POPIA Compliance: A Practical Data Protection Checklist for SA Businesses

Many South African business owners still think of POPIA as something for banks, hospitals and call centres. It isn't. If your business has a website with a contact form, a quote request, an email newsletter signup, an online checkout, or even a standard analytics tool, you are processing personal information and POPIA applies to you. There is no small-business exemption.
The good news is that compliance is mostly about discipline, not budget. Almost none of it requires new software. What it requires is that a handful of decisions get written down, given an owner, and reviewed. Below is a checklist you can work through in order, with a clear line between what the Act actually obliges you to do and what is simply good practice that makes the obligations survivable.
POPIA covers more of your data than you think
Two things surprise most people the first time they look properly.
The first is how wide "personal information" runs. It is not just ID numbers and addresses. It includes email addresses, telephone numbers, location data and online identifiers; employment, financial, medical and education history; biometric data, which catches the fingerprint clock at the workshop door; someone's personal opinions and preferences; private correspondence; and a person's name wherever it appears alongside anything else that identifies them. Your CCTV footage, your recruitment inbox, your support tickets and your payroll exports are all in scope.
The second is that POPIA protects juristic persons as well as natural ones. Your B2B customer list is personal information. A supplier company can lodge a complaint or object to processing in the same way an individual can. If you have been treating "we only deal with businesses" as a reason POPIA doesn't apply, that reasoning does not hold.
It is also worth being clear on your role. For your own customer, staff and supplier data you are the responsible party — accountable for everything that happens to it, including what happens to it inside somebody else's system. Suppliers who process that data on your instruction, from a payroll bureau to a cloud backup provider, are operators. Both roles carry duties, and they are different duties.
If your instinct is to reach for what you know about GDPR here, resist it. POPIA has eight named conditions rather than GDPR's principles, no general right to erasure and no right to data portability, no 72-hour breach clock, and no adequacy list for cross-border transfers. Mapping a GDPR programme straight onto POPIA reliably produces gaps.
The eight conditions, in plain terms
Chapter 3 of the Act sets out eight conditions for lawful processing. They are named and numbered in the Act itself, so it pays to learn them in that order rather than in GDPR's.
| # | Condition | Sections | What it means for you |
|---|---|---|---|
| 1 | Accountability | s8 | Someone is answerable for compliance, at design time and every day after. In practice: a registered Information Officer and a compliance framework that is actually operated. |
| 2 | Processing limitation | ss9–12 | Collect only what you need, on one of six named lawful grounds, and collect it directly from the person unless a listed exception applies. |
| 3 | Purpose specification | ss13–14 | Every collection has a specific, stated purpose, and you keep the data only as long as that purpose (or a law or contract) justifies. |
| 4 | Further processing limitation | s15 | Reusing data for a new purpose is only allowed if the new purpose is compatible, or falls inside a short closed list. "It's a legitimate business purpose" is not on that list. |
| 5 | Information quality | s16 | Reasonable steps to keep the data complete, accurate, current and not misleading — proportionate to what the data is used to decide. |
| 6 | Openness | ss17–18 | Documented processing operations (discharged through your PAIA manual) and a privacy notice at every point where you collect. |
| 7 | Security safeguards | ss19–22 | Appropriate, reasonable technical and organisational measures, plus written contracts with operators and a breach notification duty. |
| 8 | Data subject participation | ss23–25 | People can ask what you hold, ask for it, and ask you to correct or delete it — and you must have a way to answer. |
Everything below is those eight conditions turned into work.
Step 1: Register an Information Officer
Obligation. Every organisation that processes personal information must register an Information Officer with the Information Regulator, and registration is required before the officer takes up duties. Registration is free, and it is a requirement in its own right rather than a formality — an unregistered Information Officer is a gap on the face of it.
Two details catch people out. First, the Information Officer is the head of the organisation by law — the owner, MD or CEO. You do not get to appoint a junior "data protection officer" instead. You can designate a Deputy Information Officer to do the hands-on work, in writing and also registered, but delegating does not shift accountability off the head of the body.
Second, registration gates everything downstream. Breach notifications are submitted through the Regulator's eServices portal, and you cannot submit one if the organisation and its Information Officer are not registered on that portal already. Registering on the morning you discover a breach is not a plan.
If you have not done this, do it before anything else on this list.
Step 2: Build a processing register
Good practice that every obligation depends on. POPIA's openness condition is discharged through your PAIA manual rather than through a GDPR-style Article 30 register, but in practice you cannot write the manual, answer an access request, or defend a lawful ground without a working inventory first.
Get these down in writing, one row per processing activity:
- What personal information you collect (customer records, employee files, marketing lists, CCTV, applicant CVs, copies of IDs).
- Why you collect it, stated as a specific purpose, not "business operations".
- On what lawful ground — one ground per activity, not four listed in case.
- Where it lives: on-premises servers, laptops, cloud platforms, third-party SaaS, mailboxes, backups.
- Who can see it, inside the business and outside it.
- How long you keep it, and what drives that period.
This exercise usually surfaces uncomfortable surprises: old spreadsheets of client data in a shared drive, ID documents kept indefinitely "just in case", a marketing tool nobody remembers signing up for. Trim what you don't need. Data you don't hold can't be breached, and it can't be requested.
Also an obligation: a PAIA manual, published on your website and available at your principal place of business, with Information Officer details that match your registration exactly. Small bodies are not exempt from this.
Step 3: Name a lawful ground for each activity
Obligation. POPIA gives six grounds for processing: consent; necessity for a contract with the data subject; compliance with a legal obligation; protection of a legitimate interest of the data subject; performance of a public law duty; and the legitimate interests of you or a third party you supply.
Defaulting to "consent" for everything is the worst possible choice — consent is the only ground where the burden of proving it sits squarely on you, and it can be withdrawn. Paying an employee is contract. Keeping tax records is legal obligation. Sending an invoice reminder is not a consent question at all. Reserve consent for the cases that genuinely need it, notably electronic direct marketing, and keep the evidence: timestamp, the exact wording shown, and the channel.
You should also collect directly from the person wherever practicable. Buying or scraping a contact list falls foul of this, and the exceptions that permit indirect collection are specific — record which one you are relying on.
Step 4: Fix your privacy notice, and put it everywhere you collect
Obligation. A compliant notice tells the person what you collect and, where it wasn't collected from them, the source; who you are; the purpose; whether supplying the information is voluntary or mandatory and what happens if they refuse; any law requiring the collection; whether the information leaves the country and what protection it has there; who receives it; and their rights to access, correction, objection and complaint to the Regulator. The right to object is an easy clause to leave out — check that yours carries it.
The other frequent failure is placement. A notice on the website does nothing for the paper application form at reception, the onboarding pack, the job advert, the CCTV signage or the call script. Every collection point needs one.
Step 5: Write a retention schedule and actually delete
Obligation. You may not keep personal information longer than necessary for the purpose, unless a law, a contract, your own documented lawful purpose, or the person's consent justifies it. Once retention is no longer justified, the record must be destroyed, deleted or de-identified as soon as reasonably practicable, in a way that prevents reconstruction.
Two practical warnings. One blanket period for everything, because that is the period you were once told applies to accounting records, is not a schedule — the driver has to match the record class. And deletion in the live application is not deletion. Backups, DR replicas, mail archives, SIEM indexes, exports sitting in someone's Downloads folder and copies held by your suppliers are all records. Your deletion process needs to reach them or say, in writing, why it cannot.
Step 6: Get written operator agreements in place
Obligation. Where a third party processes personal information on your behalf, the Act requires a written contract obliging that operator to establish and maintain the same security measures you owe under section 19, and the operator must notify you immediately if it has reasonable grounds to believe data has been accessed or acquired by an unauthorised person. That duty to have the contract sits on you, not on the supplier.
Make a list of every supplier that touches personal information — payroll bureau, accounting practice, marketing agency, CRM, backup provider, hosting, help desk tooling, any offshore support. For each, confirm there is a signed agreement covering security measures, confidentiality, the immediate-notification duty, flow-down to their own sub-processors, where the data physically sits, and cooperation with access and correction requests.
This is the point where POPIA and commercial reality meet: your clients are increasingly running the same review on you. Getting your own third-party risk management into shape closes a real compliance gap and makes you easier to buy from. If you are starting from nothing, our guide to managing third-party vendor risk sets out a review process that fits an SME's budget.
Cross-border transfers deserve their own line in the register. If a supplier stores your data outside South Africa, you need a named basis for that transfer, and South Africa has no adequacy list to lean on — the assessment is yours to make and document.
Step 7: Make your security measures evidenced, not assumed
Obligation. Section 19 requires "appropriate, reasonable technical and organisational measures", and then, unusually, spells out a cycle: identify all reasonably foreseeable internal and external risks; establish and maintain safeguards against those risks; regularly verify that the safeguards are effectively implemented; and keep them updated as new risks and deficiencies appear. You are also expected to have due regard to generally accepted information security practice for your sector.
The last two are the easiest half to let slide, and they are not optional — the section requires the safeguards to be verified and kept up to date, not merely put in place. Expired security licences, controls nobody checked, a risk register written once and never revisited — a control that exists on paper but has never been tested is not a control that will hold up.
At a working minimum for an SME, that means multi-factor authentication on email and business systems, patched and monitored endpoints, encrypted backups with a restore you have actually tested, access restricted so staff see only what their role requires, and logs kept long enough to be useful. Then the evidence layer: a risk register with owners, patch and vulnerability reports, periodic access reviews, and a record of what changed after each review. This is where managed cybersecurity services from a security-first MSSP earn their keep, because the verification half of the cycle is continuous work rather than a project with an end date.
If you are in a regulated sector, check what your regulator expects on top of POPIA — financial services firms in particular now face South Africa's tightened cyber rules alongside their POPIA duties.
Step 8: Have a procedure for data subject requests
Obligation. On adequate proof of identity, a person can ask you to confirm free of charge whether you hold their information, and then request the record or a description of it — including the identity of the third parties, or categories of third parties, who have had access. That last part is only answerable if Step 2 and Step 6 are done. They can also request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or destruction of a record you are no longer entitled to keep. You must notify the person of the outcome of a correction or deletion request in writing, within the period the Regulations prescribe — confirm the current period and the required form with your attorney before you write your procedure.
Two things POPIA does not give people: a general right to erasure, and data portability. Do not promise either in your privacy notice.
Requests must be free to lodge and accepted through ordinary channels — by hand, post, email, SMS and WhatsApp among them — with telephonic requests recorded. Log every request, its classification, the clock, the outcome and proof that you responded.
Step 9: Get direct marketing consent right
Obligation. Unsolicited electronic direct marketing requires the person's consent, and you may only ask once. The narrow exception is for existing customers whose details you obtained in the context of a sale, for your own similar products or services, with a clear opt-out on every message. An opt-out mechanism is not consent, and offering one does not create it.
"Electronic communication" is capable of being read more widely than email and SMS, and the safer working assumption is that the other electronic channels you use to reach people are in scope too. If your growth plan depends on cold outbound, plan for the wider reading rather than the narrow one.
Practically: keep proof of consent, maintain a suppression list that is honoured across every tool, and stop processing when someone objects.
Step 10: Prepare for a security compromise before you have one
Obligation. Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, you must notify the Information Regulator and the affected data subjects. Note what is absent: there is no low-risk exemption and no 72-hour deadline. The standard is as soon as reasonably possible after the discovery — which in a bad week is a tighter constraint than a fixed clock, not a looser one.
Notification to the Regulator is submitted through its eServices portal rather than by email, which is why Step 1 matters so much. Notification to affected people must be in writing, by a prescribed method, and must describe the possible consequences, the measures you have taken or intend to take, what the person can do to protect themselves, and the identity of the unauthorised person if you know it. An internal all-staff email does not discharge the duty.
Write the plan now, while nobody is shouting: who declares an incident, who makes the call on whether it is a compromise, who submits the notification, who speaks to affected customers, who speaks to the media. If you are an operator for someone else's data, your duty is to notify them immediately — they carry the duty to notify the Regulator.
A self-audit you can run this week
Work down this list and mark each one honestly. Anything you cannot evidence counts as a no.
- Our Information Officer is registered with the Information Regulator, and we can produce the confirmation.
- Our organisation is registered on the eServices portal, so we could submit a breach notification today.
- A Deputy Information Officer is designated in writing, and the details match our PAIA manual.
- We have a written processing register covering every system that holds personal information, including juristic-person data.
- Every processing activity has one named lawful ground, and someone decided it deliberately.
- Our PAIA manual is published on the website and available at our premises.
- A compliant privacy notice appears at every collection point, not only online.
- We have a retention schedule with a driver per record class, and deletion reaches backups and supplier copies.
- Every supplier that touches personal information has a signed written agreement covering security and immediate breach notification.
- We know which suppliers store data outside South Africa and on what basis.
- We have a risk register with owners, and evidence that safeguards were verified — not just installed.
- MFA is enforced on email and business systems, and backups have been restore-tested this year.
- We have a written procedure for access, correction and deletion requests, and a log of the ones we have received.
- Marketing consent is recorded, the suppression list is honoured everywhere, and objections stop processing.
- Our incident response plan names who declares, who notifies and who communicates, and someone has read it this year.
Most businesses find they can tick only a handful on the first pass, and that is a normal starting position rather than a crisis.
Where South African SMEs actually get stuck
Three patterns come up again and again.
Documents that exist but are not operated. A privacy policy downloaded from a template site, saved to a folder, never assigned an owner and never reviewed. Under the accountability condition, a framework you do not run is close to no framework at all.
The supplier chain. Businesses secure their own network carefully and then hand a full customer export to a marketing agency on the strength of a phone call. This is exactly what the written-contract requirement is aimed at: without it, nothing obliges the operator to maintain your security measures, and nothing obliges it to tell you immediately when it has been breached.
Verification. Identifying risks and buying controls is the part that feels like progress. Regularly checking that those controls still work — licences current, patches applied, access reviewed, restores tested — is the part that gets deferred, and it is explicitly required.
Frequently asked questions
Does POPIA apply to a business with only a handful of employees?
Yes. POPIA has no small-business exemption and no revenue threshold. If you process personal information — and any business with employees, customers and a contact form does — the eight conditions apply. The Act does scale in one sense: what counts as "appropriate, reasonable" security is judged against your size, sector and risk. A five-person firm is not expected to run a security operations centre. It is expected to have registered an Information Officer, to know what data it holds, and to have taken sensible measures.
Do we need consent for everything we do with personal information?
No, and defaulting to consent usually makes things harder. Consent is one of six lawful grounds, and it is the one where you carry the burden of proof and where the person can withdraw. Employment records rest on contract and legal obligation. Invoicing rests on contract. Where consent genuinely is the right ground — most notably unsolicited electronic direct marketing — record it properly.
What is the difference between a responsible party and an operator?
The responsible party decides why and how personal information is processed and carries the primary accountability. An operator processes it on the responsible party's behalf, on instruction. Most businesses are both: a responsible party for their own staff and customer data, and an operator for any client data they handle. The roles carry different duties — notably, the operator's duty to report a suspected compromise runs to the responsible party immediately, while the duty to notify the Regulator stays with the responsible party.
How quickly must we report a data breach in South Africa?
POPIA does not set a fixed number of hours or days. The standard is that notification to the Information Regulator and to affected data subjects must happen as soon as reasonably possible after the discovery of the compromise, and there is no exemption for incidents you judge to be low risk. Notification to the Regulator is submitted through its eServices portal, which requires your organisation and Information Officer to be registered in advance.
Is POPIA compliance a once-off project?
No. Staff change, tools get added, and new data flows appear quietly — a new SaaS trial, a new form, a new integration. Treat the checklist above as something to revisit at least annually and whenever you adopt a system that touches customer or employee data. The security condition in particular describes an ongoing cycle, not a milestone.
A living obligation, not a certificate
POPIA compliance is not something you earn once and file away. What the Act asks for is an organisation that keeps looking. Businesses that engage, document their reasoning and fix what they find are in a very different position from businesses that ignore correspondence from the Regulator.
If working through this feels like more than your team has time for, that is a normal place to be. Getting the fundamentals right — a registered Information Officer, an honest picture of what you hold, written agreements with the suppliers who touch it, security measures you can evidence, and a breach plan someone has actually read — puts most businesses a long way ahead of where they started.
This article is general information, not legal advice. POPIA decisions, correspondence with the Information Regulator and enforcement responses should be taken with a South African admitted attorney, and accountability rests with your Information Officer.
Want this handled for you?
Talk to the F1 team about cybersecurity, AI and managed IT for your business.



