POPIA, PAIA and Privacy Compliance for South African Businesses
Two Acts, one Regulator. POPIA governs the personal details you hold — clients, staff, the people who fill in your contact form — and in practice that is nearly every business. PAIA governs what happens when somebody asks to see your records, and it requires a written manual saying how they go about it. The Information Regulator oversees both. We work out what you are holding, whether you are entitled to hold it, what your privacy policies should actually say, and get the PAIA manual done properly.
What this covers
What you hold, and where
Working out what personal information your business actually has, where it sits, who can reach it and how long you've been keeping it. This is where most of the gaps turn up, because very few businesses have the full picture before they go looking. That's normal.
The eight things POPIA asks
Underneath the legal wording, POPIA asks eight simple questions about anything you hold. Why do you have this? Did you tell the person you would? Who can see it? Is it accurate? How safe is it? And when will you let it go? The Act calls these the eight conditions for lawful processing. We check your business against each one and show you where practice and the law have drifted apart.
The person legally answerable
Someone in your business is legally answerable for personal information. POPIA calls them the Information Officer, and by default it's the head of the business — whether or not anyone has mentioned it to them. Registering with the Information Regulator is a legal requirement rather than a formality, deputies register too, and the details need updating when people move on.
Privacy policies people actually use
A privacy policy tells people what you do with their information. It is also the document most often copied off another website and quietly contradicted by how the business really works. We write yours from what you actually do — the notice on your forms, how long you keep things, who you share them with — so it holds up when somebody reads it properly. Written so your staff can follow it without a lawyer in the room, and embedded so that they do.
Your section 51 PAIA manual
The Promotion of Access to Information Act gives people a way to ask for records your business holds. Section 51 says you have to publish a manual setting out what you keep and how somebody asks for it. It belongs at your office and on your website. The same Information Officer carries it, and the Information Regulator oversees it alongside POPIA. It takes very little time to produce, and it's an awkward one to be caught without.
When something goes wrong
A breach isn't only a hacker. It's an email to the wrong recipient, a laptop left in a taxi, a spreadsheet shared with someone who shouldn't have it. Knowing what to do in the first hour matters more than any document you file away.
- Every private body — the PAIA manual requirement does not depend on your size
- Anyone with employees — payroll, HR files, CVs from people you didn't hire
- Businesses holding client files, bank details or copies of ID documents
- Anyone whose data sits with a supplier, a bookkeeper or a cloud service
- Any website with a contact form, a newsletter sign-up or a login
- A gap assessment against the eight conditions POPIA sets out
- A register of what personal information you hold, and why you hold it
- A privacy policy and the notices that go with it, written from what you actually do
- A section 51 PAIA manual, ready to publish on your website and keep at the office
- Retention rules and an incident plan for when something goes wrong
- Help getting your Information Officer and Deputy registered
- Staff who can explain their obligations in their own words
Questions we get a lot
Any organisation, public or private, that decides why and how personal information gets used. POPIA calls that the responsible party — if you hold people's personal details, that's you. Names, contact details, ID numbers, bank details, staff records: all of it counts, and there is no small-business exemption.
The Information Regulator can issue an enforcement notice telling you to put something right. Failing to comply with one can result in a fine of up to R10 million or imprisonment. Serious offences under the Act carry criminal liability.
Yes. If you run a private business, you're the Information Officer by default — it isn't a role you opt into — and you have to register with the Information Regulator. Deputy Information Officers register too, and it's worth checking the details whenever the people in those roles change.
Almost certainly. Section 51 of the Promotion of Access to Information Act requires private bodies to compile a manual setting out what records they hold and how someone can request access to them, and to make it available at the office and on the website. It is a short document and a common gap — plenty of businesses have a privacy policy and no manual at all. The Information Regulator oversees PAIA and POPIA together, so the same Information Officer carries both.
POPIA is about the personal information you hold: what you may collect, what you may do with it, and how you keep it safe. PAIA is about access — how somebody asks to see records your business holds, and what you have to tell them about that process. One Regulator oversees both, and in practice the same person in your business is answerable for each.
It can be. The Information Regulator found a public body non-compliant after a staff member emailed personal information, including background check results, to colleagues who weren't entitled to see it. The email was recalled two days later with an apology. That didn't settle it.
Let’s take a look at where you stand.
A free consultation works out what applies to your business and what you already have in place — before you commit to anything else.