Contact

BlogManaged IT

Managed IT

POPIA Compliance for Small Businesses: A Practical Website & Data Checklist

A practical POPIA checklist for South African small businesses: website privacy and consent, data and access controls, email security, where your data lives, and what to do if a breach happens.

Derick PayneDerick PayneFounder and lead developer

Published 16 June 2026Read 9 min

On this page
  1. Does POPIA apply to my small business?
  2. What changed in 2025?
  3. What does my website need?
  4. How do I protect the data in my systems?
  5. What do I need from my IT provider and other suppliers?
  6. Can my data be stored outside South Africa?
  7. What do I do if there is a breach?
  8. Where should I start?
  9. Common questions
  10. What is the practical next step?

POPIA applies to any South African business that collects personal information, including through a website contact form. To comply, publish an honest privacy policy, collect only what you need, ask for real opt-in consent before marketing, secure your email and systems, know where your data is stored, and report breaches through the Information Regulator’s portal.

This is a practical checklist for owners and managers, not lawyers. It is guidance, not legal advice: for a decision with real legal risk, ask a POPIA attorney. Every rule below links to its source, so you can check it yourself.

Does POPIA apply to my small business?

Yes, if you collect, store or use personal information about customers, staff or suppliers: names, email addresses, ID numbers or payment details. That makes you a “responsible party” under the Protection of Personal Information Act 4 of 2013 (the Act), and you are accountable for that information.

The Act has been fully enforced since 1 July 2021. Most of it began on 1 July 2020, and section 114(1) gave businesses one year to “conform to this Act”. The Regulator called 1 July 2021 “the full implementation and enforcement of POPIA” (Information Regulator, 24 March 2021).

You also need a registered information officer. For a private business that is the head of the organisation, usually the owner or managing director, and the Regulator says plainly that “registration is not optional” (eServices portal). Section 55(2) says officers may take up their duties “only after the responsible party has registered them”.

The penalties are real but narrower than many summaries suggest. An administrative fine for an offence under the Act may not exceed R10 million (section 109). Prison terms of up to 10 years apply only to specific offences listed in section 107, such as obstructing the Regulator or ignoring an enforcement notice.

What changed in 2025?

Two things. On 17 April 2025 the amended POPIA Regulations were published “for implementation with immediate effect” (GN 6126, Government Gazette 52523). Regulation 6.4 now says that for electronic direct marketing, “opt-out shall not constitute consent”. The consent request may use a form “substantially similar to Form 4”, by email, phone, SMS or WhatsApp.

Second, since 1 April 2025 it “is mandatory for all organisations to report any security compromises using the portal, rather than via email” (Information Regulator, 7 April 2025).

What does my website need?

Your website is usually the first place you collect personal information, through a contact form, a quote request, a newsletter signup or a checkout. Start here.

  • An honest privacy policy. Name the responsible party and your information officer, what you collect and why, how long you keep it, who else handles it, where it is stored, and how people exercise their rights. A copied template with another company’s name in it is worse than nothing.
  • Real opt-in consent for marketing. Section 69 prohibits electronic direct marketing unless the person consented or is an existing customer. You may ask for consent “only once”, and an unticked box the person chooses to tick is the safe pattern. Since April 2025, an opt-out is not consent.
  • Cookies, decided deliberately. POPIA has no cookie rule. But the Act counts an “online identifier” as personal information, so cookies that identify a person must meet the same conditions as any other data. A clear choice before non-essential cookies load is the sound way to do that.
  • Only the fields you need. Every extra field on a form is data you now have to protect. If you do not use it, do not ask for it.
  • A secure, maintained site. HTTPS everywhere and current software. A neglected website is a data protection risk, which is part of why real care plans matter.

How do I protect the data in my systems?

Section 19 requires “appropriate, reasonable technical and organisational measures” against loss, damage and unlawful access. For a small business, these five carry most of the weight:

  • Map where personal information lives: email, your CRM, spreadsheets, accounting software and cloud storage. You cannot protect data you have not found.
  • Turn on multi-factor authentication for email and every key system. Microsoft’s research shows MFA “can block more than 99.2% of account compromise attacks” (Microsoft Learn).
  • Authenticate your email domain with SPF, DKIM and DMARC. Business email compromise was the second-largest loss type in the FBI’s 2025 Internet Crime Report, at $3.05 billion reported (IC3 2025 report). The DNS & email security playbook shows the setup, and the email health check shows where your domain stands.
  • Back up, and test the restore. A backup you have never restored is not protection against ransomware or a deleted folder.
  • Give people only the access their role needs, and remove it the day they leave.

What do I need from my IT provider and other suppliers?

A written contract. Anyone who processes personal information for you, such as your IT provider, web host, payroll bureau or marketing agency, is an “operator”. Section 21(1) requires a “written contract” that makes the operator keep the security measures of section 19. Section 21(2) requires the operator to tell you “immediately” when there are reasonable grounds to believe the data was accessed by an unauthorised person.

Check whether that contract exists, rather than assuming it does. When I checked our own web host’s terms, I found its data processing agreement is not automatic: Pressable offers it on request (Pressable GDPR page). Many providers work the same way.

Can my data be stored outside South Africa?

Yes, with conditions. Section 72(1) allows a transfer abroad when the recipient is bound by “a law, binding corporate rules or binding agreement” that gives an adequate level of protection, when the person consents, or when the transfer is needed to perform a contract with them. POPIA does not force you to keep data in South Africa. It asks you to know where your data sits and to have decided it deliberately.

Local options exist when residency matters. For a tenant provisioned in South Africa, Microsoft stores core Microsoft 365 data at rest, such as mailboxes, SharePoint and OneDrive files and Teams chats, only in its South African data centres in Cape Town and Johannesburg (Microsoft Learn). That is part of choosing and configuring Microsoft 365 properly. Azure runs the South Africa North region in Johannesburg, and its South Africa West region is reserved for scenarios such as disaster recovery (Azure regions). AWS has run its Africa (Cape Town) region, af-south-1, since 22 April 2020 (AWS).

Here is how I decided it for rizonetech.com. The site and its form submissions are hosted by Pressable, an Automattic company, in its Amsterdam data centre, as section 7 of our privacy policy records, and Pressable’s network “serves cached assets from the nearest edge location while dynamic requests route to the origin data center” (Pressable data centres). I chose the European Union because its data protection law is the strongest case for the “adequate level of protection” section 72 asks for. Public pages are still served from cached copies in Johannesburg. You can see it yourself: open your browser’s developer tools on any page of this site, and its server-timing response header names the edge that served it (dc;desc=jnb for Johannesburg).

The honest limit: Amsterdam is where the live data sits, not the only place it exists. Pressable’s sub-processor list places its backups with Amazon Web Services in the United States (Pressable sub-processors). Its data centre page adds: “Each site runs on paired primary and secondary servers, with the secondary hosted in a different geographic region” (Pressable data centres). So I treat hosting as a cross-border transfer, and our privacy policy says so.

That transfer still has to meet section 72. Pressable says it uses “European Commission approved standard contractual arrangements” for transfers outside the European Economic Area (Pressable privacy policy), but it publishes no data processing agreement: it offers one on request (Pressable GDPR page). The binding-agreement route in section 72, and the written operator contract in section 21, only hold once that agreement is actually signed. Read your own provider’s sub-processor list and terms before you promise anyone that their data stays in one country.

What do I do if there is a breach?

Section 22 requires you to notify the Regulator and the affected people “as soon as reasonably possible” when there are reasonable grounds to believe their personal information was accessed or acquired by an unauthorised person. The notice to people must be in writing, for example by email.

Report to the Regulator through its eServices portal. One detail catches businesses out: the portal’s guide says that to submit a report, “the organisation and its Information Officers must be registered” (eServices guide). Register your information officer now, not on the day of the breach. If you have already mapped your data and controlled access, you can answer “what was exposed, and whose?” quickly.

Where should I start?

StepWhy it comes firstRule
Register your information officerThe breach portal will not take your report without itSection 55(2)
MFA on email and key systemsThe single control that stops most account takeoversSection 19
An honest privacy policyIt is what the people you collect data from readSection 18
Written agreements with your operatorsYou stay accountable for what they do with your dataSection 21
Tested backups and authenticated emailThey limit the damage when something does go wrongSection 19

Common questions

Do I need a cookie banner under POPIA? POPIA does not mention cookies. If your site uses cookies that identify people, such as advertising or tracking cookies, give visitors a real choice first. If it sets none, you do not need a banner.

Do I have to keep data in South Africa? No. Section 72 allows transfers abroad under its conditions. Know where your providers store data, including their backups, and say so in your privacy policy.

Who is my information officer? The head of your business, usually the owner or managing director. You may designate deputy information officers to help, but the head stays responsible. Register them on the Regulator’s eServices portal.

Is a privacy policy template enough? Only if every line is true for your business. A policy that promises what you do not do is a liability, not protection.

What is the practical next step?

You do not need to fix everything at once. Start with the table above. Most of these steps sit naturally inside a managed-IT relationship; see what managed IT should include. If you are not sure where you stand, a short review will show what is exposed and what to fix first.

Next step: if you would rather have your site’s forms, consent notices and backups looked after, see how a care plan handles this.

Published 16 June 2026. Last updated 3 October 2026.

Get your IT looked after

Tell us what keeps going wrong, or what worries you. We'll tell you plainly what it takes to fix, before any work starts.