POPIA basics every South African small business should know
Zuvo Team12 September 20267 min read
POPIA (the Protection of Personal Information Act) applies to your business the moment you store a client's name, phone number, or email — which means it applies to almost every small business in South Africa, whether you've registered as an "information officer" or not.
What POPIA actually asks of you
Strip away the legal language and POPIA comes down to five practical habits:
Only collect what you need. If you're booking a haircut, you don't need a client's ID number. Collecting data "just in case" is itself a compliance risk, not a safety net.
Say what you'll use it for, and stick to that. If a client gives you their number to confirm an appointment, using it to add them to a marketing WhatsApp broadcast without asking is a separate use that needs its own consent.
Keep it secure. A spreadsheet of client details emailed to your personal Gmail, or a phone with client information and no screen lock, is a real exposure — not a technicality.
Don't keep it forever. Data you no longer have a business reason to hold should be deleted, not archived indefinitely "just in case."
Let people ask what you hold on them. Under POPIA, a client can ask what personal information you have about them and request it be corrected or deleted. You need a way to actually do that, not just a policy that says you will.
Where small businesses usually get caught out
Not in the areas you'd expect. The common real-world gaps are mundane: a shared staff WhatsApp group with customer phone numbers visible to everyone in it; a walk-in sign-in sheet where every new visitor can read the name and number of the person before them; a laptop with a client database that leaves the office unencrypted; a "Contact Us" form on a website with no privacy policy explaining what happens to the submission.
A starting checklist
Write down, in one page, what personal information you actually collect and why. If you can't justify collecting something, stop collecting it.
Publish a short, honest privacy notice — even a simple one — on your website or booking form.
Get explicit consent before adding anyone to a marketing list, separate from any transactional consent (like booking confirmations).
Password-protect and, where possible, encrypt anything holding client information — phones, laptops, shared drives.
Decide how long you'll keep records, and actually delete them on that schedule.
Know who to contact if a client asks what data you hold on them — even if that's just you.
Where AI tools fit into this
If you're using an AI tool to draft client correspondence, that tool is processing personal information on your behalf — which makes the same POPIA questions apply to it. Worth checking, for any tool you use: is data encrypted in transit and at rest? Is it used to train the vendor's models (a real risk with some tools, and one you'd need to disclose)? Can you request deletion? Those aren't nice-to-haves — they're the same obligations you already have, extended to a vendor.
Zuvo is built around these answers, not around avoiding the question
Client and business content is encrypted in transit and at rest, never used to train third-party AI models, and deletable on request — the same standard this checklist asks of you, applied to the tool itself.
This is general information to help you think through the basics, not legal advice. For guidance specific to your business, consult the Information Regulator's published guidance or a South African attorney.