Data protection · South Africa

POPIA and your customer records

POPIA is the Protection of Personal Information Act 4 of 2013. Its substantive conditions commenced on 1 July 2020. If your business decides why and how customer data is processed, you are the responsible party and the obligations are yours. Your CRM or invoicing vendor is an operator, and section 21 requires a written contract with it.

Last updated 2026-09-04. Published by Umbra ERP.

Key facts

The Act
Protection of Personal Information Act 4 of 2013, assented to on 19 November 2013.
Commencement
Sections 2 to 38 and 55 to 109 commenced on 1 July 2020; sections 110 and 114(4) on 30 June 2021; section 58(2) on 1 July 2021.
Regulator
The Information Regulator, which enforces POPIA and the Promotion of Access to Information Act 2 of 2000.
Responsible party vs operator
Section 1: a responsible party determines the purpose of and means for processing. An operator processes for a responsible party under contract or mandate, without coming under its direct authority.
The eight conditions
Chapter 3, sections 8 to 25: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
Breach notification
Section 22: notify the Regulator and the affected data subject as soon as reasonably possible after discovering the compromise.
Maximum administrative fine
Section 109(2)(c): an infringement notice may not specify an administrative fine exceeding R10 million. Certain offences carry up to 10 years imprisonment under section 107.

What POPIA is, and who it binds

The Protection of Personal Information Act 4 of 2013 was assented to on 19 November 2013 and then commenced in stages. Section 1 and the sections establishing the Information Regulator took effect on 11 April 2014. The substantive obligations, sections 2 to 38 and sections 55 to 109, commenced on 1 July 2020, with the final pieces following on 30 June 2021 and 1 July 2021. That staged commencement is why so many businesses treated POPIA as a future problem for six years and then discovered it was a present one.

The Act does two things. It sets minimum conditions for the processing of personal information by public and private bodies, and it establishes the Information Regulator to enforce them. The Regulator enforces both POPIA and the Promotion of Access to Information Act 2 of 2000, which is why the two Acts keep referring to each other and why a POPIA question so often turns into a PAIA manual question.

The definition of a private body is where most small businesses discover they are in scope. It covers a natural person who carries or has carried on any trade, business or profession, but only in such capacity, a partnership carrying on a trade, business or profession, and any former or existing juristic person. A sole proprietor with a customer list is a private body under POPIA. There is no small-business exemption.

Section 3(1) sets the territorial and technical scope. The Act applies where personal information is entered in a record by or for a responsible party, whether by automated or non-automated means, and where non-automated, it forms part of a filing system or is intended to. It applies where the responsible party is domiciled in the Republic, and also where it is not domiciled here but makes use of means in the Republic, unless those means are used only to forward information through the country. A paper ledger in a filing cabinet is in scope. A shoebox of unsorted receipts arguably is not.

Two exclusions matter in practice. Section 6(1)(a) excludes processing in the course of a purely personal or household activity, which is why your personal phone contacts are not a POPIA matter and your business contact database is. Section 6(1)(b) excludes information that has been de-identified to the extent that it cannot be re-identified again, which is a much higher bar than simply removing a name column.

One difference from European data protection law catches people out. POPIA defines personal information as information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person. Companies have data protection rights in South Africa. Your business-to-business customer database is personal information too.

Responsible party or operator: the split most businesses get wrong

Section 1 defines a responsible party as a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information. It defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party.

The test is decision-making, not possession. Your cloud accounting system holds your customers' names, addresses, phone numbers and VAT numbers, but it did not decide to collect them and it does not decide what they are for. You did. You are the responsible party. The software vendor is an operator. The same is true of your bookkeeper, your email marketing platform, your payroll bureau and your hosting provider.

This matters because responsibility does not transfer with the data. Nothing you sign with a vendor makes them answerable to a data subject in your place. Section 8 puts the accountability squarely on the responsible party to ensure that the conditions for lawful processing are given effect. When a customer asks who has their information, the answer is you, and then a list.

The Act does place real duties on operators. Section 20 requires an operator, or anyone processing on behalf of a responsible party, to process the information only with the knowledge or authorisation of the responsible party, and to treat it as confidential and not disclose it, unless required by law or in the course of the proper performance of their duties. So a vendor cannot lawfully mine your customer list for its own purposes.

Section 21 is the one that generates paperwork. Subsection (1) requires that a responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator establishes and maintains the security measures referred to in section 19. Not an understanding, not a tick box during signup: a written contract. If you use six cloud services that touch customer data, you need that term in six contracts. Subsection (2) then requires the operator to notify the responsible party immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.

A vendor cannot be POPIA compliant on your behalf, and no software product is POPIA compliant as a property of itself. A product can hold data securely, restrict access, log changes and make correction easy. Whether your use of it is lawful depends on why you collected the data, what you told the person, how long you keep it and who you pass it to. That is your decision set, not the vendor's.

The eight conditions, in the order they will bite

Chapter 3 of the Act sets out eight conditions for lawful processing, running from section 8 to section 25. They are cumulative. Satisfying seven of them is not compliance, and a breach of any one of them is an interference with the protection of personal information under section 73.

Condition 1: Accountability (s8)
The responsible party must ensure the conditions are given effect. This one is not delegable.
Condition 2: Processing limitation (ss 9 to 12)
Lawfulness, minimality, consent and objection, and collection directly from the data subject.
Condition 3: Purpose specification (ss 13 to 14)
Collect for a specific, explicitly defined and lawful purpose, and do not keep the record longer than that purpose needs.
Condition 4: Further processing limitation (s15)
A new use has to be compatible with the purpose you collected the data for.
Condition 5: Information quality (s16)
Keep the information complete, accurate, not misleading and updated where necessary.
Condition 6: Openness (ss 17 to 18)
Document your processing operations, and tell the data subject what you are collecting and who you are.
Condition 7: Security safeguards (ss 19 to 22)
Secure the information, bind your operators in writing, and notify when it is compromised.
Condition 8: Data subject participation (ss 23 to 25)
Let people see what you hold about them and have it corrected or deleted.

Section 10, minimality, is the condition that quietly rules out a lot of ordinary business behaviour. Personal information must be adequate, relevant and not excessive given the purpose. A quotation does not need a date of birth. A delivery does not need an identity number. Every field you collect because it might be useful one day is a field you have to justify, secure, keep accurate and eventually destroy.

Section 12(1) requires that personal information must be collected directly from the data subject, subject to the exceptions in subsection (2). Scraping a list, buying a database or having a salesperson transcribe details from a business card pile all sit uncomfortably against that default. The cleanest position is the one where the customer typed their own details.

Consent is not the default, and it is the weakest ground

A common and expensive misreading of POPIA is that everything needs consent. Section 11(1) lists six grounds on which personal information may be processed, and consent is only the first of them. Processing is also lawful where it is necessary to carry out actions for the conclusion or performance of a contract to which the data subject is party, where it complies with an obligation imposed by law on the responsible party, where it protects a legitimate interest of the data subject, where it is necessary for the proper performance of a public law duty by a public body, or where it is necessary for pursuing the legitimate interests of the responsible party or of a third party to whom the information is supplied.

Almost everything a normal trading business does with a customer record sits on the contract ground or the legal obligation ground rather than on consent. You hold a customer's billing address because you have to deliver to it and invoice it. You hold their VAT number because the VAT Act requires it on a full tax invoice. You retain the invoice for five years because tax law says to. None of that needs a consent checkbox, and asking for consent you do not need creates a right of withdrawal you did not have to grant.

Where you do rely on consent, section 11(2)(a) puts the burden of proof on you. You have to be able to show, later and to a sceptical Regulator, that this specific person gave this specific consent for this specific purpose. A tick box with no timestamp, no record of the wording shown and no audit trail is not evidence. Section 11(2)(b) then lets the data subject withdraw consent at any time, without affecting the lawfulness of what you did before the withdrawal or of processing that rests on the other grounds.

Section 11(3) gives a separate right to object, at any time, to processing carried out on the legitimate interest grounds or for the purposes of direct marketing other than by unsolicited electronic communication. Section 11(4) is short and absolute: if a data subject has objected, the responsible party may no longer process the personal information. There is no balancing test written into that subsection. An objection is an off switch, and your systems need somewhere to record that it was pulled.

What a customer record should hold, and for how long

Section 13(1) requires that personal information be collected for a specific, explicitly defined and lawful purpose related to a function or activity of the responsible party. Section 14(1) then says that records must not be retained any longer than is necessary for achieving that purpose, unless retention is required or authorised by law, unless the responsible party reasonably requires the record for lawful purposes related to its functions or activities, unless a contract requires it, or unless the data subject has consented to the retention.

Section 14(4) is the part almost nobody implements. A responsible party must destroy or delete a record of personal information, or de-identify it, as soon as reasonably practicable after it is no longer authorised to retain it. Most businesses have no deletion process at all. Their customer database is an accumulation, not a managed set, and it contains records of people who enquired once in 2017 and were never heard from again. Those records are a liability with no offsetting purpose.

The tax rules give you a defensible floor rather than a ceiling. SARS requires vendors to keep records of documentary proof and other records of transactions for at least five years, so an invoice and the customer details on it have a clear lawful basis for retention. That does not extend to the marketing list, the enquiry that never converted or the abandoned quotation from four years ago.

Section 16, information quality, is where duplicates become a compliance problem rather than an annoyance. If the same customer exists three times in your CRM with three different phone numbers, at least two of those records are inaccurate, and a correction request under section 24 will only fix the one you happen to find. Deduplication is a data protection control, not just tidiness.

Two features of Umbra bear directly on this, and neither of them makes anyone compliant on their own. The first is the client self-service details link, which attaches to a quotation and lets the client fill in their own legal name, address, tax number, VAT number and billing emails. That is collection directly from the data subject, which is the section 12 default, and it moves the accuracy burden to the person who actually knows the answer. Blank fields are treated as unanswered and never wipe what you already hold, so a half-completed form does not destroy good data.

The second is how the assistant handles a pasted customer conversation. Before proposing anything, it checks the extracted details against your existing customers, leads and open quotes using deterministic database matching: exact email, the last nine digits of the phone number, and a fuzzy name score. That is what stops a repeat enquiry from silently becoming a fourth copy of the same person. Nothing is written until you confirm it, and replying "ok" or "thanks" does not count as consent to execute.

Security safeguards and the breach clock

Section 19(1) requires a responsible party to secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of it.

Subsection (2) turns that into four specific duties, and they are worth reading as a checklist because the Regulator will. You must identify all reasonably foreseeable internal and external risks to the personal information in your possession or under your control. You must establish and maintain appropriate safeguards against the risks you identified. You must regularly verify that the safeguards are effectively implemented. And you must ensure the safeguards are continually updated in response to new risks or to deficiencies in ones you implemented previously. Note the word internal. The most common risk to a small company's customer database is a former employee with a live login, not an attacker.

Subsection (3) adds that the responsible party must have due regard to generally accepted information security practices and procedures which may apply to it generally or be required by specific industry or professional rules. The standard is not "whatever we could afford", it is what is generally accepted for a business like yours.

Section 22 governs what happens when it goes wrong. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Regulator and, subject to subsection (3), the data subject, unless the identity of the data subject cannot be established. The notification must be made as soon as reasonably possible after the discovery of the compromise, taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the information system.

There is no numbered deadline in section 22, which is not the reprieve it sounds like. "As soon as reasonably possible after the discovery" gives you no fixed grace period to hide behind. The only permitted delay to notifying the data subject is under subsection (3), where a public body responsible for preventing, detecting or investigating offences, or the Regulator, determines that notification will impede a criminal investigation.

The content of the notice is prescribed. Under section 22(5) it must give the data subject enough information to take protective measures, including a description of the possible consequences of the compromise, a description of the measures the responsible party intends to take or has taken, a recommendation about what the data subject should do to mitigate the adverse effects, and the identity of the unauthorised person if it is known. It must be in writing, delivered by post to the last known address, by email, by a prominent position on your website, by publication in the news media, or as the Regulator directs.

Direct marketing and sending data offshore

Section 69 is the provision most likely to be breached by an ordinary small business, because it is breached by pressing send. Processing personal information for the purpose of direct marketing by means of any form of electronic communication, including automatic calling machines, fax machines, SMSs or email, is prohibited unless the data subject has consented, or is a customer of the responsible party.

The consent route is narrower than it looks. Under section 69(2) you may approach a data subject whose consent is required, and who has not previously withheld consent, only once in order to request that consent. One request, in the prescribed manner and form. If they ignore it, that is the end of the conversation.

The customer route has three cumulative conditions in section 69(3). You must have obtained the contact details in the context of the sale of a product or service. The marketing must be of your own similar products or services. And the data subject must have been given a reasonable opportunity to object, free of charge and without unnecessary formality, both at the time the information was collected and on the occasion of each communication. So the unsubscribe link is not a courtesy, it is a statutory condition of the exemption you are relying on. Section 69(4) separately requires every direct marketing communication to carry the identity of the sender or the person on whose behalf it was sent, and an address or other contact details for a request that the communications cease.

Cross-border transfer is governed by section 72, and it applies the moment your data leaves the Republic, including to a cloud server. A responsible party in the Republic may not transfer personal information about a data subject to a third party in a foreign country unless one of five things is true. The recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection that upholds principles substantially similar to the conditions for lawful processing, and that includes substantially similar provisions about onward transfer. Or the data subject consents. Or the transfer is necessary for the performance of a contract between the data subject and the responsible party, or for pre-contractual measures taken at the data subject's request. Or it is necessary for a contract concluded in the interest of the data subject between the responsible party and a third party. Or it is for the benefit of the data subject where obtaining consent is not reasonably practicable and the data subject would be likely to give it.

In practice, for a South African business using a cloud system hosted elsewhere, the workable route is usually the binding agreement in section 72(1)(a), and it needs to be in place before the data moves, not after a question is asked. That is the same contract conversation as section 21, and it is sensible to have both terms in one document.

What a small business should actually do

The practical work is smaller than the Act makes it look, and it is mostly one-off.

  1. Register your information officer

    Section 55(2) is unambiguous: officers must take up their duties in terms of the Act only after the responsible party has registered them with the Regulator. In a small company this is usually the head of the business by default. Section 56 provides for designating deputy information officers in the manner prescribed by section 17 of PAIA.

  2. Write down what you process and why

    Section 17 requires you to maintain documentation of all processing operations under your responsibility, as referred to in section 14 or 51 of the Promotion of Access to Information Act. One document listing each category of data, its purpose, its lawful ground under section 11, where it is stored and how long you keep it will satisfy this and will answer most Regulator questions.

  3. List your operators and check the contracts

    Every third party that touches customer data needs a written contract carrying the section 21 security obligation and, where the data leaves the country, the section 72 protections. Accounting system, CRM, email platform, bookkeeper, hosting.

  4. Fix your collection notices

    Section 18(1) requires you to take reasonably practicable steps to make the data subject aware of what is being collected, the source if it was not collected from them, and the name and address of the responsible party. A short line on your quotation, your enquiry form and your website does this.

  5. Build a route for access and correction requests

    Section 23 gives a data subject the right to confirm free of charge whether you hold information about them, and to request the record or a description of it including the identity of third parties who have had access. Section 24 gives the right to have inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained information corrected or deleted. You need one named inbox and one person who knows what to do.

  6. Decide your retention periods and enforce them

    Section 14(4) requires destruction, deletion or de-identification as soon as reasonably practicable once you are no longer authorised to retain a record. Five years after the last transaction is a defensible default for trading records because of tax record-keeping requirements. Marketing lists need a much shorter one.

The consequences are not theoretical. Section 73 defines interference with the protection of personal information as any breach of the Chapter 3 conditions, or non-compliance with sections 22, 54, 69, 70, 71 or 72. Section 99 gives a data subject, or the Regulator on their behalf, a civil action for damages. Section 109 allows the Regulator to serve an infringement notice specifying an administrative fine which may not exceed R10 million, with 30 days to pay, arrange to pay, or elect to be tried in court. Section 107 provides that certain offences carry a fine or imprisonment for a period not exceeding 10 years, and others up to 12 months.

Umbra helps with parts of this and not with others, and the distinction is worth being blunt about. Records are held in one system rather than scattered across spreadsheets and phones. The self-service details link lets a client supply and correct their own information. The assistant's deterministic matching reduces duplicate records. Scoped API keys mean an integration can be given access to invoices without being given access to everything. Separate businesses on one login stay separate, so a subsidiary's customer list is not merged into the parent's by accident. None of that makes a business POPIA compliant. Compliance is a set of decisions about purpose, notice, retention and contracts that only the responsible party can make, and that responsible party is you.

Frequently asked questions

Does POPIA apply to a sole proprietor?

Yes. The Act defines a private body to include a natural person who carries or has carried on any trade, business or profession, but only in that capacity. A sole proprietor holding customer names, phone numbers and addresses is a responsible party with the full set of obligations. There is no small-business exemption in POPIA.

Am I the responsible party or the operator?

If you decide why customer information is collected and how it is processed, you are the responsible party. Your accounting system, CRM, email platform and bookkeeper are operators: they process for you under a contract or mandate without coming under your direct authority. Responsibility does not transfer to them, and section 21 requires a written contract with each of them.

Do I need consent to keep a customer's details?

Usually not. Section 11(1) gives six grounds, and consent is only one. Holding a billing address to perform a contract, or a VAT number because the VAT Act requires it on a tax invoice, rests on the contract and legal obligation grounds. Asking for consent you do not need creates a withdrawal right you did not have to grant.

Can I email my customer list about a new product?

Only if they consented, or if they are a customer and three conditions in section 69(3) are met: you obtained the contact details in the context of a sale, the marketing is of your own similar products or services, and they were given a free and easy opportunity to object both at collection and in every message. Every message must also identify the sender.

Does POPIA protect companies as well as people?

Yes, which is a significant difference from European law. Section 1 defines personal information as information relating to an identifiable, living, natural person and, where applicable, an identifiable, existing juristic person. A business-to-business customer database of company names, addresses and registration details is personal information under POPIA.

Do I have to register an information officer with the Regulator?

Yes. Section 55(2) states that officers must take up their duties in terms of the Act only after the responsible party has registered them with the Information Regulator. In a small business this is typically the owner or chief executive by default. Section 56 provides for designating deputy information officers where the workload requires it.

Can my customer data be hosted outside South Africa?

Yes, if one of the section 72 grounds applies. The most workable for a business using an offshore cloud system is a binding agreement giving an adequate level of protection substantially similar to POPIA, including provisions on onward transfer. Consent, or necessity for performing a contract with the data subject, are the other common routes. Put it in place before the data moves.

What is the maximum fine for a POPIA breach?

Section 109 lets the Regulator serve an infringement notice specifying an administrative fine that may not exceed R10 million, with 30 days to pay, arrange payment or elect to be tried. Section 107 provides for criminal penalties, with certain offences carrying a fine or imprisonment of up to 10 years and others up to 12 months.

Sources

Regulatory figures on this page are taken from the following primary sources. Tax rates and thresholds change; check the source before relying on a figure.