compliance8 min read

POPIA Compliance Checklist for SA Businesses

A practical POPIA compliance checklist for South African businesses: data audits, lawful basis, Information Officers, breach plans and staff training.

What does POPIA actually require from a business?

POPIA places five duties on a business. Appoint and register an Information Officer, process personal information lawfully and for a stated purpose, secure it with reasonable technical and organisational measures, keep it only as long as needed, and notify the Information Regulator and affected people when it is compromised. The Protection of Personal Information Act (POPIA) came into full effect in July 2021, but years later, many South African businesses are still winging it. "We're too small to worry about that" is something we hear weekly. It's also something that won't hold up when the Information Regulator comes knocking.

POPIA isn't just paperwork; it's about trust. If you lose a client's personal data through negligence, the fine is painful (up to R10 million), but the reputation damage is often fatal. Customers don't forgive breach notifications.

What are the non-negotiable POPIA requirements?

Four things are non-negotiable: a registered Information Officer, a documented lawful basis and purpose for the personal information you hold, reasonable security safeguards, and a breach notification process.

  • Lawful Consent: Stop adding random people to your newsletter because you met them at a networking event. You need active, informed opt-in consent before processing personal information. Pre-ticked boxes don't count. Silence doesn't count. You need a clear "Yes, I want to receive this" action from the person.
  • Encryption at Rest: If a laptop is stolen from your employee's car, is the hard drive encrypted? (BitLocker for Windows, FileVault for Mac). If yes, it's an annoying hardware loss and you need to buy a new laptop. If no, it's potentially a data breach reporting event, and you have 72 hours to notify the Information Regulator and affected individuals. The difference is massive.
  • Encryption in Transit: Data moving across the internet must be encrypted. This means HTTPS on your website, TLS for your email servers, and VPN or encrypted connections for remote access to company systems. No excuses.
  • The Information Officer: You legally must designate someone as your Information Officer responsible for data protection in your organisation. If you haven't formally appointed someone, it defaults to the CEO. That CEO is then personally accountable. Most businesses delegate this to a senior manager or compliance officer, but it must be documented and registered.
  • Data Retention Policies: Delete those CVs from applicants you didn't hire three years ago. Hoarding data you don't need isn't an asset, it's a liability. Every record you hold is a potential breach vector. If you don't need it for a legitimate business purpose, delete it. Document your retention periods and actually enforce them.
  • Processing Agreements: Any third party that handles your customer data needs a formal operator agreement. This includes your IT provider, your accountant, your marketing agency, your cloud services, everyone. These agreements must specify how they protect data and what happens if they breach.

Which POPIA obligations do businesses most often miss?

The commonly missed obligations are written operator agreements with suppliers, a retention schedule that is actually enforced, and a working route for people to request or delete their data.

  • Your Website Privacy Policy: "We respect your privacy" is not a privacy policy. You need to specifically state what data you collect, how you use it, who you share it with, how long you keep it, and how people can request access or deletion. Your current policy was probably copied from a template in 2018. It needs updating.
  • Employee Training: Your receptionist, your sales team, your delivery drivers, everyone who handles personal information needs basic training on data protection. Knowing not to leave client files in an Uber is data protection. Update this training annually.
  • Subject Access Requests: If someone asks you "What data do you hold about me?", you must respond within 30 days with a complete answer. Do you have a process for this? Most businesses don't, until they receive their first request and panic.
  • Breach Response Plan: If data is compromised, what happens? Who makes decisions? Who contacts the regulator? Who drafts the notification to affected people? Having a plan before you need it is the difference between a contained incident and a public relations disaster.
POPIA: what is required, and what it means in practice
RequirementWhat it means in practice
Information OfficerBy default the CEO or business owner, registered with the Information Regulator
Lawful basis and purposeYou can say why you hold each category of personal information, and it is the reason you collected it
Security safeguardsReasonable technical and organisational measures: MFA, patching, encryption, access control, backups
Operator agreementsWritten contracts with any supplier that processes personal information for you
Retention limitsA schedule that says how long each record is kept, and evidence that it is deleted
Breach notificationNotify the Information Regulator and affected people as soon as reasonably possible after a compromise
Data subject requestsA route for people to ask what you hold, and to have it corrected or deleted

Where should a business start with POPIA compliance?

Start by writing down what personal information you hold, where it lives and who can reach it, because every other POPIA obligation depends on that inventory. POPIA compliance isn't a once-off project, it's an ongoing process. Start by:

  1. Auditing what personal data you actually hold and where it lives
  2. Documenting your lawful basis for processing each category of data
  3. Implementing technical controls (encryption, access control, backup)
  4. Training your staff
  5. Reviewing and updating your policies annually

If this feels overwhelming, you're not alone. Most businesses need external help for the initial setup. But the investment is far cheaper than the alternative. Start with our printable POPIA compliance guide, or book a POPIA compliance assessment and let us map the gaps for you.