POPIA for a Small Business: What You Actually Have to Do, Explained Plainly
POPIA — the Protection of Personal Information Act — is one of the more commonly misunderstood compliance obligations among small business owners, usually in one of two opposite directions: either "that's only for big companies with call centres and customer databases" (wrong), or a vague sense that it requires an expensive, complicated compliance programme before a small business can safely operate (also generally wrong). The real obligation sits in between, and is genuinely achievable for a small company without specialist help for most of it.
Who POPIA actually applies to
The Information Regulator — the statutory body that administers POPIA — states plainly that any organisation, public or private, irrespective of its size, which processes personal information of data subjects is a "responsible party" under the Act. This explicitly includes individuals trading as sole proprietors and small businesses, not only registered companies above some size threshold. If your business keeps a customer list, an employee record, a supplier database, or even just an email newsletter sign-up, you are processing personal information and POPIA applies to you.
The one concrete step almost every business needs to take: register an Information Officer
Every responsible party is required to have an Information Officer — usually the business owner in a small company, or a director — responsible for ensuring POPIA compliance. Critically, the Information Regulator specifically confirms that sole proprietors and small businesses are obliged to register their Information Officer if they process personal information, on exactly the same basis as a large corporate. This registration is free, done directly with the Information Regulator, and is the single most commonly missed obligation among small businesses — many owners simply do not know it exists, or assume a privacy policy on their website is sufficient on its own (it isn't; the two are different requirements).
What POPIA actually requires you to do with personal information
Beyond registering an Information Officer, POPIA's substance sits in eight conditions for the lawful processing of personal information, running through the Act. In plain terms, for a small business, these boil down to a manageable set of practical habits:
- Collect only what you actually need for a genuine business purpose — not personal information gathered "just in case" it might be useful later.
- Tell people what you're collecting and why — a clear, honest explanation at the point of collection (a sign-up form, a job application, a contract), not information gathered silently.
- Use it only for the purpose you collected it for — a customer's details given for an invoice should not quietly become a marketing list without their knowledge.
- Keep it accurate and up to date where reasonably possible.
- Keep it secure — reasonable technical and organisational safeguards against loss, unauthorised access, or leaks, scaled to what a small business can reasonably implement (password-protected systems, controlled access, not leaving spreadsheets of customer details openly accessible).
- Don't keep it longer than necessary — a genuine retention practice, not an indefinite accumulation of every record the business has ever collected.
- Let people access and correct their own information on reasonable request — a data subject has rights over information held about them, including the right to ask what you hold and have errors corrected.
- Be accountable for all of the above — the responsible party (your business) carries the obligation, not an external processor you might use.
What this looks like for a genuinely small business, practically
For a business with a handful of staff and a modest customer base, reasonable POPIA compliance usually means: register an Information Officer, write a short and honest privacy notice for your website and any forms that collect personal information, keep customer and employee records reasonably secure (not published, not left on an unsecured shared drive), only use contact details for what customers actually agreed to, and have a basic sense of how long you keep old records before deleting them. This is achievable without hiring a compliance consultant for most small businesses — it becomes a genuinely specialist undertaking mainly once a business handles large volumes of sensitive personal information (health records, financial data at scale, biometric data) or operates in a sector with sector-specific rules layered on top.
What happens if you don't comply
The Information Regulator can investigate complaints, conduct its own monitoring, and issue compliance notices requiring a business to fix specific failures. Penalties for non-compliance can be serious — the Act provides for administrative fines and, for some specific offences (such as failing to notify the Regulator where prior authorisation for certain high-risk processing is required), a fine of up to R10 million or imprisonment of up to 12 months, or both. In practice, the Regulator's own public enforcement activity to date has focused heavily on genuine, serious failures — large data breaches, wilful non-compliance — rather than small businesses making an honest, reasonable effort. That said, "the Regulator probably won't come after a small business" is not the same as "the obligation doesn't apply", and a data breach involving customer or employee information is a real reputational and legal risk regardless of company size.
Where POPIA connects to the rest of running a compliant company
POPIA obligations sit alongside, but are separate from, the other compliance areas this series has covered — beneficial ownership (who owns the company) and FICA (financial crime and identity-verification obligations for certain businesses) both involve handling sensitive personal information, and getting POPIA's basic practices right makes those other obligations easier to satisfy honestly, rather than as four separate, disconnected compliance exercises.
Sources: the Information Regulator of South Africa's published guidance confirming POPIA applies irrespective of organisation size, and that sole proprietors and small businesses are obliged to register an Information Officer; the Information Regulator's stated penalty of a fine not exceeding R10 million or imprisonment not exceeding 12 months (or both) for specific notification offences under the Act. This is general information, not legal advice — a business handling sensitive personal information at scale, or uncertain about a specific processing activity, should get advice from a POPIA practitioner or attorney.
A worked example
A small retailer collects customer names, phone numbers and email addresses at checkout to send delivery notifications — a legitimate, disclosed purpose customers would reasonably expect. Six months later, the owner decides to use that same list to send a marketing newsletter about a new product range, without ever telling customers this second use was coming. This is exactly the kind of "further processing" POPIA's conditions are built to catch: the information was lawfully collected for one purpose (delivery notifications) and then used for a materially different one (marketing) without the data subject's knowledge or a lawful basis for the change. The fix is simple and cheap — a clear opt-in checkbox for marketing communications at the point of collection — but skipping it is a genuine POPIA compliance gap, not a technicality.
Frequently asked
Do I need a Deputy Information Officer as well? Only the Information Officer registration is required for most small businesses; a Deputy Information Officer is optional and generally only relevant once a business is large enough that one person can no longer reasonably handle all POPIA-related responsibilities alone.
Does POPIA apply if I only process South African customers' information, or does it matter where my business is based? POPIA applies to processing of personal information within South Africa, or by a responsible party based in South Africa, regardless of where the data subjects themselves are located — the trigger is where the processing happens and who is doing it, not solely the data subject's nationality or location.
Do employee records count as personal information under POPIA? Yes — an employee's ID number, contact details, banking details, and performance records are all personal information, and a small business's own payroll and HR records are subject to POPIA exactly as customer data is.
Is a privacy policy on my website enough on its own? No — a privacy policy (telling people what you do with their information) is one part of compliance, but it does not substitute for registering an Information Officer or for actually following the eight conditions in how the business genuinely handles personal information day to day.
What should I do if a customer asks what personal information I hold about them? POPIA gives data subjects the right to request access to, and correction of, their own personal information — a small business should have a simple, honest process for responding to such a request within a reasonable time, rather than no process at all.