POPIA Act explained for small businesses in South Africa
5 min read · General information, not legal advice
Quick answer
The Protection of Personal Information Act 4 of 2013 (POPIA) applies to any business that collects personal information such as names, phone numbers, emails or ID numbers. Its main provisions have been enforced since 1 July 2021.
The eight conditions
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. In plain terms: collect only what you need, say why, keep it safe and let people see or correct it.
Information Officer
The head of a business is its Information Officer by default (for a sole trader, that's you). Information Officers must be registered with the Information Regulator.
Privacy notice and consent
Tell people what you collect and why, usually in a privacy policy on your website. Direct marketing by email or SMS generally needs consent unless the person is an existing customer (section 69).
Security breaches
If personal information is accessed by someone unauthorised, you must notify the Information Regulator and the affected people as soon as reasonably possible.
Penalties
The Information Regulator can issue fines of up to R10 million, and serious offences can lead to imprisonment.
Free to fill in
Website Terms & POPIA Privacy Policy
Fill it in online free, preview it as you go, then download Word + PDF from R199.
Frequently asked questions
Does POPIA apply to small businesses?
Yes. POPIA has no small-business exemption; it applies to anyone processing personal information.
Do I need a privacy policy under POPIA?
You must tell people how you use their information, and a website privacy policy is the usual way to do that.
Is a PAIA manual the same as a POPIA policy?
No. A PAIA manual explains how people request records from you; a privacy policy explains how you use their personal information.



