Why POPIA compliance matters for small businesses
POPIA has been fully enforceable since 1 July 2021. Every South African business that processes personal information must comply, regardless of size. There is no small-business exemption.
The Information Regulator is now actively enforcing the Act. In the 2024/25 financial year, 2,374 data breaches were reported. By August 2025, a further 1,947 had been reported. The Regulator has imposed fines of R5 million on the Department of Basic Education, R500,000 on Blouberg Municipality, and R100,000 on Lancet Laboratories. Non-compliance with an Enforcement Notice carries a fine of up to R10 million or imprisonment of up to 10 years, or both.
Beyond fines, non-compliance creates practical business risks. Corporate procurement and ESD questionnaires now routinely ask for POPIA evidence. A missing privacy notice or Information Officer registration is an easy disqualifier for tenders and supply chain opportunities.
This checklist covers what every small business must do, in order of priority.
Step 1: Appoint and register an Information Officer
Every business must have an Information Officer. This is not optional.
Under Section 55 of POPIA, the Information Officer is responsible for encouraging compliance, dealing with data subject requests, working with the Regulator on investigations, and ensuring compliance with the Act.
If you do not appoint one, the CEO or head of the business becomes the Information Officer by default. You can authorise another person to fill the role, but the CEO remains ultimately accountable.
The Information Officer must be registered with the Information Regulator. The registration is free and can be completed online at inforegulator.org.za. You need to register before the Information Officer takes up their duties.
For small businesses, the practical minimum is one Information Officer and at least one Deputy Information Officer who can handle requests when the Information Officer is unavailable.
Step 2: Publish a privacy policy
The openness condition requires you to tell people what you do with their information. In practice, that means a privacy policy that states:
- What personal information you collect
- Why you collect it
- Who you share it with
- Whether it leaves South Africa
- How long you keep it
- How you secure it
- How a person can access or correct what you hold
- Your Information Officer’s contact details
A generic template copied from an overseas website usually fails this test. Most are written for GDPR, not POPIA. Your privacy policy must reflect your actual business practices.
The policy must be available at your principal place of business and on your website if you have one.
Step 3: Compile a PAIA manual
POPIA and PAIA share the same Information Officer. The Promotion of Access to Information Act requires every private body to maintain a manual describing the records it holds, how to access them, and the process for requesting information.
The PAIA manual must be available for public inspection during normal business hours at your principal place of business. If you have a website, it should be published there as well.
Many small businesses overlook this requirement. The Information Regulator has noted that PAIA compliance remains poor across both public and private bodies, and that many organisations still fail to publish PAIA manuals.
Step 4: Establish a lawful basis for processing
POPIA recognises several lawful bases for processing personal information. Consent is one, but not the only one. The lawful bases include:
- Consent of the data subject
- Performance of a contract with the data subject
- Compliance with a legal obligation
- Protection of a legitimate interest of the data subject
- Performance of a task carried out in the public interest
- Legitimate interests of the responsible party (subject to a balancing test)
You need to know which basis applies to each category of personal information you process. If you rely on consent, you must be able to prove you have it. Memory is not a record.
Direct marketing has its own stricter rules under Section 69. Marketing to someone who is not an existing customer by email, SMS, or automated call requires their consent first, and you may only ask for that consent once.
Step 5: Implement consent records and data collection notices
Section 18 of POPIA requires you to notify data subjects of specific information at or before the time you collect their personal information. This includes:
- The purpose of the collection
- Whether the collection is required or voluntary
- The consequences of not providing the information
- Who will receive the information
- Whether the information will be transferred outside South Africa
- The right to lodge a complaint to the Information Regulator
Where you rely on consent, the consent must be documented and can be withdrawn by the data subject at any time. You must be able to produce the consent record if challenged.
Step 6: Set up a process for data subject requests
People have the right to ask what personal information you hold about them, and to have it corrected or deleted. These requests generally must be answered within 30 days.
Your process needs:
- A known way for people to submit a request (email, form, or in person)
- A way to verify the requester’s identity before disclosing anything
- A record showing each request was handled on time
- A process for correcting or deleting information when requested
For a small business, the minimum is a documented process and a register of requests received and completed.
Step 7: Prepare a data breach response plan
Section 22 of POPIA requires you to notify the Information Regulator, and in most cases the affected people, as soon as reasonably possible after personal information is compromised. The amended regulations set this at 72 hours.
A breach is the worst possible moment to figure out who does what. Your response plan should include:
- Who identifies and reports the breach
- Who assesses the scope and severity
- Who notifies the Information Regulator (using the prescribed Form 2)
- Who notifies affected data subjects
- What corrective steps are taken
- How the incident is documented
The Information Regulator has issued enforcement notices specifically for failures to notify after breaches. In May 2026, Central Johannesburg TVET College received an enforcement notice for failing to notify both the Regulator and affected individuals after personal information was unlawfully shared.
Step 8: Sign operator agreements
If a third party processes personal information on your behalf, you must have a written agreement in place. This applies to cloud providers, payroll processors, accountants, IT service providers, and anyone else who handles personal information for you.
The agreement must ensure the operator:
- Processes personal information only on your instructions
- Implements adequate security measures
- Notifies you of any breaches
- Returns or destroys personal information when the contract ends
You remain the Responsible Party and cannot outsource your accountability. If your operator has a breach, you are still responsible for notifying the Regulator and affected data subjects.
Step 9: Train your staff
POPIA compliance depends on the people who handle personal information every day. Regular training should cover:
- What personal information is and why it matters
- The business’s privacy policy and data handling procedures
- How to recognise and report a data breach
- How to handle data subject requests
- The consequences of non-compliance
Training does not need to be expensive. A practical session covering your specific business processes, with documented attendance, is sufficient.
Step 10: Monitor and review
POPIA compliance is not a once-off exercise. Businesses should:
- Review the privacy policy and PAIA manual annually
- Update consent records when processes change
- Check that operator agreements are current
- Monitor breach reporting obligations
- Stay informed about Regulator guidance and enforcement trends
The Information Regulator held a media briefing on 31 August 2026 outlining its enforcement priorities. Businesses that stay informed are better placed to avoid becoming the next enforcement notice.
What happens if you do not comply
The consequences are real and growing:
- Administrative fines up to R10 million for non-compliance with enforcement notices
- Imprisonment of up to 10 years for serious offences
- Reputational damage from public enforcement notices
- Loss of corporate tenders and procurement opportunities
- Civil claims from data subjects who suffer harm
The Regulator is moving toward immediate fines upon a finding of non-compliance, rather than the current grace-period approach. This mirrors the GDPR model and signals that the enforcement environment will only tighten.
The bottom line
POPIA compliance is a legal requirement, not a recommendation. The 10 steps in this checklist are the practical minimum for any South African small business. Most of them cost nothing to implement beyond the time it takes to do them.
The businesses that complete these steps protect themselves from fines, maintain access to corporate procurement, and build trust with their customers. The businesses that ignore them face growing regulatory and commercial risk.
SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support businesses across South Africa with compliance frameworks, statutory audits, independent reviews, and assurance services. Contact SC Audit to discuss how POPIA compliance affects your business.
Frequently Asked Questions
Does POPIA apply to small businesses?
Yes. Any South African business that processes personal information is a responsible party under POPIA. There is no size threshold. The moment you collect customer names, contact details, employee information, or supplier records in the course of business, POPIA applies to you.
What is the minimum POPIA compliance for a small business?
The practical minimum is: register an Information Officer with the Information Regulator, publish a privacy notice, compile a PAIA manual, establish a lawful basis for the data you hold, and secure it appropriately. These five items represent the baseline the Regulator expects.
How long do I have to respond to a data subject access request?
The amended POPIA regulations set a 30-day deadline for responding to requests for access, correction, or deletion of personal information. You must verify the requester’s identity before disclosing anything.
What happens if I suffer a data breach?
You must notify the Information Regulator within 72 hours using the prescribed Form 2. In most cases, you must also notify the affected data subjects. Failure to notify is itself an offence under POPIA and has been the basis for enforcement notices against organisations that suffered breaches.
Do I need separate POPIA and PAIA compliance?
Both Acts apply to the same business and share the same Information Officer. POPIA protects personal information; PAIA enables access to records held by public and private bodies. You need compliance with both, and the Information Officer registered under POPIA also serves as the Information Officer under PAIA.