Four POPIA Myths That Are Putting Small Businesses at Risk

Most small business owners know POPIA exists. Far fewer understand what it actually requires of them. Here are four common misconceptions — and what the law really says.

South Africa's Protection of Personal Information Act (POPIA) has been fully in force since 2021, but a large number of small businesses are still operating under assumptions about the law that simply aren't true. Surveys of the local SME sector have repeatedly found that large shares of small businesses believe POPIA only applies to digital records, or that compliance is optional for small firms. Neither is correct — and the gap between what owners believe and what the law requires is where risk quietly accumulates. This post unpacks four of the most persistent myths: - Myth 1: POPIA is only for big companies - Myth 2: It only applies to digital data - Myth 3: We're compliant because we have a privacy policy on our website - Myth 4: Nothing will happen to us if we're not compliant ## Myth 1: POPIA Is Only for Big Companies This is probably the most widespread misunderstanding. POPIA applies to any person or organisation that **processes personal information** about others — and "processes" is defined very broadly. Collecting a customer's name and phone number, storing employee payslips, emailing a supplier quote, keeping a WhatsApp group for clients — all of it falls within POPIA's scope. There is no employee headcount or turnover threshold below which the Act stops applying. If you have customers, staff, or suppliers, you're processing personal information, and the law applies to you. > POPIA doesn't have a "small business" exemption. If you process other people's data — even just a contact list — it applies to you. ## Myth 2: It Only Applies to Digital Records POPIA covers personal information in **any form** — digital files, printed documents, handwritten notes, even information held in your head as part of an ongoing business relationship (where records exist). A client file in a cabinet is as subject to the Act's protection principles as a spreadsheet on your desktop. In practice, this means physical records matter too. Printed job applications with ID numbers, customer invoices filed in a folder, staff contracts in a drawer — all of it needs to be handled, stored, and eventually disposed of in line with the law. ## Myth 3: A Privacy Policy on the Website Means We're Compliant A website privacy policy is one piece of POPIA compliance — specifically, it's part of informing people about what you collect. But POPIA's requirements go further than disclosure. The Act sets out **eight conditions for lawful processing**, covering how you collect data, why you're allowed to use it, how long you keep it, who you share it with, and how you protect it. Simply posting a policy doesn't address most of these. Without a clear understanding of what personal information your business holds, where it lives, who can access it, and how it's secured, a privacy policy is a legal document with no operational backing. Real compliance is a process, not a page. ## Myth 4: Nothing Will Happen If We're Not Compliant The Information Regulator — the body that enforces POPIA — has been building its enforcement capacity since the Act came into force. While large, high-profile breaches are the most visible enforcement targets, the Regulator has the power to investigate complaints from any individual whose personal information was mishandled, regardless of the size of the organisation involved. The penalties under POPIA can reach up to **R10 million or ten years' imprisonment** for the most serious contraventions. More practically for most small businesses, a data breach — even a small one, like a customer list being stolen or emailed to the wrong person — triggers notification obligations to both the Regulator and the affected individuals. The reputational and operational cost of that process tends to far exceed the cost of getting the basics right beforehand. ## Where to Start Compliance doesn't require a team of lawyers. For most small businesses, the practical starting point is understanding what personal information you collect and hold, where it is, who has access to it, and whether you have a plan if something goes wrong. That audit is the foundation everything else builds on. ## How Bighearts Online Can Help Bighearts Online works with small organisations on the systems and tools that underpin day-to-day operations — including the secure handling of data. If you're not sure whether your current setup gives your customers' and employees' information the protection it needs, we can help you take a practical look at where you stand.