Back to InsightsCompliance

POPIA compliance checklist for SMBs in 2026

The Information Regulator is actively enforcing POPIA. Here's a plain-English checklist to ensure your business handles personal data lawfully — without needing a lawyer for every step.

April 20266 min read

The Protection of Personal Information Act (POPIA) has been fully in force since 2021, and the Information Regulator has moved from warnings to active enforcement — including fines, compliance notices, and public naming of non-compliant organisations. Fines can reach R10 million per incident. Yet most South African SMBs still only meet one or two of POPIA's eight legal conditions.

This isn't a checklist that requires a legal team to work through. It's the same set of practical questions we use with clients — written in plain language, focused on what the Regulator actually looks for first.

POPIA applies to every business that processes personal information — names, ID numbers, contact details, employee records, client data — regardless of size. There is no small-business exemption.

1. Accountability — do you have an Information Officer?

Every business must appoint an Information Officer (usually the owner or a senior manager) and register them with the Information Regulator. This person is accountable for POPIA compliance across the business.

  • Have you appointed and registered an Information Officer?
  • Do you have a written data protection policy, even a short one?
  • Does at least one other person in the business know what that policy says?

2. Processing limitation — are you only collecting what you need?

POPIA requires that you only collect personal information that is adequate, relevant, and not excessive for the purpose. A sign-up form that asks for a customer's ID number when all you need is their name and email is a common, easily fixed violation.

  • Do your forms (web, paper, WhatsApp) only ask for information you actually use?
  • Have you reviewed what your CRM, invoicing, and marketing tools store about people?

3. Purpose specification and further processing

You must tell people why you're collecting their information, and you can't later use it for something unrelated without new consent. Collecting an email for a quote, then adding that person to a marketing newsletter without asking, is a textbook breach.

  • Does every form or contract state clearly what the data will be used for?
  • Do you have a process for getting fresh consent before using data for something new?

4. Openness — is there a privacy notice people can actually find?

A privacy policy buried in a footer link, written entirely in legal jargon, technically exists but doesn't meet the spirit of the "openness" condition. It needs to be genuinely accessible and understandable.

  • Is your privacy notice linked from every page that collects data?
  • Would a non-technical customer understand it in under two minutes?

5. Security safeguards — what happens if you're breached?

This is the condition most SMBs fail hardest, and the one with the sharpest legal teeth: POPIA requires you to notify the Information Regulator and affected individuals as soon as reasonably possible after discovering a data breach.

  • Do you have basic technical safeguards — access controls, backups, secure email (see our DMARC guide)?
  • Do you have a written breach response plan, even a one-page version?
  • Would you actually notice if a breach happened?

6–8. Data subject participation, further conditions, and special personal information

The remaining conditions cover a person's right to access, correct, or request deletion of their own data; restrictions on cross-border data transfers; and stricter rules for "special" categories of information such as health, religious belief, or biometric data. Most SMBs need targeted fixes here rather than a full overhaul — but they still count toward your overall compliance score.

What non-compliance actually costs

Beyond the statutory maximum fine of R10 million or up to 10 years' imprisonment for serious offences, the more common cost for SMBs is reputational: a public compliance notice, a breach disclosure that damages client trust, or losing a tender because a corporate client's procurement team requires proof of POPIA compliance before signing.

The good news is that closing these gaps is usually far cheaper and faster than businesses expect — most of it is documentation and a handful of process changes, not new software.

Score your business in 2 minutes

Answer 20 practical questions and get an instant compliance score, gap analysis, and costed remediation plan — free.

Run the free POPIA checklist