The Business List logo
Login   |   Register   |  Contact/Help   |  Subscriptions
 
 
SMMEs

POPI Act Compliance: The Practical Checklist for Small Businesses

A clear, practical POPIA checklist for South African SMMEs: map data flows, secure consent, limit retention, train staff and be ready to respond to breaches. Actionable steps you can implement this month.

Why POPIA matters for small businesses

The Protection of Personal Information Act (POPIA) affects every South African business that processes personal information — from a hair salon keeping client appointment notes to an online retailer storing customer addresses. Non-compliance can mean fines, reputational damage and difficulties doing business with larger partners who expect compliance. This checklist gives SMMEs a practical, step-by-step route to meet the law without a big legal bill.

POPIA compliance: the one-page checklist

Use this as an actionable roadmap. Tick items off, and assign an owner in your business.

  • 1. Map what personal information you hold

    List categories: customers (names, contact details), suppliers, employees, CCTV footage, marketing lists. Note where it’s stored: paper ledgers, Excel, cloud services, mobile phones.

  • 2. Identify lawful basis for processing

    Common bases include consent, performance of a contract, or legal obligation (e.g. payroll tax submissions to SARS). For marketing, ensure you have explicit consent for SMS/WhatsApp broadcasts.

  • 3. Create a short, clear privacy notice

    Tell people why you collect data, how long you keep it, and who you share it with. Put it on your website, invoices and in-store notices. Example: “We collect contact details to confirm bookings and send appointment reminders. We retain records for 3 years.”

  • 4. Limit collection and retention

    Only collect what you need. Set retention periods (e.g. 2–6 years for client records depending on sector) and schedule secure deletion. Keep a simple retention table.

  • 5. Secure data reasonably

    For small budgets there are effective steps: lock paper files, password-protect devices, enable 2-factor authentication on email, use reputable cloud providers, and encrypt backups. For CCTV, ensure footage access is restricted and signs are visible on site.

  • 6. Manage third parties and suppliers

    If you use payroll providers, e-commerce platforms or marketing agencies, have a written agreement stating they provide adequate protection and only process data as instructed.

  • 7. Appoint an Information Officer

    Small businesses can appoint an employee as Information Officer (or share a role). The Information Officer oversees compliance and acts as contact for data subject requests.

  • 8. Prepare for data subject rights

    Be ready to respond to requests for access, correction or deletion within POPIA time frames. Have a simple form and log to track requests and responses.

  • 9. Plan for breaches

    Create a short incident response plan: who to notify internally, how to contain the breach, where to log details, and when to inform the Information Regulator and affected individuals. Practise with tabletop scenarios.

  • 10. Train your team

    Run short, regular briefings on common risks: phishing emails, unsecured file sharing, proper disposal of paper records. Make data protection part of onboarding.

  • 11. Keep records of processing activities

    Maintain a basic register of processing activities: purpose, categories of data subjects, data recipients, and retention periods. This supports audits and supplier checks.

  • 12. Consider cross-border transfers

    If you store data on overseas servers or use foreign service providers, check whether transfers are allowed and document safeguards (e.g. provider’s security standards).

Practical examples for common SMMEs

Retail shop: keep a simple paper sign-up form for loyalty SMS with opt-in tick box and a privacy notice on the back of the till receipts. Delete inactive contacts after your set retention period.

Freelancer/consultant: store client deliverables in a passworded cloud folder, keep invoices for tax periods only, and avoid sharing client data via personal WhatsApp without consent.

Restaurant with CCTV: place visible signage, restrict access to footage, and retain footage for a short, justified period (e.g. 14–30 days) unless needed for an incident.

Low-cost tools and next steps

  • Use free templates from the Information Regulator to draft privacy notices and breach logs.
  • Enable built-in security on devices (disk encryption, strong passwords, auto-lock).
  • Buy simple staff training (half-day workshops) or watch short online modules as a team.
  • If unsure, consult a compliance specialist listed under The Business List South Africa (search POPIA consultants) for a targeted assessment.

POPIA compliance is practical and scalable. Start with mapping and quick wins — consent forms, basic security, and a breach plan — then build policies as your business grows. Demonstrating good data hygiene helps win trust from customers and partners in South Africa’s increasingly privacy-aware marketplace.

Action today: Pick one record type (customer list, payroll, CCTV), apply the checklist steps and set a 30-day deadline to close gaps. Small steps protect your business and your clients.