Resource · Checklist

POPIA Compliance Checklist for SMEs

23 audit-ready steps, organised around the eight conditions for lawful processing defined by South Africa's Protection of Personal Information Act. Built for SMEs who need a defensible position — not a legal essay.

Free · No signup · Updated for the latest Regulator guidance

01

Accountability

Appoint, register and resource an Information Officer who owns POPIA compliance end-to-end.

  • 01

    Register your Information Officer

    Submit the IO registration to the Information Regulator and keep proof on file.

  • 02

    Document a compliance framework

    Written policies covering processing, retention, security, and breach response.

  • 03

    Assign a deputy IO if you have multiple sites

    Required for groups, franchises, or branches operating semi-independently.

02

Processing limitation

Collect the minimum personal information needed, lawfully and directly from the data subject where possible.

  • 01

    Map every data collection point

    Web forms, CRMs, payroll, CCTV, support tickets — list source, purpose and storage.

  • 02

    Capture a lawful basis for each flow

    Consent, contract, legal obligation, legitimate interest, or public interest.

  • 03

    Minimise on intake

    Remove form fields you don't strictly need. 'Nice to have' is not a lawful basis.

03

Purpose specification

Be explicit about why you hold information and delete it when the purpose is fulfilled.

  • 01

    Publish a purpose statement per dataset

    Customers, employees, suppliers, marketing leads — each gets a defined purpose.

  • 02

    Set retention periods

    Anchor every dataset to a statutory or operational retention rule, then automate deletion.

  • 03

    Run a quarterly disposal job

    Document what was deleted, when, and by whom — auditors will ask.

04

Further processing limitation

Don't repurpose data for unrelated activities without a fresh lawful basis.

  • 01

    Block silent repurposing

    Marketing cannot reuse a support dataset without consent or a compatibility test.

  • 02

    Run compatibility assessments

    Document why a new use aligns with the original purpose before approving it.

05

Information quality

Keep personal information accurate, complete and up to date.

  • 01

    Offer a self-service correction channel

    Customers and employees must be able to fix their own records.

  • 02

    Schedule periodic data reviews

    Stale CRM, HR and supplier records are a POPIA risk and a business one.

06

Openness

Tell people what you do with their information and publish a PAIA manual.

  • 01

    Publish a POPIA-aligned privacy notice

    Plain language, covers all 8 conditions, linked from every form.

  • 02

    Maintain a Section 51 PAIA manual

    Hosted on your site; updated when systems, products, or processors change.

  • 03

    Notify the Regulator of processing where required

    Specific categories of data (children, special information) trigger prior authorisation.

07

Security safeguards

Protect personal information with appropriate technical and organisational measures.

  • 01

    Run a documented risk assessment

    Identify reasonably foreseeable internal and external risks per system.

  • 02

    Enforce MFA, encryption-in-transit and least-privilege access

    Baseline controls expected by the Regulator and most enterprise procurement teams.

  • 03

    Sign Operator Agreements with every processor

    Cloud providers, payroll bureaus, marketing tools — all need a Section 21 contract.

  • 04

    Maintain a tested breach response plan

    Includes the 'as soon as reasonably possible' notification path to the Regulator and data subjects.

08

Data subject participation

Let people see, correct and delete their information on request.

  • 01

    Stand up a DSAR / DSR intake channel

    Email alias at minimum; a tracked workflow is better.

  • 02

    Meet the statutory turnaround

    Respond within 30 days; document extensions in writing.

  • 03

    Verify identity before disclosure

    Avoid handing personal information to the wrong person — that itself is a breach.

Run this checklist on autopilot

Privara turns each of these 23 steps into a tracked workflow with generated evidence, owner assignments, and audit trails. Free for 14 days.

Start free trial