The Protection of Personal Information Act (POPIA) has been fully enforceable in South Africa since July 2021. Despite this, the majority of South African small businesses are still not fully compliant. The risks are real: fines up to R10 million, reputational damage, and data subject claims. The good news is that for most SMEs, the compliance requirements are straightforward and achievable without a legal team.

Does POPIA apply to your business?

POPIA applies if your business:

That covers virtually every South African business. There is no size exemption, but the practical requirements are proportionate to your risk profile and the sensitivity of the data you process.

The eight POPIA conditions every business must meet

The practical POPIA checklist for SMEs

1. Register your Information Officer

Go to justice.gov.za and register your Information Officer with the Information Regulator. This is mandatory and free. The Information Officer is legally responsible for your POPIA compliance — for most SMEs, this is the business owner or MD.

2. Publish a privacy policy

Your website and any form that collects personal information must link to a clear privacy policy. It must explain: what you collect, why, how you store it, how long you keep it, and how data subjects can exercise their rights. Don’t copy a template — it must reflect your actual practices.

M.Y Tech Guys builds POPIA-compliant privacy policies and data subject request systems into every website we deliver. If your current site doesn’t have one, let’s fix that →

3. Audit your data collection

List every place your business collects personal information: contact forms, WhatsApp, email, paper, spreadsheets, point-of-sale, HR systems. For each: is there a clear business purpose? Is the data secured? Do you know where it’s stored? How long do you keep it?

4. Secure your data

Technical safeguards required under POPIA include:

5. Handle data subject requests

POPIA gives South Africans the right to: access their personal information, request correction of inaccurate data, object to processing, and request deletion. You need a process to receive and action these requests within a reasonable timeframe (typically 30 days).

6. Manage marketing consent

You may only send marketing communications to people who have consented. Existing customers can receive marketing on the same class of products/services they purchased (opt-out model), but new contacts require explicit opt-in. Keep records of consent.

POPIA and employee data

Employee personal information is also protected under POPIA. This includes payroll data, performance records, health information, and disciplinary records. Key requirements:

The cost of POPIA compliance technology

For most SMEs, the tech cost of POPIA compliance is modest:

Frequently asked questions

What happens if I get a data breach?

Under POPIA, you must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a breach. You should have a breach response plan before this happens — not after. Document the breach, its scope, and your response actions.

Can I use Google Forms or WhatsApp to collect customer data?

Yes, but with caveats. Google Forms data is stored on Google’s servers offshore — you need to ensure this is disclosed in your privacy policy and that Google’s data processing terms are compatible with your POPIA obligations. WhatsApp messages are end-to-end encrypted but WhatsApp/Meta has access to metadata.

Do I need a cookie banner on my South African website?

If your website uses cookies that track personal information (analytics, advertising, session tracking), yes — you need to disclose this and allow visitors to opt out of non-essential cookies. Basic session cookies required for the site to function are exempt.

Is sharing customer data with my accountant a POPIA issue?

Yes. Your accountant is an operator processing personal information on your behalf. You need a data processing agreement with them and should ensure they have adequate security measures in place.


M.Y Tech Guys builds POPIA compliance into every website and system we deliver — privacy policies, cookie consent, secure data handling, data request workflows. Get a POPIA compliance assessment → or see POPIA tech services →