principal place of business for inspection during normal business hours, and to the Information Regulator on request. Section 51(1) of PAIA sets out what it must contain, and since the amendment that took effect on 30 June 2021 it must also cover the POPIA-related information. The Information Regulator publishes a free PAIA Manual template for private bodies on inforegulator.org.za. Our PAIA and Information Officer support service includes a PAIA manual template for R990.

What you don't need to do (despite what consultants will tell you)

  • A 50-page "POPIA compliance manual" that nobody reads.
  • Quarterly compliance audits.
  • Re-papering every contract you've ever signed.
  • A standalone Data Protection Officer (Information Officer is sufficient and is typically your existing leadership).
  • Encryption of every database (TLS in transit and reasonable cloud-provider encryption at rest is sufficient for most small businesses; full disk encryption is good practice but not legally mandated).
  • Annual penetration testing (good practice for businesses handling sensitive data, not a POPIA requirement for general small businesses).
  • Cyber insurance (sensible to consider, not required by POPIA).

Cost and time estimate

A small business doing this themselves: 2 to 3 weeks of focused effort, mostly people-time. Direct cost can be under R1,000 (Information Officer registration is free, privacy policy can be done with a R299 template, training can be done internally).

A small business outsourcing the documentation: R699 for the document bundle, plus internal time on the policy and training implementation.

A small business that wants a guided assessment with gap analysis and remediation roadmap: R2,990 with our POPIA readiness assessment, including an implementation call.

The point is: POPIA compliance is achievable for any small business. It does not require a six-figure budget. The risk of non-compliance is real (R10m maximum penalty, plus civil claims), but the cost of compliance is very manageable when you focus on what actually matters.

If you want to start with the documents, our POPIA bundle covers the privacy notice, website privacy policy, data-subject request procedure, incident-response checklist, operator agreement template and a retention and access-control checklist for R699. If you want a deeper look, the R2,990 readiness assessment delivers a gap report and priority action plan. Pick what fits your situation.

Important: This resource is general information, not personalised legal advice. Check current official instruments and the facts of your matter before acting.