Published: 21 July 2026 | By AOLC
The Protection of Personal Information Act — better known as POPIA — came into full effect in South Africa on 1 July 2021. Since then, the Information Regulator has been actively investigating complaints, issuing enforcement notices, and making it clear that non-compliance is not something South African businesses can ignore. Yet many SMEs still do not have a clear picture of what POPIA actually requires them to do.
This checklist cuts through the legal jargon and gives you a practical, step-by-step framework to assess where your business stands, identify gaps, and take action. Whether you are starting from scratch or reviewing an existing compliance programme, this guide covers the essentials — from appointing your Information Officer to securing your systems and training your team.
POPIA penalties can reach R10 million per offence, or up to 10 years in prison for the most serious contraventions. Ignorance of the law is not a defence — the Information Regulator can investigate any business, regardless of size.
Does POPIA Apply to Your Business?
The short answer is: almost certainly yes. POPIA applies to any "responsible party" — an individual, company, public body, or other entity — that determines the purpose and means of processing personal information. If your business does any of the following, POPIA applies to you:
- Stores customer names, email addresses, or phone numbers — including in your CRM, accounting software, or email contacts
- Processes employee payroll or HR records — salary data, ID numbers, banking details, disciplinary records
- Collects website visitor data — via contact forms, cookies, analytics tools, or newsletter subscriptions
- Handles supplier or contractor information — any data about a natural person, not just customers
- Manages student or patient records — schools, clinics, and other professional services have heightened obligations
The Act covers personal information about any living natural person (and existing juristic persons such as companies in some cases). It does not matter how small your business is or whether you are a sole trader — if you process personal information, you have obligations under POPIA.
R10M
maximum fine per offence under POPIA — applicable to any registered business in South Africa, regardless of size.
The 8 Conditions for Lawful Processing.
POPIA is built around eight conditions that every responsible party must satisfy when processing personal information. Think of these as the pillars of your compliance programme:
- Accountability — You are responsible for ensuring compliance. This includes appointing an Information Officer and registering them with the Information Regulator.
- Processing Limitation — You may only process personal information with the data subject's consent, or where another lawful ground applies (legal obligation, contract, legitimate interest).
- Purpose Specification — Personal information must be collected for a specific, clearly defined, and lawful purpose. Data subjects must be told what that purpose is at the time of collection.
- Further Processing Limitation — Data collected for one purpose may not be used for an incompatible purpose without fresh consent or another lawful basis.
- Information Quality — You must take reasonable steps to ensure the personal information you hold is accurate, complete, not misleading, and kept up to date.
- Openness — You must be transparent about what information you collect, why, how it is used, and how data subjects can exercise their rights. This is typically done through a Privacy Notice.
- Security Safeguards — You must implement appropriate technical and organisational measures to protect personal information against loss, damage, destruction, or unlawful access. Your IT security posture is directly relevant here.
- Data Subject Participation — Data subjects have the right to request access to their information, correct inaccuracies, and in certain circumstances, request that their data be deleted or that processing be stopped.
Tip
Register your Information Officer on the Information Regulator's online portal (inforegulator.org.za). Failure to register your Information Officer is itself a contravention of POPIA — it is one of the first things the Regulator checks during an investigation.
The POPIA Compliance Checklist.
Use this checklist to audit your current position and identify what still needs to be done. The items are grouped by area so you can assign them to the right person in your organisation.
Governance & Documentation
- Appoint an Information Officer — and a deputy if your organisation is large enough. Register both with the Information Regulator.
- Draft a POPIA-compliant Privacy Notice — for your website, contact forms, and all data collection points. It must explain what you collect, why, how long you keep it, and how data subjects can exercise their rights.
- Create a data retention policy — specifying how long each category of personal information is kept, and the process for secure deletion when retention periods expire.
- Document your lawful basis for processing — for every category of personal information, record the lawful basis (consent, contract, legal obligation, legitimate interest). This is your first line of defence in a regulatory investigation.
- Compile a PAIA Manual — required for private bodies with more than 50 employees, but recommended for all businesses handling significant volumes of personal information.
Data Mapping & Third Parties
- Conduct a Personal Information Impact Assessment (PIIA) — map what personal data you hold, where it is stored, who has access, how long you keep it, and what controls protect it. Even a simple spreadsheet is a valuable start.
- Audit your third-party processors — cloud platforms, payroll providers, marketing tools, and HR software all process personal information on your behalf. You need written data processing agreements with each of them confirming they will protect the data.
- Identify cross-border data transfers — sending personal information outside South Africa is permitted but requires appropriate safeguards. If you use US-based cloud services (Microsoft 365, AWS, Google Workspace), this applies to you.
South African businesses using Microsoft 365, Google Workspace, or AWS are technically transferring personal information outside the country. This is permitted under POPIA, but requires a data processing agreement with the provider — something many businesses have not yet put in place.
Technical & Security Controls
- Apply the principle of least privilege — only staff who genuinely need access to personal information for their role should have it. Review and audit access rights regularly.
- Encrypt sensitive data at rest and in transit — this covers email, cloud storage, databases, and laptops. Encryption is one of the most direct ways to satisfy POPIA's security safeguard requirement.
- Enable multi-factor authentication (MFA) — on all systems that contain personal information, including email, payroll systems, and cloud platforms. See our guide on cloud security for SA businesses for practical steps.
- Conduct regular vulnerability assessments — at least annually, or after any significant change to your IT environment. Security assessments identify gaps before attackers do.
- Ensure your backup covers personal information — and that restore procedures are tested. Loss of personal information through a failed backup is a notifiable security compromise under POPIA.
Staff Training & Internal Procedures
- Train all staff who handle personal information — POPIA obligations, how to handle data subject requests, and what to do if they suspect a breach. Annual training is the minimum; document attendance.
- Update employment contracts and HR policies — to reflect POPIA obligations, including confidentiality clauses covering personal information.
- Create a clear breach reporting procedure — staff must know who to contact and how quickly if they suspect that personal information has been compromised.
Data Subject Rights & Breach Response
- Create a process for data access requests — you have 30 days to respond. Document how requests are logged, reviewed, and fulfilled.
- Create a process for correction and deletion requests — data subjects can ask you to correct inaccurate information or, in some cases, request deletion.
- Develop an incident response plan — covering how you detect, contain, and report a data breach. POPIA requires notification to the Information Regulator and affected data subjects as soon as reasonably possible after a breach is discovered.
- Maintain a breach register — documenting all incidents, even those that do not require notification. This demonstrates your accountability to the Regulator.
72h
Best practice target for notifying the Information Regulator after a data breach is discovered. POPIA requires notification "as soon as reasonably possible" — waiting weeks is not acceptable.
Penalties for Non-Compliance.
The Information Regulator has real enforcement powers. Under POPIA, the consequences of non-compliance include:
- Fines of up to R10 million — for offences such as failing to notify the Regulator of a breach, obstructing a Regulator investigation, or wilfully processing personal information unlawfully.
- Imprisonment of up to 10 years — for the most serious offences, including selling personal information without consent.
- Civil liability — data subjects can sue for damages suffered as a result of a POPIA contravention, separate from any regulatory action.
- Reputational damage — the Information Regulator publishes enforcement actions. A public enforcement notice can seriously damage customer trust and brand reputation.
The Regulator has already issued enforcement notices to major South African organisations, including government departments, financial services firms, and large employers. SMEs are not immune — complaints from a single data subject can trigger a formal investigation against any business.
Tip
The best defence against a regulatory action is documented evidence that you take POPIA seriously — not just a privacy policy on your website, but training records, breach logs, access controls, and signed data processing agreements. Documentation is what the Regulator asks to see.
Where to Start.
If POPIA compliance feels overwhelming, start with these five steps and build from there:
- Register your Information Officer — this is non-negotiable and costs nothing. Visit inforegulator.org.za and register your nominated officer today.
- Update your Privacy Notice — every website and customer-facing touchpoint needs an accurate, POPIA-compliant notice. If you copied a template from the internet without adapting it, it is not compliant.
- Map your data — you cannot protect what you do not know you have. Start with a basic spreadsheet: what personal information do you hold, where is it stored, who has access, and how long do you keep it?
- Secure your systems — enable MFA everywhere, encrypt sensitive data, and apply least-privilege access controls. These are also good managed IT hygiene practices that satisfy POPIA's security safeguard requirement. If you are unsure where your gaps are, a security assessment is the fastest way to find out.
- Train your team — POPIA compliance is not just an IT issue. Every employee who touches personal information is both a risk and a safeguard. Annual training, properly documented, is the minimum standard.
POPIA compliance is not a once-off project — it is an ongoing programme. The good news is that most of the building blocks are the same as good IT practice: strong access controls, regular backups, up-to-date security, and clear internal procedures. If your IT is well managed, you are already partway there.
Get POPIA Ready.
Not sure where your business stands? Our team can help you assess your current POPIA posture, identify gaps, and build a practical compliance roadmap — without the legal jargon.
Book a POPIA Assessment
← Back to Blog