POPIA for a small business: what Section 19 actually asks for
POPIA applies to any South African business that holds personal information about customers, staff or suppliers, regardless of size. There is no small business exemption, no employee threshold and no turnover threshold. If you hold a client’s identity number, a staff member’s bank details or a supplier contact list, the Act applies to you in exactly the way it applies to a listed company.
What Section 19 says
Section 19 of the Protection of Personal Information Act 4 of 2013 requires a responsible party to secure the integrity and confidentiality of personal information in its possession by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of that information, and unlawful access to it.
It then requires that business to take reasonable measures to identify all reasonably foreseeable internal and external risks, establish and maintain appropriate safeguards against those risks, verify that the safeguards are effectively implemented, and ensure the safeguards are continually updated in response to new risks.
The word doing the work in that section is reasonable. Section 19 is deliberately not a checklist, which is why two businesses of the same size can arrive at different answers and both be compliant.
What that means in practice
In practice a South African business of ten to two hundred staff is expected to be able to show most of the following, in a form somebody outside the business could read:
- Access control. A record of who can reach what, why, and when that was last reviewed. Former staff removed on their last day rather than eventually.
- Encryption. Laptops encrypted, so a device left in a car does not become a notifiable breach.
- Backup that has been restored from. Not a backup that reports success, one that somebody has actually recovered a file from and written down the date.
- Monitoring. Something watching for unusual access, and a person who receives the alert.
- An incident response process. Written down before an incident, not during one.
- Data processing agreements. With every supplier that touches personal information on your behalf, which includes your IT provider.
- A risk assessment. Dated, and reviewed more than once.
The four failures we see most often
Across health checks for South African businesses, the same four gaps come up repeatedly, and none of them are exotic.
Accounts of people who have left. Still active, sometimes still receiving mail, occasionally still licensed. This is the single most common finding and the easiest to fix.
No data processing agreement with the IT provider. The supplier with the deepest access to personal information is frequently the only one with no agreement in place governing it.
A risk assessment that was done once. Section 19 requires safeguards to be continually updated in response to new risks. A single dated document from three years ago demonstrates the opposite.
Backups nobody has restored from. Covered in detail in backup is not disaster recovery, and it is the failure with the worst consequences.
What happens if you get it wrong
The Information Regulator can impose an administrative fine of up to R10 million. Enforcement action has already been taken against the Department of Basic Education, the National Police Commissioner and the South African Police Service, the Department of Justice, Dis-Chem Pharmacies and WhatsApp. The Regulator’s stated plan for 2026 and 2027 shifts from reacting to complaints toward proactive compliance audits, targeting financial services, insurance, health, retail, telecommunications and the public sector.
The more immediate consequence for most businesses is commercial rather than regulatory. Larger clients now send security questionnaires before they will contract, and a business that cannot answer one loses the work to a business that can.
Do you have to report a breach within 72 hours?
Not every business does. A specific 72 hour reporting window applies to defined categories such as electronic communications service providers and financial institutions. POPIA itself requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible after a compromise is discovered, without setting a single universal clock for every organisation. Check which obligation applies to your sector rather than adopting the 72 hour figure because it appears on most websites.
Where to start if you have done nothing
Start by finding out what has already leaked, because that is free and it takes a day. Then close the accounts of people who have left, get a data processing agreement in place with your IT provider, and restore one file from your backup and write down the date. Those four actions take a week between them and remove the most common findings.
LANTEK builds these controls into client environments as standard rather than as a project. That approach is described on the Compliant by Design page, structured on the six functions of the NIST Cybersecurity Framework 2.0.
Sources: Protection of Personal Information Act 4 of 2013, Section 19 and Section 72. Cybercrimes Act 19 of 2020, Section 11(1). Information Regulator enforcement records and published 2026 to 2027 plan. This article is general information about South African law and is not legal advice.
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.