← SIGNAL · Compliance

POPIA compliance checklist for small businesses (2026)

By KTH-Tech · Compliance & data · 8 min read

POPIA applies to every South African business that touches personal information — and if you have customers, staff or a WhatsApp list, that's you. The Act isn't designed to sink small businesses; most of what it asks is good hygiene. But "we're too small for POPIA" is a myth that ends in enforcement notices. Here's what the Act actually requires of an SME, distilled into a 12-point checklist you can work through in a month. (Building software? The engineering view is in our POPIA for SaaS guide.)

POPIA isn't a document you buy — it's a set of habits: collect less, protect what you keep, and be honest about what you do with it.

1.Know what counts as personal information

Names, contact details, ID numbers, location, financial details, opinions about a person, staff records, CCTV footage — if it identifies a living person (or an existing company), POPIA covers it. Your customer spreadsheet, lead forms, payroll and even your email archive are all "processing".

2.The lawful basis & minimality

You need a reason the Act recognises to process data — consent is one, but performing a contract, a legal obligation, or your legitimate interest often fit better. And collect only what the purpose needs: if the job requires a name and number, don't also harvest an ID number "for the file".

3.The Information Officer — register, it's free

Every business automatically has an Information Officer: the owner or head. They must be registered with the Information Regulator (free, via the eServices portal) and are responsible for compliance, the privacy policy, and handling data-subject requests. For most SMEs this is an afternoon's admin that most competitors haven't done.

4.Security is a legal duty

Section 19 requires "appropriate, reasonable technical and organisational measures" — in practice: MFA, unique passwords, updates, encrypted devices, access control and tested backups. That's the exact stack in our SME cybersecurity guide — do that and your Section 19 story is strong.

5.Breaches: report, don't bury

If personal information gets into the wrong hands, you must notify the Information Regulator and the affected people "as soon as reasonably possible". Pre-write the template and know where to send it — a calm, fast notification is also the best reputational defence.

6.Marketing, cookies & cross-border

Direct electronic marketing needs opt-in consent (with an opt-out on every message) unless you're mailing existing customers about similar products. Website forms need a linked privacy policy. And if your tools process data offshore — most cloud and AI tools do — that's a cross-border transfer, allowed when the destination offers adequate protection or you have consent/contractual safeguards.

The 12-point POPIA checklist

Work through these — most SMEs finish in a month:

We can list what personal data we hold, where it lives, and why
Every processing purpose has a lawful basis we can name
We collect the minimum needed — no "nice to have" fields
Our Information Officer is registered with the Regulator
A plain-language privacy policy is live on our site and forms link to it
Marketing lists are opt-in, with working opt-outs
MFA, unique passwords and updates protect every system holding data
Devices are encrypted; backups run automatically and restores are tested
Access is role-based; leavers lose access the day they go
Contracts with processors (hosting, payroll, marketing tools) cover POPIA
We know our cross-border position for cloud and AI tools
A breach-response one-pager exists with the Regulator's contact details

The bottom line

POPIA compliance for an SME is a month of focused admin, not a legal siege: map your data, register your Information Officer, publish an honest privacy policy, secure your systems, and rehearse the bad day. Fines reach R10 million — but the everyday win is simpler: customers trust businesses that treat their data properly, and trust converts.

Want compliance built in, not bolted on?

KTH-Tech builds POPIA-by-design platforms and runs compliance uplift for South African businesses — from privacy policies to hardened systems.

Get compliant properly →

General guidance, not legal advice. Your POPIA obligations depend on your specific processing — validate with a qualified privacy professional.