About Practice Areas How We Work Attorney FAQ Articles Contact Book a Consultation
← All Articles

POPIA Compliance for Small Businesses in South Africa

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa’s data protection law. It applies to any person or organisation that processes personal information of South African data subjects — which means virtually every business operating in the country. Non-compliance carries penalties of up to R10 million or imprisonment of up to 10 years.

What is personal information under POPIA?

Personal information is broadly defined and includes any information that can identify a living person: names, contact details, ID numbers, financial information, health records, location data, online identifiers such as IP addresses, and even opinions about a person. If your business collects, stores, uses, or shares any of this, POPIA applies.

The eight conditions for lawful processing

  1. Accountability — appoint an Information Officer and register them with the Information Regulator
  2. Processing limitation — collect only what you need, for a specific purpose, with the data subject’s knowledge or consent
  3. Purpose specification — be clear about why you are collecting the information
  4. Further processing limitation — do not use the information for a purpose incompatible with why it was collected
  5. Information quality — keep the information accurate and up to date
  6. Openness — notify data subjects of what you collect and why via a privacy notice or policy
  7. Security safeguards — implement reasonable technical and organisational measures to protect personal information
  8. Data subject participation — allow data subjects to access, correct, or request deletion of their information

Practical steps for small businesses

1. Appoint and register your Information Officer

Every business must have an Information Officer — in a small business this is typically the owner or a senior manager. They must be registered with the Information Regulator at inforegulator.org.za.

2. Map your data

Identify what personal information your business collects, where it is stored, who has access to it, and how long you keep it. This is your data inventory — the foundation of all compliance work.

3. Update your privacy policy

Your website and client-facing materials must include a POPIA-compliant privacy policy that explains what you collect, why, how long you keep it, and how data subjects can exercise their rights.

4. Secure your data

Implement basic security measures: strong passwords, two-factor authentication, encrypted storage, and restricted access. Review which employees can access client data and whether that access is necessary.

5. Prepare for data breaches

POPIA requires you to notify the Information Regulator and affected data subjects if a security breach is likely to harm them. Have a basic breach response plan in place before you need it.

HvS Attorneys advises businesses on POPIA compliance, drafts privacy policies and data processing agreements, and assists with Information Regulator matters. Contact us for a compliance review.

Legal Authority

  • Protection of Personal Information Act 4 of 2013 — ss 4–25 (the eight conditions for lawful processing); s 55 (Information Officer); s 107 (offences and penalties); s 109 (administrative fines, maximum R10 million)
  • Information Regulator (South Africa) — registration of Information Officers, inforegulator.org.za

Related reading:
If your business uses AI tools that process personal data, read our guide on AI in South African law.
New companies have POPIA obligations from day one — and registering a company does not make you its owner: governance structure matters for accountability.

Need legal assistance? HvS Attorneys advises clients across Johannesburg on business, employment, property and technology law.

Book a consultation
WhatsApp Us