TL;DR
- If you hold names, emails, ID numbers, or any personal information about customers or staff, POPIA applies to you. Every business does.
- For a typical SME, compliance is mostly common-sense data hygiene: inventory, purpose, consent, privacy notice, security, operators, breach plan, training.
- Use this page as a practical SME compliance checklist for POPIA: inventory, purpose, consent, notice, security, operators, breach plan, training.
- The four gaps SMEs most often miss: no data inventory, no test-restored backups, ex-employees still holding access, and a privacy policy that does not match reality.
- Fix those four and you have closed most of the common gaps.
- This is general guidance, not legal advice. Verify your specific obligations with a legal professional.
The Protection of Personal Information Act 4 of 2013 (POPIA) has been fully enforceable for a few years now, yet many South African SMEs still treat it as a big-company problem. It is not.
If you hold names, emails, ID numbers, or any personal information about customers or staff, and every business does, POPIA applies to you. Here is a practical checklist. This is general guidance, not legal advice. Verify your specific obligations with a legal professional. The Information Regulator monitors and enforces POPIA; Information Officer registration and related services run through the Regulator’s eServices portal.
What belongs on an SME compliance checklist in 2026?
An SME compliance checklist under POPIA is not a 200-page policy binder. For most Johannesburg and Gauteng businesses it is eight practical checks: know what personal information you hold, appoint and register an Information Officer, document why you collect each field, record consent where required, publish an accurate privacy notice, secure data with reasonable safeguards, vet operators and subprocessors, and rehearse breach response. Work through the sections below in order. Each heading is one check you can tick in a working session.
General guidance only, not legal advice. Reviewed by Jacques Joubert.
Do you know what personal information you hold?
You cannot protect or account for data you have not mapped. List what you collect (customers, staff, suppliers), where it is stored (email, CRM, spreadsheets, cloud, paper), and who can access it.
This “data inventory” is the foundation of everything else.
Have you appointed an Information Officer?
By default this is your head of the business (CEO/owner), and POPIA requires them to be registered with the Information Regulator.
You can delegate day-to-day tasks to a Deputy Information Officer. Confirm the current process on the Regulator’s eServices portal.
Do you have a clear reason for every piece of data?
POPIA requires you to collect personal information for a specific, lawful purpose and not keep it “just in case.”
Review your forms: are you asking for data you do not actually need? Minimise.
Do you get and record consent where it is required?
For marketing especially, you generally need consent, and people must be able to opt out easily.
Make sure your newsletter and contact forms explain what you will do with the data and link to your privacy policy.
Is your privacy notice published and accurate?
Tell people what you collect, why, who you share it with, and their rights (access, correction, deletion, objection).
A visible privacy policy page is the baseline. Most SMEs already need to update theirs.
Are you securing the data with reasonable safeguards?
POPIA requires “reasonable” technical and organisational safeguards. Practically: MFA on email and key systems, endpoint protection, encrypted backups, access limited to who genuinely needs it, and prompt removal of ex-staff access.
Most of these are ordinary good IT security, which is why a POPIA gap is usually also a security gap.
Do you manage third parties (operators) properly?
If a supplier processes personal information for you (your cloud provider, payroll bureau, email platform), POPIA expects a written agreement holding them to the same standards.
List your operators and check you have the paperwork.
Do you have a plan for data subject requests and breaches?
People can ask what you hold about them and request corrections or deletion. You need a way to handle that.
If a breach exposes personal information, you must notify the Information Regulator and affected people as soon as reasonably possible (see the Regulator’s guidance on inforegulator.org.za). Decide now who does what if it happens.
Is your team trained on the real risks?
The weakest link is usually a person clicking a phishing link or emailing a spreadsheet to the wrong address.
Short, regular awareness training closes more real-world POPIA risk than any single tool.
Do you review the checklist at least once a year?
Data, systems and staff change. Revisit this checklist at least once a year, and whenever you adopt a major new system.
Where do SMEs most often fall short?
No data inventory, no test-restored backups, ex-employees still holding access, and a privacy policy that does not match what they actually do.
Fix those four and you have closed most of the common gaps.
What should you do next?
Start with our free IT audit checklist, the backups and POPIA note for Johannesburg SMEs, or a free IT audit. For ongoing work, see cybersecurity and POPIA compliance.
POPIA compliance and IT security are the same job done well. African Vanilla helps Johannesburg and Gauteng businesses close both. Request a free security and compliance assessment.