POPIA: A Plain-English Guide to South African Privacy Law for Small Businesses

A practical guide to South Africa's Protection of Personal Information Act (POPIA) for businesses: who's covered, the eight conditions for lawful processing, the Information Officer, access via PAIA, breach notification, and penalties.

Last updated: 2026-06-23

If you process personal information in South Africa, POPIA applies to you — and it applies to businesses of every size. POPIA has been fully enforceable since 2021, and the Information Regulator has moved firmly into enforcement mode. This guide explains what's required.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified lawyer or privacy professional for guidance specific to your business. The information here is based on the Protection of Personal Information Act 4 of 2013 and guidance from the Information Regulator, as of the date below.

The Protection of Personal Information Act 4 of 2013 (POPIA) has required full compliance since 1 July 2021. It is regulated by the Information Regulator (South Africa), which administers both POPIA and the Promotion of Access to Information Act (PAIA).

Does This Law Apply to Your Business?

Yes. POPIA applies to any "responsible party" — a public or private body, or any other person — that determines the purpose and means of processing personal information. There is no size exemption. Two distinctive features:

  • It protects companies, not just people. POPIA's definition of "personal information" extends to identifiable juristic persons (companies), so information about your business customers can be protected too.
  • You are usually the "responsible party" and the people (or companies) whose data you hold are "data subjects."

What Rights Do Data Subjects Have?

RightSectionKey detail
Accesss23Confirm and obtain the personal information you hold (via PAIA)
Correction / deletions24Correct or delete inaccurate, irrelevant, or excessive information
Object to processings11(3)Object to processing on reasonable grounds
Direct marketing opt-outs69Electronic direct marketing requires opt-in consent
Not be profileds71Not be subject to a decision based solely on automated processing

Access requests are routed through PAIA: the information officer must generally decide within 30 days, extendable by up to a further 30. Private bodies must maintain a PAIA manual describing the records they hold.

What Your Business Must Do

POPIA is built on eight conditions for lawful processing: accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards, and data subject participation. Stricter rules apply to special personal information (health, religion, race, biometrics) and children's data.

Key practical steps:

  • Register your Information Officer with the Regulator. By default this is the head of the organisation (the CEO, MD, or owner), who must be registered before performing the role.
  • Map your processing with a data inventory and align it to the eight conditions.
  • Publish a privacy notice and prepare your PAIA manual (see do I need a privacy policy?).
  • Switch electronic direct marketing to opt-in consent — since the 2025 amended Regulations, opt-out is not valid consent.

Breach Notification

Under section 22, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, you must notify both the Information Regulator and the affected data subjects"as soon as reasonably possible" after discovery. Note POPIA has no fixed 72-hour deadline (that's the GDPR). Since 1 April 2025, breach notifications must be filed through the Regulator's eServices portal.

Penalties

POPIA carries administrative fines up to ZAR 10 million (via infringement notices) and criminal penalties of a fine or imprisonment up to 10 years for the most serious offences. The Information Regulator has shifted decisively from guidance to enforcement, issuing enforcement notices and fines across both sectors — though several have been challenged in court, so enforcement is real but contested. Individuals may also bring civil claims under section 99.

References

Last reviewed: June 2026. Privacy laws and regulations change. Verify all statutory references against the current text of POPIA and its Regulations and consult qualified legal counsel before making compliance decisions for your business.