GUIDE

POPIA checklist for small businesses.

Twelve things a South African small business needs in place under POPIA, in the order we would do them.

Last reviewed: 7 October 2026

Does POPIA apply to you?

The Protection of Personal Information Act 4 of 2013 (POPIA) applies to any business in South Africa that handles personal information: client records, staff files, supplier contacts, CCTV footage, a mailing list. There is no exemption for small businesses.

POPIA calls your business the responsible party. You stay responsible even when a supplier stores or processes the information for you.

The checklist

  1. Register your Information Officer. By default it is the head of the business, and they must be registered with the Information Regulator before taking up the role. See how to register an Information Officer.
  2. Publish a PAIA manual. Every private business has needed one since 1 January 2022. See what a PAIA manual must contain.
  3. List the personal information you hold. What it is, whose it is, where it lives, who can reach it and why you have it. Everything else on this list depends on this step.
  4. Check your reason for each use. You need a lawful basis such as a contract, a legal duty, a legitimate interest or consent. Collect only what the purpose needs.
  5. Publish a privacy notice. Tell people what you collect, why, who you share it with and how to reach you. Put it on your website and refer to it on your forms.
  6. Secure it. POPIA requires appropriate, reasonable technical and organisational measures. For a small office that means multi-factor sign-in on email, a password manager, patched and encrypted devices, backups you have test-restored, and access limited to the people who need it.
  7. Sign agreements with your operators. An operator is anyone who processes personal information for you: your IT provider, payroll bureau, cloud accounting or practice-management system. POPIA requires a written contract that obliges them to keep the information secure and to tell you about a breach.
  8. Set retention periods. Keep records only as long as the purpose or another law requires. Tax and company records have their own minimum periods. After that, delete or destroy them properly.
  9. Be ready for requests. People can ask what you hold about them and ask you to correct or delete it. Decide who handles these requests and how you confirm the requester's identity.
  10. Write a breach plan. If personal information is accessed or taken by someone who should not have it, you must notify the Information Regulator and the people affected as soon as reasonably possible. Decide now who makes that call and where the contact lists are kept.
  11. Fix your direct marketing. Electronic marketing by email, SMS or WhatsApp to people who are not already your customers needs their consent first. Every message needs a working opt-out.
  12. Train your people and keep evidence. Most incidents start with a person, not a firewall. Run short awareness sessions and keep a record of who attended, what changed and what was tested.

What it costs to ignore

The Information Regulator can issue enforcement notices and administrative fines of up to R10 million, and serious offences carry criminal penalties. For most small businesses the nearer risk is commercial: larger clients send security and POPIA questionnaires before they sign, and a blank answer loses the work.

Where to start

Do items 1, 2 and 3 first. The first two are quick and visible to anyone who checks. The third tells you how much work the rest will be.

This is practical guidance, not legal advice. For a legal opinion on a specific situation, speak to an attorney.

All guides

Free POPIA readiness assessment

A 60-minute, no-obligation review of your IT and compliance posture, with a written summary you keep — whether you work with us or not.

Book your assessment