POPIA Requirements: The Complete List for SA Businesses
Every obligation POPIA places on a South African business, with the section of the Act each one comes from: the 8 processing conditions, your Information Officer, security measures, breach notification and data subject rights.
What POPIA actually requires
Most POPIA articles tell you to "be compliant" without saying what the Act demands. This one is the list. Every obligation below is tied to the section of the Protection of Personal Information Act 4 of 2013 it comes from, so you can check any of it against the source.
It is long because the Act is long. If you only want the practical version for a website, our POPIA checklist is the shorter read, and the free checklist tool will score your site in about two minutes.
Does POPIA apply to you?
Section 3 sets the scope, and it is wide. POPIA applies to any responsible party domiciled in South Africa that processes personal information by automated or non-automated means. "Processing" is defined in section 1 to include collecting, storing, using, sharing and even deleting.
The practical answer for almost every business: yes. If you hold customer names, employee records, supplier contacts or website analytics, you process personal information. There is no small-business exemption, no turnover threshold and no employee-count minimum.
Two genuine exclusions in section 6: purely household or personal activity, and information that has been de-identified to the point where it cannot be re-identified.
Requirement 1: The eight conditions for lawful processing
Chapter 3 sets out eight conditions. These are the core of the Act, and everything else is detail.
- Accountability (s8). You must be able to show you meet the conditions. Not just meet them - demonstrate it. Documentation is the whole point.
- Processing limitation (s9-12). Process lawfully, minimally, and with a legal basis: consent, contractual necessity, legal obligation, protecting a legitimate interest, or public duty. Collect directly from the person where practical.
- Purpose specification (s13-14). Collect for a specific, explicitly defined, lawful purpose, and do not keep records longer than that purpose needs.
- Further processing limitation (s15). Using data for something new must be compatible with why you originally collected it.
- Information quality (s16). Take reasonable steps to keep information complete, accurate and current.
- Openness (s17-18). Maintain documentation of processing operations, and tell people what you are collecting and why.
- Security safeguards (s19-22). Secure the information, impose the same duty on operators, and report breaches.
- Data subject participation (s23-25). People may ask what you hold, and require correction or deletion.
Requirement 2: Appoint and register an Information Officer
Section 55 makes this mandatory. By default the Information Officer is the head of the business - the CEO, or the owner of a sole proprietorship - and that stays true whether or not anyone was formally appointed.
The role must be registered with the Information Regulator before taking up duties, and their responsibilities include encouraging compliance, dealing with requests, and working with the Regulator on investigations. Deputies may be designated under section 56.
We cover the role in detail in what an Information Officer actually does.
Requirement 3: A PAIA manual
This one comes from a different Act, and it is the requirement businesses most often miss. Section 51 of the Promotion of Access to Information Act obliges every private body - including sole proprietors - to compile a manual describing the records it holds and how to request them.
The blanket exemption that covered most small businesses expired on 31 December 2021. If you have not made one since, you do not have one. See PAIA manual requirements for what must be in it.
Requirement 4: Valid consent, where consent is your basis
Consent is defined in section 1 as a voluntary, specific and informed expression of will, and section 11(2)(b) lets a person withdraw it at any time. In practice that means unticked boxes, separate from your terms, worded for the specific purpose - and a genuine way to change their mind later.
Consent is not always the right basis. Section 11 also permits processing necessary for a contract, a legal obligation, or a legitimate interest. Using consent where contract would do creates a problem: consent can be withdrawn, and then you must stop.
Special personal information (race, health, biometrics, religious or political belief, criminal history) is prohibited under section 26 unless a section 27 exception applies. Children's information requires consent from a competent person under section 35.
Requirement 5: Security measures
Section 19 requires "appropriate, reasonable technical and organisational measures" against loss, damage and unlawful access. The Act deliberately does not list technologies, but it does require you to identify risks and maintain safeguards - and to verify they are working.
Section 20 extends the duty to anyone processing on your behalf, and section 21 requires a written contract with every operator. That includes your hosting provider, email platform and CRM. It is the requirement most often overlooked, because it lives outside your own systems.
Requirement 6: Report data breaches
Section 22 requires notification to both the Information Regulator and the affected people as soon as reasonably possible after discovering a compromise. Notice to individuals must describe the possible consequences and what you are doing about it, and must be given in writing.
Our breach response guide sets out the sequence.
Requirement 7: Honour data subject rights
Sections 23 to 25 give people the right to know whether you hold their information, to receive a copy, and to request correction or deletion. Section 5 adds the right to object to processing and to complain to the Regulator.
A request for access is made under PAIA, which is why the two Acts are so entangled. Requests must generally be answered within 30 days.
Requirement 8: Direct marketing rules
Section 69 restricts unsolicited electronic marketing. You may market to an existing customer about similar products, provided they were given an opportunity to object when you collected their details and in every message since. Marketing to anyone else requires prior consent, which may only be requested once.
The direct marketing rules cover the exceptions properly.
Requirement 9: Rules for sending data outside South Africa
Section 72 restricts transferring personal information across borders unless the recipient is subject to comparable protection, the person consented, or the transfer is necessary for a contract. If you use overseas hosting, analytics or email tools - most South African businesses do - this applies to you, and your privacy policy should say so.
What happens if you do not comply
The Regulator may issue an enforcement notice, and failure to comply with one is an offence. Penalties reach R10 million or imprisonment of up to 10 years for the most serious offences, with lesser offences carrying up to R1 million or 12 months. Individuals may also claim civil damages under section 99, whether or not the Regulator acts.
See POPIA fines and penalties for how each tier is triggered.
Where most businesses actually stand
Nobody does all of this on day one. In our experience the requirements that get missed are, in order: the PAIA manual, operator contracts under section 21, registering the Information Officer, and a cookie banner that genuinely blocks non-essential cookies before consent.
The documentation is the tractable part. POPIA Ready generates seven of the documents referenced above - privacy policy, terms, cookie policy, disclaimer, refund policy, acceptable use policy and a section 51 PAIA manual - customised to your business, free to preview. The rest is process, and the free checklist will tell you which parts you are missing.
This article describes the requirements of the Act as at July 2026. It is a plain-English summary, not legal advice, and the Act itself is the authority.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview