South African business team reviewing POPIA information-protection controls

POPIA compliance can feel abstract until a customer questionnaire, tender, insurer or security incident asks you to prove what your business actually does. For a small or medium South African business, the practical goal is not a folder of policies that nobody uses. It is a defensible way to collect, use, protect, retain and delete personal information—supported by day-to-day controls that can be shown to an auditor, customer or regulator.

This guide explains a sensible starting point. It is written for business owners, finance leaders and practice managers, not lawyers. It does not replace legal advice, and your obligations will depend on the information you process and the purpose for which you process it.

What is POPIA, and who does it apply to?

The Protection of Personal Information Act 4 of 2013 (POPIA) regulates the processing of personal information in South Africa. Its main provisions have applied since 1 July 2021. In practice, POPIA affects almost every business that handles information about customers, employees, suppliers, directors, website visitors or other identifiable people.

“Processing” is deliberately broad. It includes collecting, storing, viewing, changing, sharing, backing up, archiving and deleting information. Personal information is also broader than an identity number. It can include contact details, employment records, financial information, correspondence, device identifiers and opinions about a person.

POPIA distinguishes between three important roles:

  • Data subject: the person to whom the information relates.
  • Responsible party: the organisation or person that determines why and how the information is processed.
  • Operator: a service provider that processes information for a responsible party under a contract or mandate.

Your business remains accountable when an operator processes information on its behalf. Cloud platforms, payroll providers, marketing systems, backup providers and IT support companies should therefore be considered in your compliance work.

Does POPIA apply to a small business?

Usually, yes. POPIA does not create a general exemption merely because a business has few employees or limited turnover. The scale and sensitivity of your processing should, however, influence what measures are reasonable.

A five-person consultancy and a national retailer do not need identical controls. Both should be able to explain what personal information they hold, why they need it, who can access it, which suppliers process it and how it is protected. The smaller organisation may use simpler records and processes, but “small” is not the same as “unaccountable”.

The eight conditions for lawful processing

POPIA organises its core requirements into eight conditions. A useful compliance plan should connect each condition to evidence that exists in the business.

Condition Plain-language meaning Practical evidence
Accountability The responsible party must ensure compliance. A named Information Officer, an approved framework, assigned actions and review dates.
Processing limitation Process information lawfully, reasonably and only to the extent needed. Lawful-purpose records, consent where appropriate, and forms that do not collect unnecessary data.
Purpose specification Collect information for a specific lawful purpose and do not keep it indefinitely. A retention schedule and a process for secure deletion or de-identification.
Further processing limitation Do not reuse information in a way that is incompatible with the original purpose. Change-control or review before data is reused, exported or shared for a new purpose.
Information quality Keep information complete, accurate, current and not misleading. Processes for updates, corrections and removal of stale records.
Openness Be transparent about collection and processing. Privacy notices at the point of collection, a PAIA manual where required, and supplier transparency.
Security safeguards Protect the integrity and confidentiality of information with reasonable measures. Access control, MFA, patching, endpoint protection, backups, logging, incident response and operator agreements.
Data subject participation Let people access and, where justified, correct or delete their information. A documented request process, identity verification and response records.

Responsible Party, Operator and Information Officer

The responsible party decides the purpose and means of processing. An operator acts for that responsible party. A written operator agreement should require appropriate security, confidentiality and timely incident reporting; a supplier’s standard terms should be reviewed rather than assumed to be sufficient.

For a private body, the head of the organisation is ordinarily the Information Officer by law. Deputy Information Officers can be designated where appropriate. Information Officers must be registered with the Information Regulator before taking up their duties, and the Regulator’s eServices portal provides the current registration service.

The role is not ceremonial. It includes encouraging compliance, handling requests, working with the Regulator and ensuring that a compliance framework is developed, implemented, monitored and maintained. The Information Officer needs authority, access to the right people and a practical action register.

What does POPIA expect from your IT?

Section 19 requires appropriate, reasonable technical and organisational measures. It does not prescribe one product or checklist for every business. The business should identify reasonably foreseeable risks, establish safeguards, verify that they work and update them as risks change.

For a typical small or medium business, the following controls form a practical baseline:

1. Identity and access control

  • Give each user a unique account and prohibit shared administrator credentials.
  • Use multi-factor authentication for Microsoft 365, remote access, finance systems and other important services.
  • Apply least privilege: users and administrators should have only the access their roles require.
  • Review access regularly and remove it promptly when someone leaves or changes role.

2. Managed devices and patching

  • Maintain an inventory of business laptops, desktops and servers.
  • Apply supported operating-system and application updates consistently.
  • Use endpoint protection and monitor alerts rather than installing software and assuming it remains effective.
  • Encrypt portable devices where feasible and define how lost devices are reported and contained.

3. Email and domain security

  • Protect email accounts with MFA and sensible conditional-access policies.
  • Maintain SPF, DKIM and DMARC to reduce domain impersonation and improve email authenticity.
  • Use layered filtering and a clear process for reporting suspicious messages.
  • Verify changes to banking details and urgent payment requests through a separate trusted channel.

4. Backup and recovery

  • Define which systems and information must be backed up.
  • Keep protected copies separate from the production platform so one compromised account or service does not expose both.
  • Monitor backup failures and test whether important data can actually be restored.
  • Document recovery priorities: not every system has the same business impact.

For covered Microsoft 365 workloads, Primeworks can back up mailboxes, OneDrive, SharePoint and Teams data every 24 hours to a separate, non-Microsoft platform. That reduces dependence on the production environment while still requiring sensible retention and recovery decisions.

5. Supplier and cloud oversight

  • Record which suppliers receive or can access personal information.
  • Review contracts, data locations, breach obligations, retention and termination arrangements.
  • Remove obsolete integrations and supplier accounts.
  • Keep evidence of due diligence proportionate to the risk.

6. Logging and incident readiness

  • Retain useful logs for important systems and review meaningful alerts.
  • Give staff a simple way to report a lost device, wrong recipient, suspicious login or accidental disclosure.
  • Maintain an incident plan with decision-makers, technical contacts and legal or regulatory escalation.
  • Run a short tabletop exercise so roles are understood before a real incident.

What must you do after a personal-information breach?

A security compromise is more than a cyberattack. It can include an email sent to the wrong person, a lost unencrypted device, excessive access, exposed files or stolen credentials.

Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, section 22 requires notification to the Information Regulator and affected data subjects, subject to the Act’s requirements. Notification should be made as soon as reasonably possible after discovery, while considering legitimate needs such as establishing the scope and restoring system integrity. The Regulator provides official guidance and an eServices route for reporting security compromises.

Do not wait for an incident to decide who investigates, who communicates, what evidence is preserved or who can authorise notifications. Those decisions belong in the incident plan.

What are the penalties?

POPIA allows regulatory investigation, enforcement notices, civil claims and criminal offences for specified contraventions. Serious offences can carry fines or imprisonment, and the Act provides for administrative fines up to R10 million in defined circumstances. The maximum penalty does not automatically apply to every compliance gap, but reputational damage, business interruption, customer claims and contractual consequences may be more immediate than a fine.

A practical 90-day starting plan

Days 1–30: establish the facts

  1. Confirm and register the Information Officer and any deputies.
  2. List the main categories of personal information, purposes, systems, locations and recipients.
  3. Identify high-risk information and processing, including employee, financial and special personal information.
  4. Record key operators and collect the relevant contracts.
  5. Fix urgent access issues: departed users, shared admin accounts, missing MFA and unsupported devices.

Days 31–60: put the framework into operation

  1. Update privacy notices so people are informed at the point of collection.
  2. Define retention and secure-deletion rules for the most important records.
  3. Adopt operator requirements and a supplier review process.
  4. Document data-subject request handling and identity verification.
  5. Build the incident-response and breach-notification workflow.

Days 61–90: test and evidence

  1. Test recovery of a representative set of important data.
  2. Review privileged access and Microsoft 365 security settings.
  3. Run a phishing-awareness or incident exercise.
  4. Complete a proportional personal-information impact assessment for higher-risk activities.
  5. Record findings, owners, deadlines and evidence in a living improvement plan.

POPIA small-business checklist

  • Information Officer registered and responsibilities documented
  • Personal-information and supplier register maintained
  • Lawful purposes and collection notices reviewed
  • Retention and secure-deletion rules approved
  • Unique accounts, MFA and least privilege applied
  • Leaver access removed promptly
  • Managed patching and endpoint protection operating
  • Email and domain security maintained
  • Separate, monitored backups and recovery tests in place
  • Operator agreements and supplier risks reviewed
  • Incident and breach-notification plan tested
  • Data-subject request process documented
  • Actions, evidence and review dates tracked

Where should your business start?

Start with the information and systems that would cause the most harm if they were unavailable, altered or disclosed. The first useful deliverable is usually a short, prioritised action plan—not a generic policy pack.

Primeworks helps South African businesses translate security obligations into practical technology controls: managed IT support, Microsoft 365 administration, endpoint security, domain and email protection, and monitored data backup. We do not provide legal advice, but we can help you understand the current technical position, close avoidable gaps and produce evidence of the controls being managed.

Request an IT assessment or review our privacy policy.

Frequently asked questions

Does POPIA apply to every small business in South Africa?

POPIA generally applies when a business processes personal information. There is no broad exemption based only on company size or turnover, although the safeguards and records used should be proportionate to the nature and risk of the processing.

Who should be the Information Officer?

For a private body, the head of the organisation is ordinarily the Information Officer by law. Deputy Information Officers may be designated where appropriate. The role should have enough authority and access to oversee a practical compliance programme.

Does using Microsoft 365 make a business POPIA compliant?

No single platform makes a business compliant. Microsoft 365 can support appropriate security controls, but the business must still configure access properly, use multi-factor authentication, manage devices and suppliers, apply retention decisions, maintain backups and operate documented processes.

Must a business report every security incident?

Not every IT event is automatically a reportable security compromise. Where there are reasonable grounds to believe that personal information was accessed or acquired by an unauthorised person, POPIA requires notification in line with section 22. Legal advice may be appropriate when the facts are uncertain.

Can Primeworks certify POPIA compliance?

No. Primeworks does not provide legal certification or legal advice. We help businesses assess and improve the technical controls that support their obligations, including managed IT, Microsoft 365 administration, endpoint security, email protection and monitored backup.

Official sources