South Africa's Protection of Personal Information Act (POPIA) has been fully enforceable since July 2021, yet a surprising number of small and medium businesses in Bedfordview, Germiston and across Gauteng are still not compliant. The Information Regulator has been steadily ramping up enforcement — and the fines and reputational damage are no joke.
Why POPIA Still Matters in 2026
POPIA isn't a tick-box exercise that ended in 2021. It's an ongoing obligation. Every time your business collects a customer's name, phone number, email address, ID number or even a vehicle registration, you're processing personal information under the Act.
Recent enforcement trends show the Information Regulator is now targeting mid-sized businesses, not just big corporates. Complaints from customers and employees are a common trigger for investigations — meaning an unhappy client or ex-employee can put your business in the Regulator's sights.
The Eight Conditions You Need to Know
POPIA sets out eight conditions for lawful processing. The practical essentials for an SMB are:
- **Accountability** — You must be able to show you comply
- **Processing limitation** — Only collect what you actually need
- **Purpose specification** — Tell people why you're collecting their data
- **Further processing limitation** — Don't use data for unrelated purposes
- **Information quality** — Keep records accurate and up to date
- **Openness** — Have a privacy policy and be transparent
- **Security safeguards** — Protect data with appropriate technical and organisational measures
- **Data subject participation** — Honour access and correction requests
Your Practical POPIA Checklist
Appoint an Information Officer
Every business must register an Information Officer with the Information Regulator. In an SMB this is usually the owner or a senior manager. They're personally accountable for compliance.
Audit What You Collect
- Walk through every form, spreadsheet and CRM
- Note what personal information you hold and where it lives
- Delete anything you don't genuinely need
- Document how long you'll keep what remains
Update Your Customer Communications
- Add a clear privacy notice to your website
- Include consent wording on all data-capture forms
- Review your email footer and quotes/contracts
Secure the Data You Hold
- Encrypt customer databases and backups
- Use access controls so staff only see what they need
- Keep software patched — breaches usually start with unpatched systems
- Have a data breach response procedure (POPIA requires you to notify the Regulator and affected parties)
Handle Requests Properly
Data subjects can request access to, or correction of, their information. You must respond within a reasonable time — typically 30 days — and you may not charge excessive fees.
Common Mistakes We See in Gauteng SMBs
- **No Information Officer registered** — the single most common gap
- **Consent boxes pre-ticked** — consent must be freely given and specific
- **Marketing lists with no opt-out** — every direct marketing message must offer an opt-out
- **Old client data kept forever** — retention periods are a POPIA requirement
- **No breach procedure** — you have a limited window to notify after a breach
Not sure where your business stands on POPIA? CT Bedfordview can run a data-protection gap assessment and help you implement the technical safeguards — encryption, access control, backups and breach response. Contact us for a compliance review.