Legal support & compliance services — not an admitted attorney; we do provide legal advice on non-reserved matters, but no reserved work or court representation.Read our full disclaimer

CIPC Reg 2026/518678/07

All resources
Compliance8 min read

POPIA in plain English for small businesses

The eight conditions for lawful processing, what an Information Officer actually does, and a 7-step starting plan for SMEs.

The Protection of Personal Information Act (POPIA) applies to almost every South African business that handles personal information — which is almost every business. Compliance is not a one-off project; it is an operating discipline. The good news: a small business can reach a defensible baseline in a few weeks.

The eight conditions for lawful processing

  • Accountability — someone must own POPIA in your business (your Information Officer).
  • Processing limitation — only collect what you need, only with a lawful basis (consent, contract, legal duty, legitimate interest).
  • Purpose specification — tell people why you are collecting their information.
  • Further processing limitation — don't repurpose data for something incompatible.
  • Information quality — keep it accurate and up to date.
  • Openness — publish a privacy notice that people can actually read.
  • Security safeguards — appropriate technical and organisational measures.
  • Data subject participation — let people access, correct or delete their data.

What does an Information Officer actually do?

By default the head of your business (the CEO, MD or sole proprietor) is the Information Officer. You can delegate specific duties to a deputy. The role is to register with the Information Regulator, develop and roll out compliance policies, handle data-subject requests, manage breaches, and report annually.

Your 7-step starting plan

  • 1. Register your Information Officer with the Information Regulator (online, free).
  • 2. Map your data: what you collect, why, where it is stored, who it is shared with.
  • 3. Publish a plain-language privacy notice on your website and in your contracts.
  • 4. Get consent clauses into your client onboarding, employment and supplier contracts.
  • 5. Put basic security in place: strong passwords, MFA, backups, locked filing cabinets, access controls.
  • 6. Write a short breach-response plan so you know who does what if data is leaked.
  • 7. Train your team once a year and keep a register of training.

Common SME mistakes

  • Treating consent as a tickbox at the bottom of every form — consent must be specific, informed and voluntary.
  • Forgetting employee data — payslips, ID copies and CVs are personal information too.
  • Sharing client data with marketing tools without a written processor agreement.
  • Keeping data 'forever' instead of having a retention schedule.

How we help

We run a POPIA readiness assessment, deliver a starter pack of policies (privacy notice, consent clauses, breach plan, retention schedule, processor agreement template), and train your team. Book a consultation to start.

We do provide legal advice — but only on non-reserved matters. Nkadimeng Danny Legal and Compliance Support provides legal information and legal advice on non-reserved matters and prepares legal opinions. We are not a firm of admitted attorneys, so we do not undertake work reserved by the Legal Practice Act 28 of 2014 and we do not represent clients in court. See our full scope.

Nkadimeng Danny is not an admitted attorney. We provide legal information, legal advice on non-reserved matters and legal opinions — we do not take reserved work or represent clients in court. Read full disclaimer.