POPIA is South Africa's data protection law. If your business collects any personal information, your IT setup directly determines whether you are compliant or exposed to fines of up to R10 million.
If you run a business in South Africa and you collect any personal information from clients, employees or suppliers, POPIA applies to you. It does not matter how small your business is. It does not matter if you think the information you collect is harmless. If you store a name, an email address, an ID number or a phone number, you have a legal obligation to protect it.
POPIA stands for the Protection of Personal Information Act. It came into full effect in July 2021, and the Information Regulator has made it clear that enforcement is not just theoretical. Complaints have been lodged, investigations have been opened, and fines of up to R10 million or even imprisonment are on the table for serious non-compliance.
For most small businesses in Cape Town, POPIA is not something you need a lawyer to solve on their own. It is something your IT setup either supports or undermines. Here is what you need to know.
What does POPIA actually require?
At its core, POPIA says that if you collect someone's personal information, you must handle it responsibly. That means you need a lawful reason for collecting it, you must tell the person what you are using it for, and you must take reasonable steps to keep it safe.
The law breaks this down into eight conditions, but the ones that affect your IT the most are security safeguards, storage limitation and access control.
Security safeguards mean you must protect personal information against loss, damage, unauthorised access and theft. In practical terms, that means encrypted storage, strong passwords, firewalls, antivirus software and secure email. If someone breaks into your system and steals client data because you had no protections in place, you are the one who is liable.
Storage limitation means you should not keep personal information for longer than you need it. If you have old client files sitting on a shared drive from five years ago, you are holding onto risk for no reason.
Access control means only the people who need to see personal information should be able to access it. If every staff member in your business can open every file on your server, that is a problem.
Where most small businesses fall short
The biggest issue we see is that many business owners assume POPIA is a paperwork exercise. They download a privacy policy template from the internet, paste it onto their website and consider the job done. But POPIA is not just about having the right documents. It is about how your business actually handles data day to day, and that comes down to your IT systems and practices.
Here are some of the most common gaps we see in small businesses around Cape Town.
Emails with sensitive information sent without encryption. If you are emailing ID documents, contracts or financial information as plain attachments, anyone who intercepts that email can read them. Microsoft 365 with the right configuration can encrypt emails automatically when sensitive content is detected.
No access controls on shared drives or folders. If your entire team can see every file in the business, including HR records, client financials and personal details, you do not have the access controls POPIA expects. Permissions should be set so that people only see what is relevant to their role.
No proper backup or disaster recovery plan. POPIA requires you to protect data against loss. If your data lives on a single laptop or a hard drive under someone's desk, one theft, one fire or one ransomware attack could destroy it all, and leave you in breach of the law at the same time.
Old data never cleaned up. Former client records, old employee files, outdated databases. If you are keeping personal information you no longer need, you are increasing your risk without any benefit. A regular data cleanup schedule is part of being compliant.
Weak or shared passwords. If your staff share login credentials or use simple passwords without multi-factor authentication, you are not meeting the reasonable security measures POPIA expects. If you are not sure what a strong password looks like in practice, our guide on how to create a strong password is a good starting point.
What should your IT setup look like?
You do not need to spend a fortune, but you do need to get the basics right. A POPIA-ready IT environment for a small business looks something like this.
Business-grade email with encryption. Microsoft 365 is the obvious choice here. It gives you professional email, built-in encryption options, and tools to control who can access what. Using a free email provider like Gmail for business correspondence with sensitive data is a compliance risk.
Access controls and permissions. Your files and folders should be structured so that staff only have access to what they need. HR files should be restricted. Client financial data should be limited. Admin access should be tightly controlled. This is straightforward to set up in Microsoft 365 or any properly configured file server.
Endpoint protection on every device. Every laptop, desktop and phone that connects to your business systems should have up-to-date antivirus and endpoint protection. If a device is lost or stolen, you need the ability to remotely wipe business data from it.
A tested backup and recovery plan. Your data should be backed up regularly, stored securely, and you should know exactly how to restore it if something goes wrong. Backups that have never been tested are not backups at all.
A password policy with multi-factor authentication. Every user account should have a strong, unique password and MFA enabled. This is the single most effective thing you can do to prevent unauthorised access to your systems. Our guide on creating strong passwords walks through how to do this practically, and you can use our free password generator to create one.
A data retention policy that your IT systems enforce. Decide how long you need to keep different types of data, and set up automated processes to flag or remove data that has passed its retention period. Do not leave this to manual effort because it will not happen.
What happens if you get it wrong?
The Information Regulator can investigate complaints, issue enforcement notices, and impose fines of up to R10 million. In extreme cases, directors can face criminal prosecution and imprisonment.
But beyond the legal consequences, a data breach caused by poor IT practices can destroy client trust overnight. If your clients find out their personal information was stolen because your business had no firewall, no encryption and no access controls, no privacy policy on your website is going to fix the reputational damage.
For small businesses that depend on relationships and referrals, that trust is everything.
You do not have to figure this out alone
POPIA compliance is not a once-off project. It is an ongoing responsibility, and your IT systems are a critical part of it. The good news is that most of what POPIA requires from an IT perspective is just good practice anyway. Secure email, proper backups, access controls, strong passwords. These are things every business should have in place regardless of the law.
If you are not sure where you stand, or if you know there are gaps in your setup, it is worth having someone take a proper look. Recloud helps Cape Town small businesses put the right IT foundations in place so that compliance is built into how you work, not bolted on as an afterthought. Get in touch for a free, no-obligation conversation about where your business stands and what it would take to get it right.