POPIA compliance checklist for small businesses (2026)
POPIA applies to every South African business that touches personal information — and if you have customers, staff or a WhatsApp list, that's you. The Act isn't designed to sink small businesses; most of what it asks is good hygiene. But "we're too small for POPIA" is a myth that ends in enforcement notices. Here's what the Act actually requires of an SME, distilled into a 12-point checklist you can work through in a month. (Building software? The engineering view is in our POPIA for SaaS guide.)
1.Know what counts as personal information
Names, contact details, ID numbers, location, financial details, opinions about a person, staff records, CCTV footage — if it identifies a living person (or an existing company), POPIA covers it. Your customer spreadsheet, lead forms, payroll and even your email archive are all "processing".
2.The lawful basis & minimality
You need a reason the Act recognises to process data — consent is one, but performing a contract, a legal obligation, or your legitimate interest often fit better. And collect only what the purpose needs: if the job requires a name and number, don't also harvest an ID number "for the file".
3.The Information Officer — register, it's free
Every business automatically has an Information Officer: the owner or head. They must be registered with the Information Regulator (free, via the eServices portal) and are responsible for compliance, the privacy policy, and handling data-subject requests. For most SMEs this is an afternoon's admin that most competitors haven't done.
4.Security is a legal duty
Section 19 requires "appropriate, reasonable technical and organisational measures" — in practice: MFA, unique passwords, updates, encrypted devices, access control and tested backups. That's the exact stack in our SME cybersecurity guide — do that and your Section 19 story is strong.
5.Breaches: report, don't bury
If personal information gets into the wrong hands, you must notify the Information Regulator and the affected people "as soon as reasonably possible". Pre-write the template and know where to send it — a calm, fast notification is also the best reputational defence.
6.Marketing, cookies & cross-border
Direct electronic marketing needs opt-in consent (with an opt-out on every message) unless you're mailing existing customers about similar products. Website forms need a linked privacy policy. And if your tools process data offshore — most cloud and AI tools do — that's a cross-border transfer, allowed when the destination offers adequate protection or you have consent/contractual safeguards.
The 12-point POPIA checklist
Work through these — most SMEs finish in a month:
The bottom line
POPIA compliance for an SME is a month of focused admin, not a legal siege: map your data, register your Information Officer, publish an honest privacy policy, secure your systems, and rehearse the bad day. Fines reach R10 million — but the everyday win is simpler: customers trust businesses that treat their data properly, and trust converts.
Want compliance built in, not bolted on?
KTH-Tech builds POPIA-by-design platforms and runs compliance uplift for South African businesses — from privacy policies to hardened systems.
Get compliant properly →General guidance, not legal advice. Your POPIA obligations depend on your specific processing — validate with a qualified privacy professional.