The Protection of Personal Information Act (POPIA) is South Africa's comprehensive data protection legislation — and the Information Regulator is actively enforcing it. In 2026, we've seen the Regulator issue several substantial fines to organisations that failed to comply, sending a clear message that POPIA is not a paper exercise.
If your business collects, stores, or processes personal information (and almost every business does), you have legal obligations under POPIA. Non-compliance can result in fines of up to R10 million or imprisonment. Beyond the financial penalty, reputational damage following a data breach can be far more costly — losing customer trust is often the difference between a business that survives and one that shuts its doors.
Here's a practical IT systems checklist for POPIA compliance that every South African business should work through:
1. Data Inventory — Document every system that stores personal information. Include file servers, email systems, CRMs, accounting software, and cloud services. You cannot protect data you don't know exists. Many Bedfordview businesses we assess are surprised to discover how many copies of customer data are scattered across spreadsheets, personal devices, and legacy systems.
2. Access Controls — Implement the principle of least privilege. Staff should only access data they need for their role. Review permissions quarterly. A common finding in our assessments is that former employees still have active accounts with access to sensitive customer information — a clear POPIA violation.
3. Encryption — Personal information must be encrypted both at rest and in transit. This applies to databases, backups, email, and file transfers. If your data is encrypted and a breach occurs, the impact is significantly reduced — in some cases, encrypted data breaches may not even require notification to the Regulator.
4. Incident Response — Have a documented plan for data breaches, including notification procedures. POPIA requires notification to the Regulator and affected individuals. Having a robust cybersecurity incident response plan ensures your team knows exactly what to do within that critical 72-hour notification window.
5. Data Retention — Define and enforce retention policies. Don't keep personal information longer than necessary for the purpose it was collected. Set up automated deletion schedules in your systems. Holding onto outdated customer data "just in case" is a compliance risk.
6. Vendor Assessment — Your cloud providers and IT vendors must also be POPIA-compliant. Review your contracts and data processing agreements. Every third party that touches your data — from your email provider to your payroll service — needs to have appropriate safeguards in place.
7. Information Officer — Under Section 55 of POPIA, every business must register an Information Officer with the Information Regulator. This person is legally responsible for ensuring the organisation complies with the Act. Many Bedfordview businesses we've assessed had no documented Information Officer or had assigned the role without providing the necessary authority or training.
8. Data Subject Access Request (DSAR) Process — POPIA gives individuals the right to request access to their personal information held by your organisation, and you must respond within a reasonable timeframe. Without a documented DSAR procedure, you risk being caught off-guard when a request arrives — and non-response can trigger a complaint to the Regulator.
CT Bedfordview offers POPIA readiness assessments and can help implement the technical controls your business needs. We also provide support for obtaining cybersecurity insurance, which increasingly requires documented POPIA compliance as a prerequisite.