Compliance June 2025 8 min read

POPIA Compliance for South African SMEs: A Plain-Language Guide (2025)

The Protection of Personal Information Act is fully in force. Fines reach R10 million and directors face personal criminal liability. Yet most South African SMEs still aren't compliant. Here's exactly what you need to do - without the legal jargon.

POPIA (the Protection of Personal Information Act, Act 4 of 2013) has been fully enforceable since July 2021. Despite this, the majority of South African small and medium businesses remain partially or fully non-compliant - usually not out of bad intent, but because the Act is dense, the guidance is scattered, and most compliance resources are aimed at large corporates.

This guide is written for the owner or operations manager of a South African SME. No law degree required.

Does POPIA apply to your business?

Yes, if you process any personal information about South African residents - including your clients, employees, suppliers, or website visitors. "Processing" includes collecting, storing, using, sharing, or deleting personal data. If you have a client database, employee records, or a contact form on your website, POPIA applies to you.

What counts as "personal information"?

Under POPIA, personal information is broader than most people expect. It includes:

  • Names, ID numbers, passport numbers
  • Email addresses, phone numbers, physical addresses
  • Financial information (account numbers, salary details)
  • Health and medical information
  • Employment history and performance records
  • Online identifiers (IP addresses, cookies, device IDs)
  • Biometric data (fingerprints, facial recognition)
  • Opinions about or expressed by a person

The 8 conditions for lawful processing

POPIA requires that all personal information processing meets eight conditions. Think of these as the pillars your compliance programme must rest on:

1. Accountability

Appoint an Information Officer (IO) responsible for compliance. For most SMEs, this is the owner or a senior manager. Register your IO with the Information Regulator at inforegulator.org.za.

2. Processing limitation

Only collect personal information you actually need, and only use it for the purpose you collected it for. Don't collect "just in case."

3. Purpose specification

Be clear and specific about why you're collecting data. Tell people upfront - in plain language - what their information will be used for.

4. Further processing limitation

Don't use personal information for a purpose that is incompatible with the original reason it was collected. You can't collect data for invoicing and then use it for marketing without consent.

5. Information quality

Keep personal information accurate, complete, and up to date. Have a process for updating or correcting records when people request it.

6. Openness

Have a published Privacy Policy that explains what data you collect, why, how long you keep it, and how people can access or delete their information. Your website must have this.

7. Security safeguards

Implement appropriate technical and organisational measures to protect personal information from loss, damage, or unauthorised access. This is where IT security directly intersects with legal compliance.

8. Data subject participation

Individuals have the right to access their personal information, correct it, and request deletion. You must have a process to respond to these requests within a reasonable time.

Your POPIA compliance action checklist

Use this as a practical starting point. Tick each item off systematically:

Governance (do first)

  • ☐ Appoint an Information Officer and register them with the Information Regulator
  • ☐ Conduct a personal information audit - map every type of data you hold, where it lives, and who has access
  • ☐ Document your legal basis for processing each category of data (consent, contract, legal obligation, legitimate interest)

Documents and policies

  • ☐ Draft and publish a Privacy Policy on your website (in plain language)
  • ☐ Create a POPIA-compliant employee data processing policy
  • ☐ Update client contracts to include data processing clauses
  • ☐ Create an Operator Agreement for any third parties who process data on your behalf (accountants, HR software, cloud providers)
  • ☐ Implement a Data Subject Request procedure (access, correction, deletion)
  • ☐ Create a Data Breach Response Plan

Technical security (IT)

  • ☐ Implement access controls - only staff who need personal data can access it
  • ☐ Enable encryption on devices storing personal information
  • ☐ Implement and verify regular backups
  • ☐ Deploy endpoint protection (antivirus / EDR) on all company devices
  • ☐ Enable multi-factor authentication on email, cloud storage, and business systems
  • ☐ Conduct a security assessment of your website (SSL, headers, form data handling)
  • ☐ Delete personal data you no longer have a legitimate reason to hold

Ongoing

  • ☐ Train all staff on POPIA basics annually
  • ☐ Review and update your Information Officer registration annually
  • ☐ Audit third-party data processors annually
  • ☐ Report data breaches to the Information Regulator within 72 hours

What are the penalties for non-compliance?

The Information Regulator has enforcement powers including:

  • Administrative fines up to R10 million per violation
  • Criminal prosecution of directors and officers - imprisonment of up to 10 years for serious offences
  • Enforcement notices requiring you to stop processing data until compliant
  • Civil claims from individuals whose data was mishandled

Enforcement has been gradually ramping up since 2022. The Regulator has issued enforcement notices to several South African companies. This is no longer theoretical risk.

Where to register your Information Officer

Registration is done at the Information Regulator's online portal: inforegulator.org.za. It's free and takes approximately 30-60 minutes. You'll need your company registration number, the IO's ID number, and contact details.

The IT-compliance overlap

A significant portion of POPIA compliance is an IT problem. Security safeguards (Condition 7) require technical controls that most SMEs don't have in place: encrypted devices, access-controlled systems, tested backups, monitored endpoints, and a documented incident response procedure. This is exactly the kind of infrastructure a managed IT provider should be putting in place for you as a baseline - not as an add-on.

InfoServ Technologies offers a free IT and security audit that specifically checks your technical POPIA compliance posture - encryption, backups, access controls, and endpoint security. Book yours today and find out exactly where you stand.