Skip to Content

Managed POPIA Compliance for South African Businesses

Data-protection compliance under POPIA, delivered as a managed service. In development now, with early access for clients who want the framework in place before the Information Regulator comes knocking.

POPIA is enforced, not optional

The Protection of Personal Information Act (POPIA) requires every organisation that processes personal information to do so lawfully, to register an Information Officer with the Information Regulator, and to maintain appropriate safeguards, records and policies. The Regulator has moved from guidance to active enforcement, including assessments and administrative fines for non-compliance.

The POPIA readiness checklist

POPIA applies to every responsible party domiciled in South Africa that processes personal information. There is no exemption based on headcount or turnover. Below is the full checklist, free to read and free to download. It reflects the position as at August 2026, including the amended Regulations of 17 April 2025 and the move to portal-only breach reporting from 1 April 2025.

1. Accountability and roles

Condition 1 of the eight conditions for lawful processing is Accountability, section 8. Sections 55 and 56 deal with the Information Officer. Regulation 4, as amended on 17 April 2025, sets out that officer’s responsibilities.

  1. Confirm who your Information Officer is

    In a private body the Information Officer is the chief executive officer, the owner or the partner by default. That person may authorise someone else in writing, but the head of the body stays accountable.

    POPIA s1 read with s55
  2. Register the Information Officer with the Regulator

    An Information Officer takes up duties only after registration with the Information Regulator, done on the eServices portal.

    POPIA s55(2)
  3. Designate deputy Information Officers

    One or more deputies keep the organisation reachable for data subjects and requesters. The Regulator expects deputies to sit at management level.

    PAIA s17
  4. Develop and continually improve a compliance framework

    The framework must be developed, implemented, monitored, maintained and continually improved. A document written once in 2021 no longer meets the wording.

    Regulation 4(1)(a), amended 17 April 2025
  5. Publish and maintain a PAIA manual

    Every private body must have a manual, on its website, at its principal place of business, on request, and to the Regulator. The small-body exemption lapsed on 31 December 2021.

    PAIA s51

2. Lawful processing and transparency

Conditions 2 to 6 cover processing limitation (s9 to s12), purpose specification (s13 and s14), further processing (s15), information quality (s16) and openness (s17 and s18).

  1. Map the personal information you hold

    List what you collect, why, where it sits, who can see it and who you share it with. Without this you cannot evidence a lawful basis, a retention period or a control.

    POPIA s17
  2. Confirm a lawful justification for each purpose

    The grounds are consent, contract necessity, a legal obligation, protecting the data subject legitimate interest, a public law duty, or legitimate interests. Consent is one option, not the default.

    POPIA s11
  3. Give a collection notice to data subjects

    At collection, tell the person what you are collecting, who you are, why, whether supply is voluntary, the consequences of not supplying, and their rights.

    POPIA s18
  4. Handle special personal information with care

    Religion, race, trade union membership, political persuasion, health, sex life, biometrics and criminal behaviour are prohibited unless a listed ground applies.

    POPIA s26 to s33
  5. Check whether prior authorisation applies

    Prior authorisation is needed for defined processing, including credit reporting and certain cross-border transfers of special or children information.

    POPIA s57
  6. Set and apply retention and deletion rules

    Records may not be kept longer than necessary for the purpose, and must be destroyed, deleted or de-identified as soon as reasonably practicable once retention is no longer authorised.

    POPIA s14 and s14(4)

3. Security safeguards and third parties

Condition 7 is Security safeguards, sections 19 to 22. Section 72 governs transfers outside South Africa.

  1. Implement reasonable technical and organisational measures

    Identify foreseeable internal and external risks, put safeguards in place, verify regularly that they work, and update them as risks change. The Regulator first fine concerned expired security licences.

    POPIA s19
  2. Put written operator contracts in place

    Payroll bureaus, cloud providers, IT support, recruiters and marketing agencies are operators. Each needs a written contract obliging them to maintain your security measures.

    POPIA s21
  3. Check transfers outside South Africa

    Foreign hosted email, cloud storage and software as a service must be assessed against the listed transfer grounds before you rely on them.

    POPIA s72

4. Data subject rights, complaints and direct marketing

Condition 8 is Data subject participation, sections 23 to 25. Section 69 governs unsolicited electronic direct marketing.

  1. Build a data subject request process

    People may ask what you hold and request correction or deletion of information that is inaccurate, excessive, out of date, misleading or unlawfully obtained.

    POPIA s23 to s25
  2. Accept objections free of charge on multiple channels

    Since April 2025 an objection may come by hand, post, email, SMS, WhatsApp or telephone, free of charge. Telephonic objections must be recorded.

    Regulation 2, amended 17 April 2025
  3. Get direct marketing consent right

    Unsolicited electronic direct marketing needs consent, and you may approach a person for that consent once only. Existing customers may be marketed similar products with an opt-out in every message.

    POPIA s69
  4. Register on the National Opt-Out Registry if you direct market

    From 15 April 2026 direct marketers must register with the National Consumer Commission and cleanse their databases monthly against the registry. POPIA consent duties continue to apply alongside this.

    CPA Amendment Regulations, 2026
  5. Run a documented complaints process

    Complaints may be lodged on the prescribed form or one substantially similar, and must be acknowledged. A complaints register is useful evidence.

    Regulation 7, amended 2025

5. Breach response and enforcement readiness

Section 22 governs security compromise notification. Chapter 10 governs enforcement, and sections 107 to 109 the penalties.

  1. Report security compromises through the eServices portal

    Where there are reasonable grounds to believe personal information was accessed by an unauthorised person, notify the Regulator and the affected people as soon as reasonably possible. Since 1 April 2025 reporting is through the portal, not email.

    POPIA s22
  2. Prepare a breach playbook and keep records

    The Regulator fact sheet of 19 August 2025 states there is no minimum threshold, so all security compromises are reportable, and that you report before the investigation is finished.

    Regulator fact sheet, 19 August 2025
  3. Be ready for a compliance monitoring request

    Since late 2025 the Regulator has been selecting organisations and requiring a POPIA compliance report with supporting documents within 14 business days.

    POPIA s89

What POPIA non-compliance costs

  • Administrative fine: up to R10 million by infringement notice under section 109. Fines issued to date include R5 million twice, R500 000 and R100 000 twice.
  • Criminal: a fine set by the court, or imprisonment of up to 10 years for the more serious offences and up to 12 months for the rest, under section 107. The often-quoted R10 million or 10 years conflates two different provisions.
  • Civil: a data subject may claim damages whether or not there was intent or negligence, under section 99. There is no stated cap.
  • The pattern worth noting: every administrative fine so far followed a failure to comply with an enforcement notice, not the underlying contravention on its own.

Get the checklist as a PDF, and early access to the POPIA app

Same content as above, laid out as a working document with tick boxes so you can walk it with your team. Leave your details and the PDF downloads straight away. We will also let you know when the POPIA app opens, before the general release.

Your checklist is on its way down

Thanks. The PDF should have started downloading. If it did not, use the button below. We will email you when the POPIA app opens for early access.

Download the POPIA checklist (PDF)

We use your details to send the checklist and to tell you when the POPIA app is available. We do not sell or share your details. You can ask us to delete them at any time by emailing [email protected]. This checklist is general information about published law, not legal advice, and GRC Shop is not a law firm.

What the POPIA app will manage

The POPIA app is your live data-protection record, with our team doing the work behind it.

  • Information Officer registration and ongoing support
  • A processing register: what personal data you hold, why, and where it flows
  • Data subject request workflow (access, correction, deletion)
  • A PAIA manual aligned to the required format
  • Breach response and notification readiness
  • Data retention and destruction schedules

Status: in development

The POPIA app is in active development. OHS is the live app today; POPIA is next. If POPIA is your pressing risk, contact us about early access so your framework is in place from day one.

POPIA questions we get asked

Do I need to register an Information Officer?

Yes. POPIA requires every responsible party to register an Information Officer (by default the head of the organisation, or a delegate) with the Information Regulator. That officer is accountable for the organisation’s compliance.

Is the POPIA app available now?

It is in development. OHS is the live app today; POPIA is the next release. Contact us if you want early access while it is finalised.

Does POPIA apply to a small business with only a few employees?

Yes. POPIA applies to any responsible party domiciled in South Africa that processes personal information, with no exemption based on employee numbers or turnover. The only general exclusions are in section 6, which covers purely household or personal activity, sufficiently de-identified information, and certain state functions.

Do I have to register my Information Officer with the Information Regulator?

Yes. Section 55(2) of POPIA provides that an Information Officer takes up duties only after registration with the Regulator. Registration is done through the eServices portal, which replaced the earlier registrations portal on 1 May 2024.

How quickly must I report a data breach?

Section 22(2) requires notification to the Regulator and affected data subjects as soon as reasonably possible after discovering the compromise. POPIA sets no fixed hour count. Since 1 April 2025 the Regulator requires reports through its eServices portal rather than by email, and its August 2025 fact sheet states there is no minimum severity threshold, so all security compromises are reportable.

What is the maximum fine under POPIA?

The maximum administrative fine the Information Regulator may impose by infringement notice is R10 million under section 109. Criminal penalties under section 107 are a fine of an amount determined by the court, or imprisonment of up to 10 years for the more serious offences and up to 12 months for the less serious ones, or both. Section 99 also allows civil damages claims with no stated cap.

Do I still need a PAIA manual?

Yes. Section 51 of PAIA requires every private body to have a manual and make it available on its website, at its principal place of business, on request, and to the Regulator. The exemption that previously covered smaller private bodies lapsed on 31 December 2021. The April 2025 amendment removed the PAIA manual duty from the Information Officer POPIA responsibilities, but the obligation itself remains under PAIA.

Interested in POPIA?

Tell us where you stand. We'll come back inside one business day with a tailored scope.

Explore: All apps · Platform · FAQ · Resources · Contact