POPIA, PAIA and Privacy Compliance for South African Businesses
Two Acts, one Regulator. POPIA governs the personal details you hold — clients, staff, the people who fill in your contact form — and in practice that is nearly every business. PAIA governs what happens when somebody asks to see your records, and it requires a written manual saying how they go about it. The Information Regulator oversees both. We work out what you are holding, whether you are entitled to hold it, what your privacy policies should actually say, and get the PAIA manual done properly.
What this covers
What you hold, and where
Working out what personal information your business actually has, where it sits, who can reach it and how long you've been keeping it. This is where most of the gaps turn up, because very few businesses have the full picture before they go looking. That's normal.
The eight things POPIA asks
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation — the Act calls these the eight conditions for lawful processing. The questions underneath are simpler: why do you have this, did you say you would, who can see it, and when will you let it go. We check your operations against each and show you where practice and law have drifted apart.
The person legally answerable
Someone in your business is legally answerable for personal information. POPIA calls them the Information Officer, and by default it's the head of the business — whether or not anyone has mentioned it to them. Registering with the Information Regulator is a legal requirement rather than a formality, deputies register too, and the details need updating when people move on.
Privacy policies people actually use
A privacy policy tells people what you do with their information. It is also the document most often copied off another website and quietly contradicted by how the business really works. We write yours from what you actually do — the notice on your forms, how long you keep things, who you share them with — so it holds up when somebody reads it properly. Written so your staff can follow it without a lawyer in the room, and embedded so that they do.
Your section 51 PAIA manual
The Promotion of Access to Information Act gives people a route to request records from your business, and section 51 requires you to publish a manual setting out what you hold and how to ask for it. It belongs at your office and on your website. The same Information Officer carries it, the Information Regulator oversees it alongside POPIA, and it is the kind of document that is quick to produce and awkward to be caught without.
When something goes wrong
A breach isn't only a hacker. It's an email to the wrong recipient, a laptop left in a taxi, a spreadsheet shared with someone who shouldn't have it. Knowing what to do in the first hour matters more than any document you file away.
- Every private body — the PAIA manual requirement does not depend on your size
- Anyone with employees — payroll, HR files, CVs from people you didn't hire
- Businesses holding client files, bank details or copies of ID documents
- Anyone whose data sits with a supplier, a bookkeeper or a cloud service
- Any website with a contact form, a newsletter sign-up or a login
- A gap assessment against the eight conditions POPIA sets out
- A register of what personal information you hold, and why you hold it
- A privacy policy and the notices that go with it, written from what you actually do
- A section 51 PAIA manual, ready to publish on your website and keep at the office
- Retention rules and an incident plan for when something goes wrong
- Help getting your Information Officer and Deputy registered
- Staff who can explain their obligations in their own words
Questions we get a lot
Any organisation, public or private, that decides why and how personal information gets used. POPIA calls that the responsible party — if you hold people's personal details, that's you. Names, contact details, ID numbers, bank details, staff records: all of it counts, and there is no small-business exemption.
The Information Regulator can issue an enforcement notice telling you to put something right. Failing to comply with one can result in a fine of up to R10 million or imprisonment. Serious offences under the Act carry criminal liability.
Yes. If you run a private business, you're the Information Officer by default — it isn't a role you opt into — and you have to register with the Information Regulator. Deputy Information Officers register too, and it's worth checking the details whenever the people in those roles change.
Almost certainly. Section 51 of the Promotion of Access to Information Act requires private bodies to compile a manual setting out what records they hold and how someone can request access to them, and to make it available at the office and on the website. It is a short document and a common gap — plenty of businesses have a privacy policy and no manual at all. The Information Regulator oversees PAIA and POPIA together, so the same Information Officer carries both.
POPIA is about the personal information you hold: what you may collect, what you may do with it, and how you keep it safe. PAIA is about access — how somebody asks to see records your business holds, and what you have to tell them about that process. One Regulator oversees both, and in practice the same person in your business is answerable for each.
It can be. The Information Regulator found a public body non-compliant after a staff member emailed personal information, including background check results, to colleagues who weren't entitled to see it. The email was recalled two days later with an apology. That didn't settle it.
Let’s take a look at where you stand.
A free consultation works out what applies to your business and what you already have in place — before you commit to anything else.