Legal & Compliance

POPIA Compliance for Small Businesses: What You Actually Need to Do

Most South African SMBs aren't POPIA compliant. Here's a plain-English checklist of what the Protection of Personal Information Act actually requires from small businesses.

POPIA has been law for years — most SMBs still aren't compliant

The Protection of Personal Information Act (POPIA) came into full effect on 1 July 2021. The Information Regulator has already issued fines and enforcement notices. And yet, most small business owners either don't know what's required or assume it only applies to large companies.

It doesn't. POPIA applies to any business that processes personal information — which means virtually every business in South Africa.

What counts as "personal information"?

Personal information is broader than most people think. It includes: names and surnames, email addresses, phone numbers, ID numbers, physical addresses, IP addresses, location data, payment information, and even opinions about a person.

The POPIA compliance checklist for SMBs

1. Appoint an Information Officer

Every business must register an Information Officer with the Information Regulator. For a small business, this is typically the owner. Registration is free and done online at inforegulator.org.za.

2. Know what personal information you hold and why

Create a simple record of: what personal data you collect, where it's stored, why you need it, who has access to it, and how long you keep it.

3. Have a privacy notice on your website

Your website needs a privacy policy that explains what personal information you collect and why, who you share it with, and how people can access or delete their data.

4. Get consent before collecting data

You need a lawful basis for processing personal information. For most small businesses, this means getting explicit consent — a checked checkbox on a form is not consent in POPIA's view.

5. Secure personal information appropriately

Personal information must be kept secure: strong passwords, no emailing unencrypted spreadsheets of client data, restricting access to staff who need it.

6. Have a data breach response plan

If personal information is compromised, you must notify the Information Regulator and affected individuals as soon as reasonably possible.

7. Don't keep data longer than necessary

Define a retention period (e.g. 5 years after the last transaction) and stick to it.

The penalty for non-compliance

Fines under POPIA can reach R10 million or up to 10 years' imprisonment for serious breaches. The Information Regulator has already taken enforcement action — SMBs are next in the crosshairs.

How a proper CRM helps with POPIA compliance

Centralised data storage, role-based access control, audit trails, and the ability to export or delete a client's data on request. Talk to us about how MyGenesis handles this for our clients.