← Back to the blog
Compliance

POPIA basics every South African small business should know

Zuvo Team12 September 20267 min read

POPIA (the Protection of Personal Information Act) applies to your business the moment you store a client's name, phone number, or email — which means it applies to almost every small business in South Africa, whether you've registered as an "information officer" or not.

What POPIA actually asks of you

Strip away the legal language and POPIA comes down to five practical habits:

Where small businesses usually get caught out

Not in the areas you'd expect. The common real-world gaps are mundane: a shared staff WhatsApp group with customer phone numbers visible to everyone in it; a walk-in sign-in sheet where every new visitor can read the name and number of the person before them; a laptop with a client database that leaves the office unencrypted; a "Contact Us" form on a website with no privacy policy explaining what happens to the submission.

A starting checklist

  1. Write down, in one page, what personal information you actually collect and why. If you can't justify collecting something, stop collecting it.
  2. Publish a short, honest privacy notice — even a simple one — on your website or booking form.
  3. Get explicit consent before adding anyone to a marketing list, separate from any transactional consent (like booking confirmations).
  4. Password-protect and, where possible, encrypt anything holding client information — phones, laptops, shared drives.
  5. Decide how long you'll keep records, and actually delete them on that schedule.
  6. Know who to contact if a client asks what data you hold on them — even if that's just you.

Where AI tools fit into this

If you're using an AI tool to draft client correspondence, that tool is processing personal information on your behalf — which makes the same POPIA questions apply to it. Worth checking, for any tool you use: is data encrypted in transit and at rest? Is it used to train the vendor's models (a real risk with some tools, and one you'd need to disclose)? Can you request deletion? Those aren't nice-to-haves — they're the same obligations you already have, extended to a vendor.

Zuvo is built around these answers, not around avoiding the question

Client and business content is encrypted in transit and at rest, never used to train third-party AI models, and deletable on request — the same standard this checklist asks of you, applied to the tool itself.

This is general information to help you think through the basics, not legal advice. For guidance specific to your business, consult the Information Regulator's published guidance or a South African attorney.