POPIA came fully into force in 2021, but many small businesses still treat it as a large-corporate concern. In truth, if your business holds any personal information about customers, staff, or suppliers — names, emails, ID numbers, bank details — you are an accountable 'responsible party' under the Act.
The core obligations are practical: appoint an Information Officer, maintain a record of processing activities, obtain lawful consent before processing personal information, and secure that information against loss or breach. A breach must be notified to the Information Regulator and affected parties.
Start with the basics: a simple data inventory, a privacy policy published on your website (see ours here), consent captured at the point of collection, and access controls on any system holding personal data. Contracts with third-party processors (like payroll or cloud providers) must include POPIA-compliant clauses.
We help clients build a POPIA compliance baseline without over-engineering it — a proportionate set of policies, notices, and processor agreements matched to the size of the business.
This article is general information and not advice on your specific circumstances. Please speak to us before acting on it.
