POPIA in plain English: what small businesses need to know
POPIA applies to almost every business in South Africa that keeps information about people. Here's the plain-English version of what it expects — and where your systems fit in.
By Noko Mohoto · 20 July 2026 · 6 min read
The Protection of Personal Information Act (POPIA) is South Africa's data protection law, overseen by the Information Regulator. If your business keeps information about people — staff, clients, customers, suppliers — POPIA almost certainly applies to you.
This guide is general information to help you get oriented, not legal advice. For decisions about your specific obligations, speak to a legal professional.
What counts as personal information
More than most people think. Names, ID numbers, contact details, addresses, employment and financial details, health information, opinions about a person — if it identifies or relates to an identifiable person (and in some cases a company), POPIA treats it as personal information.
The core ideas, without the legalese
- Collect only what you need, for a purpose you can name
- Tell people what you're collecting and why
- Use it for that purpose — not for whatever becomes convenient later
- Keep it accurate, and don't keep it forever by default
- Protect it with reasonable security measures
- Let people ask what you hold about them, and correct or delete it
- Take responsibility for it — including when third parties process it for you
Where your software and systems come in
Much of POPIA in practice comes down to how your information is actually stored and who can reach it. Client details scattered across personal WhatsApps, shared spreadsheets, and old email threads are hard to protect, hard to correct, and nearly impossible to delete on request.
A well-planned system makes the same obligations manageable:
- Role-based access — staff see only the personal information their job needs
- Purpose-specific records instead of open-ended data hoarding
- Retention planning, so records can be removed when they've served their purpose
- Audit trails showing who accessed or changed what
- Support for data subject requests — finding, exporting, correcting, or erasing a person's information without archaeology
- Secure authentication so 'the password is on a sticky note' stops being your security model
How we build with POPIA in mind
Every system Noko Mohoto Technologies builds is planned with POPIA awareness from the start — collection, access, retention, and request-handling are design decisions, not afterthoughts. That's compliance-aware engineering, not a certification or a legal guarantee, and it works best alongside proper legal guidance for your business.

