POPIA Isn’t Optional Anymore
South Africa’s Information Regulator has stopped waiting for complaints and started going out and checking. Here’s what every SME owner needs to have in place before that knock comes.
For a long time, POPIA was the law everyone knew about and almost nobody actually operationalised. A privacy policy on the website, a line in the employment contract, and that was that. That era is closing. The Information Regulator has moved from a complaints desk to a proactive watchdog, it has shown it will fine, and the sectors it’s circling first — financial services, insurance, health, retail, telecoms, and the public sector — are exactly where most South African SMEs live. If you handle customer records, staff files, or supplier data, this piece is for you.
The Regulator Has Teeth Now
And it’s finally using them.
Translation: the Regulator used to only act if someone complained. Now it’s actively auditing businesses whether they’ve complained or not — and it’s started handing out real fines.
The Information Regulator presented its 2025/26 and 2026/27 plan to Parliament’s Portfolio Committee on Justice and Constitutional Development in May 2026, and the message was unambiguous: it is moving away from a purely reactive, complaints-driven model toward its own compliance assessments — proactively checking sectors that hold large volumes of personal information, rather than waiting to be told there’s a problem.
The Regulator’s first big enforcement case is worth understanding properly, because it shows exactly what triggers a fine. The Department of Justice and Constitutional Development suffered a ransomware attack in 2021 after letting its security software licences lapse — a mundane, entirely preventable failure. The Regulator issued an enforcement notice in May 2023 ordering the department to fix its security and prove it had done so. It didn’t comply in time. Only then did the R5 million fine follow, via an infringement notice. That sequence matters: the fine wasn’t for the breach itself — it was for failing to respond properly once the Regulator stepped in. A second R5 million fine has since followed the same pattern, and a R500,000 fine was issued against a municipality on separate grounds. Direct marketing non-compliance and data breach management have both been flagged as priority enforcement areas.
There’s also a new, sector-specific tightening worth knowing about even if it doesn’t apply to your business directly: regulations on the processing of health information came into force on 6 March 2026 with no grace period, giving insurers, medical schemes, employers, and pension funds an explicit, higher bar for handling health data. If your SME touches employee medical information — even something as simple as sick notes or a company wellness benefit — it’s worth checking whether this affects you.
Where SMEs Actually Get Caught Out
It’s rarely the dramatic data breach. It’s the paperwork nobody got around to.
Translation: most POPIA problems aren’t hackers — they’re a business that never appointed anyone to be responsible for data, never wrote anything down, and hopes nobody asks.
In practice, the gap between “we have a privacy policy” and “we are actually POPIA compliant” comes down to a handful of concrete, unglamorous requirements. These are the ones I see SMEs miss most often.
No registered Information Officer
Every business processing personal information is required to have an Information Officer responsible for POPIA (and PAIA) compliance, registered with the Regulator. Many owners either don’t know this obligation exists or assume a website privacy notice covers it. It doesn’t — this is a specific, named-person registration.
No PAIA manual
Alongside POPIA, most organisations are required to have a manual describing how people can request access to information the business holds. This is frequently skipped entirely, and it’s one of the first things an assessment checks for.
Unresolved data subject requests
When a customer or employee asks what data you hold, or asks you to correct or delete it, POPIA expects a timely, documented response — not silence, and not a fee steep enough to discourage the request.
Direct marketing without proper consent
Flagged as a current priority area for the Regulator. If your marketing list wasn’t built with clear, POPIA-compliant consent, every campaign you send is a live exposure, not a growth channel.
No incident response plan
The Department of Justice case shows the pattern clearly: it isn’t the incident itself that draws the heaviest penalty, it’s the absence of adequate security measures and a documented plan to respond when something goes wrong.
The Real Financial Exposure
Administrative fines under POPIA can reach R10 million per contravention, with the amount weighed against factors like how sensitive the information was, how many people were affected, and whether the failure was preventable. For the most serious offences — obstructing the Regulator, or unlawfully disclosing things like account numbers — the penalty can extend to imprisonment of up to 10 years. For an SME, the fine itself is often survivable. The reputational cost of an enforcement notice becoming public rarely is.
POPIA Meets King V: A Governance Issue, Not Just A Legal One
The sequel to where we left off with AI and data governance.
Translation: your lawyer can keep you POPIA-compliant on paper. What King V is now asking is whether your board actually governs data as a strategic asset — POPIA compliance is the floor, not the whole conversation.
This is where POPIA compliance stops being purely a legal or IT matter and becomes a board-level governance question. King V, the new corporate governance code that took effect for financial years beginning on or after 1 January 2026, dedicates one of its thirteen principles specifically to the governance of data, information, and technology. That’s not a coincidence — it reflects the same shift in expectation that’s driving the Regulator’s more proactive posture: personal information is now treated as something governing bodies must actively steward, not something that sits quietly with the IT department until there’s a problem.
King V isn’t law — it’s a voluntary code, and it applies most directly to larger, JSE-listed entities. But its logic travels downward fast, because banks, insurers, and corporate customers increasingly expect the SMEs in their supply chain to reflect the same standard. If you’re a smaller business hoping to win or keep contracts with larger, more governed clients, being able to show a documented POPIA compliance framework — an appointed Information Officer, a breach response plan, evidence of how you handle data subject requests — is quickly becoming a commercial requirement, not just a defensive one.
Data governance has moved from an IT checkbox to a board-level responsibility — and the businesses that treat it that way now will be the ones with the paper trail when the Regulator, or a client’s due diligence team, comes asking.
Eli Masechaba, AscentpeakThe Bottom Line
POPIA compliance for a South African SME isn’t about being perfect — it’s about being able to show your work. An appointed Information Officer, a PAIA manual, a documented process for data subject requests, real consent behind your marketing list, and a plan for the day something goes wrong. None of it is exotic. Most of it is a few weeks of proper governance discipline, not a major IT project.
What’s changed in 2026 is the cost of not doing it. The Regulator is checking proactively, the fines are no longer theoretical, and the businesses your SME wants to work with are increasingly asking the same questions the Regulator is. Treating data governance as a board-level responsibility — in the spirit King V now asks of larger organisations — isn’t red tape. It’s how you stay fundable, contractable, and out of an enforcement notice’s way.

