NexBDM Blog
POPIA Compliance Checklist for South African Small Businesses (2026)
By NexBDM Team · 2026-07-26
POPIA applies to every business that processes personal information, with no exemption for being small. This is the practical checklist: register your Information Officer, know what data you hold and why, apply the eight conditions for lawful processing, secure it, and be ready to report a breach.
POPIA compliance for a South African small business comes down to four things: register your Information Officer with the Information Regulator, know exactly what personal information you hold and why, apply the eight conditions for lawful processing to it, and be able to secure and report on it. Being small is not an exemption.
The Protection of Personal Information Act is often treated as a big-company problem. It is not. If you keep a customer list, a WhatsApp thread, a spreadsheet of leads or a folder of ID copies, you are processing personal information and the Act applies to you. This is the checklist, in plain language, with the statutory sources at the bottom.
Who must comply with POPIA?
Any responsible party that processes personal information. A responsible party is the business that decides why and how the information is processed, which for a small business is almost always the business itself. There is no small-business carve-out and no headcount threshold. The Act is about the activity, not the size of the company doing it.
Two practical consequences follow. First, sole proprietors and small teams are in scope exactly like a bank is, just with a much smaller surface area to control. Second, the fact that your customer data lives in WhatsApp and a spreadsheet rather than a database does not put it outside the Act. It just makes it harder to account for, which is the real problem.
What are the eight conditions for lawful processing?
Chapter 3 of POPIA sets out eight conditions. Everything else in a compliance programme exists to satisfy them:
- Accountability (section 8). You must ensure the conditions are met. It is your responsibility, not your software vendor's.
- Processing limitation (sections 9 to 12). Process lawfully, collect only what you actually need, have a justification such as consent or contract, and collect from the person directly where possible.
- Purpose specification (sections 13 and 14). Collect for a specific, defined purpose, and do not keep the records longer than you need them.
- Further processing limitation (section 15). If you later use the data for something new, it must be compatible with why you collected it.
- Information quality (section 16). Keep it accurate, complete and current.
- Openness (sections 17 and 18). Document what you process and tell people you are collecting their information and why.
- Security safeguards (sections 19 to 22). Protect the integrity and confidentiality of the information, and notify a security compromise.
- Data subject participation (sections 23 to 25). People may ask what you hold about them, and ask you to correct or delete it.
The POPIA compliance checklist
Work through these in order. The first three are the ones the Regulator most often finds missing.
- Appoint and register your Information Officer. In a small business this is usually the owner by default. Registration happens on the Information Regulator's portal, and the Regulator is explicit that Information Officers must only assume their duties once the responsible party has registered them.
- Do a data inventory. Write down every place personal information sits: your CRM, your inbox, WhatsApp, spreadsheets, the shared drive, the accounting system, the shoebox of copied IDs. You cannot protect or account for what you have never listed.
- Write down the purpose for each one. For every store of data, state why you hold it and what justifies it. Anything you cannot justify is a liability you are carrying for free. Delete it.
- Have a PAIA manual. The Information Regulator maintains PAIA manual guidance and expects responsible parties to have one available.
- Publish a privacy notice. Tell people, at the point you collect, what you are collecting, why, and who you share it with. This is the openness condition in practical form.
- Fix your consent for direct marketing. If you send marketing messages, know on what basis you are sending to each person. The Regulator has flagged direct marketing as an enforcement priority.
- Secure the data. Access control, unique logins, no shared passwords, encryption where you can, and no client data sitting in a personal WhatsApp account that leaves when an employee does.
- Set retention periods. Decide how long each category is kept and actually delete it when the period expires. Indefinite retention is the default only because nobody decided otherwise.
- Have a breach procedure. Section 22 requires notification of a security compromise. Decide now who is called, in what order, and who notifies the Regulator and the affected people.
- Handle data subject requests. Have a route for someone to ask what you hold, and a person responsible for answering within a reasonable time.
- Check your operators. Every supplier who processes data for you, from your bookkeeper to your hosting provider, should be under a written agreement that binds them to protect it.
- Train the people who touch the data. Most breaches in small businesses are ordinary human mistakes, not attacks. Our POPIA-aligned workplace AI policy template covers the AI-specific half of this, which matters now that staff paste client data into chat tools.
What happens if you get POPIA wrong?
The Act carries real teeth. Section 109 provides that an administrative fine issued by the Information Regulator "may, subject to subsection (10), not exceed R10 million". Section 107 sets criminal penalties for the more serious offences at a fine or imprisonment not exceeding 10 years, or both, with lesser offences carrying up to 12 months.
For a small business the realistic risk is not usually the maximum fine. It is the cost of an investigation you are unprepared for, the client who leaves because their information was mishandled, and the enforcement notice you then have to comply with under time pressure. Nearly all of that is avoidable with the checklist above.
Where small businesses actually slip
In practice, the failures are boring and repeatable:
- Customer data lives on one person's phone. When conversations sit only in a personal WhatsApp account, nobody can say what is held or delete it on request. Moving those threads into a proper system is a compliance move as much as a sales one, which is why we wrote about WhatsApp CRM for South African businesses.
- Nobody owns it. No registered Information Officer means no one is accountable, and that is itself a gap.
- Data is kept forever. Old lead lists and years-old ID copies sit in a drive because deleting them was never anybody's job.
- Tools are chosen before the data map exists. Buying a system before you know what you hold usually just moves the mess. The same trap applies to AI, which is why the work comes before the tool.
None of these are technology problems. They are the same quiet admin drift that produces the real cost of manual admin, showing up in a legal register instead of a time sheet. If you are choosing systems, the honest comparison of free CRMs in South Africa is a sensible next read, because where the data lives determines how hard the rest of this is.
Frequently Asked Questions
Does POPIA apply to small businesses in South Africa?
Yes. POPIA applies to any responsible party that processes personal information, with no exemption based on company size, turnover or headcount. A sole proprietor keeping a customer list is in scope in the same way a large company is.
Do I have to register an Information Officer?
Yes. Registration is done through the Information Regulator's portal, and the Regulator states that Information Officers must assume their duties only after the responsible party has registered them. In a small business this is normally the owner.
What is the maximum POPIA fine?
Section 109 caps an administrative fine at R10 million. Section 107 provides for criminal penalties of a fine or imprisonment not exceeding 10 years for serious offences, with up to 12 months for lesser ones.
Is WhatsApp allowed for customer conversations under POPIA?
The channel is not banned, but you remain responsible for the information in it. If client conversations live only in a personal WhatsApp account, you cannot reliably say what you hold, secure it, or delete it on request, which puts several conditions at risk.
How long can I keep customer data?
Only as long as you need it for the purpose you collected it for, unless a law requires you to keep it longer. The Act expects you to set and apply retention periods rather than keeping records indefinitely by default.
Sources
- Information Regulator of South Africa, official site: "Information Officers must assume their duties only after the responsible party has registered them with the Regulator." Registration portal: eservices.inforegulator.org.za. PAIA manual guidance: Information Regulator PAIA manuals.
- Protection of Personal Information Act 4 of 2013, Chapter 3: the eight conditions for lawful processing, sections 8 to 25.
- Protection of Personal Information Act 4 of 2013, section 109: administrative fine "may, subject to subsection (10), not exceed R10 million".
- Protection of Personal Information Act 4 of 2013, section 107: penalties, including imprisonment not exceeding 10 years for the more serious offences.
This is general information, not legal advice. Confirm your own obligations with a suitably qualified adviser.
Start with the data map, not the software
Every item on that checklist gets easier once you know where your information actually lives and which processes touch it. A Business Autopsy maps exactly that: the systems, the handoffs and the places data quietly accumulates, so compliance and efficiency get fixed by the same piece of work. Book a discovery call if you would rather talk it through first.