POPIA sounds like something only big corporates worry about β but if your business collects names, emails, ID numbers or any personal information (and almost every business does), it applies to you too. The good news: for a small business, compliance is mostly common sense plus a few concrete steps. Here’s what POPIA actually requires. This is educational, not legal advice β for complex processing, get professional input.
What is POPIA, in one sentence?
The Protection of Personal Information Act says you must handle other people’s personal information lawfully, securely, and only for legitimate purposes β and gives those people rights over their data.
The eight conditions (plain English)
POPIA is built on eight “conditions for lawful processing”. You don’t need to memorise the legalese, just the spirit:
- Accountability β someone in the business owns this.
- Purpose β collect data for a specific, lawful reason and say what it is.
- Minimality β collect only what you actually need.
- Consent & limitation β process it lawfully and don’t use it for unrelated things.
- Quality β keep it accurate and up to date.
- Openness β tell people what you collect and why (a privacy notice).
- Security β protect it with reasonable safeguards.
- Data-subject participation β let people see, correct or delete their data.
Your Information Officer
Every business has an Information Officer by default β for a small company, that’s usually the owner or a director. You should register your Information Officer with the Information Regulator. It’s a quick, free step that’s easy to overlook.
The practical minimum for a small business
- Write a plain privacy notice for your website and forms.
- Register your Information Officer with the Regulator.
- Get consent where you need it (especially for marketing).
- Lock down security β passwords, access control, encrypted backups.
- Have a simple way for people to request, correct or delete their data.
- Know your breach response β POPIA requires you to notify the Regulator and affected people of a serious breach.
POPIA and PAIA
POPIA sits alongside PAIA (access to information), which requires most businesses to have a PAIA manual. They’re often handled together as part of the same compliance pack.
Why tech and online businesses should care most
If you run a SaaS, app, online shop or agency, you process personal data at scale and often across borders β which raises the stakes (and may bring in extra obligations like data-processing agreements with clients). Building privacy in from the start is far cheaper than retrofitting it after a complaint.
Protect your clients’ data and your business. The IT, Software & Digital pack covers POPIA in depth β the eight conditions, registering your Information Officer, privacy notices, PAIA, data-processing agreements and breach response β alongside IP, contracts and export VAT for tech founders.


