← Guides

POPIA Act explained for small businesses in South Africa

5 min read · General information, not legal advice

Quick answer

The Protection of Personal Information Act 4 of 2013 (POPIA) applies to any business that collects personal information such as names, phone numbers, emails or ID numbers. Its main provisions have been enforced since 1 July 2021.

The eight conditions

Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. In plain terms: collect only what you need, say why, keep it safe and let people see or correct it.

Information Officer

The head of a business is its Information Officer by default (for a sole trader, that's you). Information Officers must be registered with the Information Regulator.

Privacy notice and consent

Tell people what you collect and why, usually in a privacy policy on your website. Direct marketing by email or SMS generally needs consent unless the person is an existing customer (section 69).

Security breaches

If personal information is accessed by someone unauthorised, you must notify the Information Regulator and the affected people as soon as reasonably possible.

Penalties

The Information Regulator can issue fines of up to R10 million, and serious offences can lead to imprisonment.

Free to fill in

Website Terms & POPIA Privacy Policy

Fill it in online free, preview it as you go, then download Word + PDF from R199.

Frequently asked questions

Does POPIA apply to small businesses?

Yes. POPIA has no small-business exemption; it applies to anyone processing personal information.

Do I need a privacy policy under POPIA?

You must tell people how you use their information, and a website privacy policy is the usual way to do that.

Is a PAIA manual the same as a POPIA policy?

No. A PAIA manual explains how people request records from you; a privacy policy explains how you use their personal information.