The Protection of Personal Information Act (POPIA) applies to almost every business in South Africa. If you keep customer contact details, employee records or supplier information, you are a "responsible party" under the Act.
1. Register your Information Officer
By default the head of the business (for example the CEO or managing director) is the Information Officer. Register them with the Information Regulator through its online portal.
2. Know what information you hold
List the personal information you collect, why you collect it, where it is stored and who can access it. You can't protect what you don't know about.
3. Publish a privacy notice
Tell people what you collect, why, who you share it with and how they can exercise their rights. Put it on your website and refer to it in your forms.
4. Collect only what you need, and get consent
Ask only for the information you need for a clear purpose. Where you rely on consent, such as for marketing emails, make it specific and keep a record of it.
5. Secure the information
Use strong passwords and multi-factor authentication, limit access, encrypt devices and lock away paper files. Train your staff, because most breaches start with human error.
6. Put agreements in place with operators
Your payroll provider, IT company, cloud software and accountant process information for you. You need written agreements requiring them to keep it secure.
7. Have a breach plan
If personal information is accessed without authority, you must notify the Information Regulator and affected people as soon as reasonably possible. Know in advance who does what.
This article is general information based on the law and SARS guidance as at 27 May 2026. It is not tax or legal advice for your specific situation. Please contact us before acting on it.



