HomeBlogDo You Need a Privacy Policy for a One-Person Business in South Africa?

Do You Need a Privacy Policy for a One-Person Business in South Africa?

POPIA has no small business exemption, but it also never asks for a document called a privacy policy. What a sole trader with a contact form actually needs.

The question behind the question

Nobody searching this actually doubts that POPIA exists. What they are really asking is narrower and more reasonable: does it apply to something this small? One person, a simple website, a contact form, maybe a mailing list with ninety people on it.

Most published answers are written for organisations with a compliance officer and a legal budget, which is why they do not settle the question. This one is written for the other end of the scale.

The short answer is that POPIA applies to you, the obligation is smaller than you fear, and the document you need is not quite the one you think.

POPIA has no small business exemption

POPIA applies to a responsible party, meaning anyone who determines the purpose and means of processing personal information. It sets no threshold for turnover, headcount, or revenue. A sole proprietor with a laptop is a responsible party in exactly the way a bank is.

There is one genuine exclusion, in section 6(1)(a), for processing in the course of a purely personal or household activity. Your family WhatsApp group is outside the Act. A business is not a household activity, no matter how small, so the exclusion does not help a freelancer.

It is worth naming where the confusion comes from, because the instinct is not irrational. Other South African statutes do have size thresholds. The Consumer Protection Act, for instance, does not apply where the customer is a juristic person at or above a R2 million threshold. People reasonably assume POPIA works the same way. It does not.

But POPIA does not require a document called a privacy policy

This is the part almost nobody says plainly, and it changes what you should actually do.

Search POPIA for the phrase "privacy policy" and you will not find an obligation to publish one. What section 18 requires is notification: when you collect someone's personal information, you must make them aware of certain things. What you are collecting, who you are, why you want it, whether providing it is voluntary, who else will receive it, whether it leaves the country, and their rights to access, correct, object and complain.

A privacy policy is simply the most practical way to discharge that duty on a website. It is a means, not the end. Two consequences follow, and both help a small operator:

  • Yours can be short. A policy that accurately describes a simple business in a page and a half discharges section 18 better than fifteen pages of inherited boilerplate.
  • It has to be true. The obligation is to inform people accurately. A long policy describing practices you do not follow does not satisfy section 18, and creates a second problem discussed below.

Do you collect personal information? Almost certainly

Personal information under POPIA is broad. It covers a name, an email address, a phone number, an ID number, an address, and information relating to an identifiable person. It includes information about juristic persons too, which is unusual internationally.

For a one-person business, it is usually already happening through:

  • A contact form or an enquiry email address
  • Analytics, which typically process IP addresses and device identifiers
  • A mailing list, however small
  • Invoices, quotes and client records
  • Bookings taken over WhatsApp or by phone
  • Payment records held by you rather than only by your gateway
  • CVs, if you have ever advertised for help

If any of that is true, you are processing personal information and section 18 is live.

The specific situations people ask about

"I only have a contact form." A contact form collects a name and an email address so you can reply. That is personal information, and the person filling it in should be told who is receiving it and what you will do with it. This is the single most common case, and yes, it counts. The upside is that a business at this scale needs a genuinely short policy.

"I only have Google Analytics." Analytics processes IP addresses and device identifiers, which are personal information, and it sends data to a third party outside South Africa. This engages your notification duty and also raises cookies. See do you need a cookie policy in South Africa.

"I only have a Facebook or Instagram page, not a website." You are still a responsible party for the enquiries, messages and customer details you collect through it. The platform's own privacy policy covers the platform, not you. Without a website, put a short notice in your page's About section or a pinned post, and be able to send it to anyone who asks.

"My site is a brochure with no forms at all." The weakest case, and the honest answer is that it depends. If the site truly collects nothing, has no analytics, no cookies beyond the strictly functional, and no contact form, your obligation is minimal. In practice almost no site is like this, and analytics alone brings you back in.

"My business is entirely offline, the site is just a shopfront." POPIA applies to your client records regardless of the website. The website is not what triggers the Act. Your customer list is.

You are already the Information Officer

Businesses often assume this is a role for large organisations. It is not appointed, it is automatic. Where nobody has been designated, the head of the private body holds it, and for a sole proprietor that is you.

That means the accountability for compliance already sits with you whether or not you have thought about it, and it comes with a registration step with the Information Regulator. Information Officer duties under POPIA covers what the role involves and how registration works.

The document you have probably never heard of

While you are here, there is a second requirement that catches small operators even more often than the privacy policy: the PAIA manual.

Every private body must have one, and a sole proprietor carrying on a trade or profession is a private body. Small businesses were once broadly exempt, but that exemption expired at the end of 2021. Since 1 January 2022 the position is that everyone needs one. See PAIA manual requirements.

This surprises people more than the privacy policy does, because there is no equivalent obligation in most other countries and it never comes up in international advice.

What actually happens if you skip it

Worth being straight about this, because fine-based scare tactics are unhelpful and small operators can tell when they are being sold to.

The Information Regulator is not auditing one-person businesses at random. Enforcement is largely complaint driven, and the realistic exposure looks like this:

  • Somebody complains. A disgruntled former client, a recipient of an unwanted marketing email, or a person whose data request you ignored. This is the most common route in.
  • You have a breach. Section 22 obliges you to report certain compromises. Once you are in front of the Regulator for that reason, everything else gets looked at too.
  • A business client asks. This is the one that actually bites freelancers and small agencies. Corporate procurement increasingly asks suppliers for a privacy policy, a PAIA manual, and an operator agreement before signing. Not having them costs you the contract, not a fine.
  • A platform requires it. App stores, ad platforms, payment providers and some insurers require a published privacy policy as a condition of use.

For most one-person businesses, the third and fourth are the real reasons to sort this out. The penalty is usually commercial rather than regulatory, which is a better argument than the R10 million headline.

What a one-person privacy policy needs to say

Scaled to a small operation, section 18 comes down to:

  • Who you are. Trading name, the person behind it, and a contact address.
  • What you collect, listed honestly. If it is a name, an email and an analytics cookie, say that.
  • Why, purpose by purpose. Replying to enquiries is a different purpose from sending a newsletter.
  • Your lawful ground for each, under section 11.
  • Who else sees it. Your email provider, your accountant, your hosting company, your mailing list tool. Name the categories.
  • Whether it leaves South Africa, which it does if you use most mainstream tools.
  • How long you keep it, with a real answer rather than "as long as necessary".
  • Their rights, and how to exercise them with you.
  • How to complain to you and to the Information Regulator.

That is a short document for a simple business, and it is meant to be. For the full section 18 treatment see how to write a POPIA privacy policy.

The mistake that matters more than not having one

If you take one thing from this: a copied privacy policy that misdescribes your business is worse than a short accurate one.

Downloaded templates routinely promise things a one-person business does not do. They reference data protection officers you have not appointed, retention schedules you do not operate, international transfer mechanisms you have never heard of, and rights procedures nobody follows. Some name GDPR and European supervisory authorities that have no bearing on a South African sole trader.

Two problems follow. It fails section 18, because the notification is not accurate. And it is a public statement about how you handle data, so if you are ever challenged, the gap between the document and reality is the evidence against you. You wrote the standard you failed to meet.

A page and a half that is true beats fifteen pages that are not.

A short checklist

  • Do you collect names, emails or phone numbers in any form? Then section 18 applies.
  • Does your policy describe what you actually do, rather than what a template assumed?
  • Is it reachable from every page, including your contact form?
  • Does it name a real person or business and a working contact address?
  • Does it say how long you keep things, with an actual answer?
  • Have you registered as your own Information Officer?
  • Do you have a PAIA manual?
  • If you run analytics or ads, do you have a cookie notice as well?

POPIA Ready generates a privacy policy, a PAIA manual and five other documents from answers about your actual business, so the result describes what you do rather than what a template assumed. Free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at August 2026, not legal advice. What POPIA requires depends on what you collect and why, and a specific situation deserves a professional opinion.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →