← Back to Blog Compliance

POPIA Compliance — What Bedfordview Businesses Must Know in 2026

Published: 28 August 2026 | CT Bedfordview

South Africa's Protection of Personal Information Act (POPIA) has been fully enforceable since July 2021, yet a surprising number of small and medium businesses in Bedfordview, Germiston and across Gauteng are still not compliant. The Information Regulator has been steadily ramping up enforcement — and the fines and reputational damage are no joke.

Why POPIA Still Matters in 2026

POPIA isn't a tick-box exercise that ended in 2021. It's an ongoing obligation. Every time your business collects a customer's name, phone number, email address, ID number or even a vehicle registration, you're processing personal information under the Act.

Recent enforcement trends show the Information Regulator is now targeting mid-sized businesses, not just big corporates. Complaints from customers and employees are a common trigger for investigations — meaning an unhappy client or ex-employee can put your business in the Regulator's sights.

The Eight Conditions You Need to Know

POPIA sets out eight conditions for lawful processing. The practical essentials for an SMB are:

  1. **Accountability** — You must be able to show you comply
  2. **Processing limitation** — Only collect what you actually need
  3. **Purpose specification** — Tell people why you're collecting their data
  4. **Further processing limitation** — Don't use data for unrelated purposes
  5. **Information quality** — Keep records accurate and up to date
  6. **Openness** — Have a privacy policy and be transparent
  7. **Security safeguards** — Protect data with appropriate technical and organisational measures
  8. **Data subject participation** — Honour access and correction requests

Your Practical POPIA Checklist

Appoint an Information Officer

Every business must register an Information Officer with the Information Regulator. In an SMB this is usually the owner or a senior manager. They're personally accountable for compliance.

Audit What You Collect

Update Your Customer Communications

Secure the Data You Hold

Handle Requests Properly

Data subjects can request access to, or correction of, their information. You must respond within a reasonable time — typically 30 days — and you may not charge excessive fees.

Common Mistakes We See in Gauteng SMBs

Not sure where your business stands on POPIA? CT Bedfordview can run a data-protection gap assessment and help you implement the technical safeguards — encryption, access control, backups and breach response. Contact us for a compliance review.