A Practical POPIA Compliance Checklist for South African Businesses
The Protection of Personal Information Act (POPIA) applies to almost every organisation in South Africa that processes personal information. Compliance is not a one-off project — it is an operating discipline. This checklist covers what you actually need in place.
Appoint and register an Information Officer
By default your Information Officer is the head of the organisation. They must be registered with the Information Regulator, and you can appoint Deputy Information Officers to share the load.
Establish a lawful basis for processing
You may only process personal information if you have a lawful ground — consent, a contract, a legal obligation, or a legitimate interest. Map what you collect, why, and on what basis.
Meet the eight conditions
- Accountability — someone owns compliance.
- Processing limitation — collect only what you need, lawfully.
- Purpose specification — a defined reason for collecting.
- Further processing limitation — don't reuse data for unrelated purposes.
- Information quality — keep it accurate and up to date.
- Openness — tell people what you hold and why.
- Security safeguards — protect it with appropriate controls.
- Data subject participation — let people access and correct their data.
Secure the data
Put appropriate technical and organisational controls in place — access control, encryption where warranted, backups, and a breach-response plan. A breach must be reported to the Regulator and affected people.
Handle data-subject requests
People can ask what you hold about them and request correction or deletion. You need a process to receive, verify and respond to these within the required timeframes.
Publish a PAIA manual and privacy notice
POPIA works alongside the Promotion of Access to Information Act (PAIA). You need a PAIA manual and a clear, public privacy notice.
What happens if you don't comply?
The Regulator can investigate, issue enforcement notices, and impose administrative fines of up to R10 million — and there is reputational and civil-claim risk on top.
Get compliant, and stay compliant
Siyakhula runs privacy gap assessments, establishes and operates Privacy Offices, and can act as your Privacy Agent under POPIA. See our governance services →
General information, not legal advice. Speak to us for guidance on your specific obligations.