POPIA Compliance for Solopreneurs: The 10-Minute Checklist

POPIA Compliance for Solopreneurs: The 10-Minute Checklist

You don't need a legal department to take POPIA seriously.

If you're a solopreneur, freelancer or small business owner, you probably handle personal information every day.

Names.
Email addresses.
Phone numbers.
Invoices.
Customer messages.
Website enquiries.
Payment information.
Employee or contractor details.

The Protection of Personal Information Act (POPIA) applies to the processing of personal information by private bodies in South Africa, including small businesses. The Information Regulator is responsible for monitoring and enforcing compliance.

The good news is that getting your basic privacy practices in order doesn't have to be complicated.

Here's a 10-minute POPIA health check you can do today.


1. What personal information do you actually collect?

Take a quick look at your business.

Do you collect:

  • Names and surnames?
  • Email addresses?
  • Phone numbers?
  • ID numbers?
  • Addresses?
  • Customer correspondence?
  • Payment or banking information?
  • Information about employees or contractors?
  • Information through website forms?

Make a quick list.

If you don't know what information you have, you can't properly protect it.


2. Why are you collecting it?

For every type of information, ask:

"Why do I need this?"

You should have a clear, legitimate purpose for collecting and processing personal information.

For example:

Customer name + email:
To communicate about a service or enquiry.

Billing information:
To issue invoices and manage payments.

Phone number:
To communicate with the customer about their service.

Don't collect information simply because you might need it someday.

The Information Regulator's own privacy principles emphasise collecting only information that is genuinely necessary for a defined purpose.


3. Tell people what you're doing with their information

Do your customers know:

  • What information you collect?
  • Why you collect it?
  • Who may receive it?
  • How they can contact you about their information?
  • What their rights are?

Your website should have an appropriate Privacy Notice or Privacy Policy.

A privacy notice should provide important information about the collection and use of personal information, including the purpose of processing, the responsible party, recipients, certain rights of data subjects and relevant contact information.

If you haven't looked at your privacy policy for years, it's worth reviewing it.


4. Check your website forms

Open your website and test your contact forms.

Ask yourself:

What information am I asking people to provide?

If your contact form asks for:

Name, email, phone number and message

that's probably reasonable for many enquiries.

But if you're collecting significantly more information than you actually need, stop and ask why.

Also make sure your privacy information is easy for visitors to find.


5. Look at your email and WhatsApp

Small businesses often handle customer information through ordinary communication tools.

Check:

  • Email accounts
  • WhatsApp
  • Google Workspace or Microsoft 365
  • Cloud storage
  • Customer databases
  • CRM systems
  • Spreadsheets

Ask:

"If someone gained access to this account, how much customer information could they see?"

This is where POPIA and cybersecurity overlap.


6. Turn on MFA

This is one of the quickest security improvements you can make.

Enable multi-factor authentication (MFA) on important accounts such as:

  • Email
  • Microsoft 365 or Google Workspace
  • Cloud storage
  • Banking
  • Accounting platforms
  • CRM systems
  • Social media
  • Website administration

The Information Regulator's privacy guidance specifically recommends strong passwords, device security and MFA as important protective measures.

Your password protects the account.

MFA helps protect the password from being the only thing standing between an attacker and your data.


7. Check who can access customer information

As a solopreneur, you may have fewer people to worry about—but don't forget about:

  • Freelancers
  • Virtual assistants
  • Bookkeepers
  • IT providers
  • Marketing agencies
  • Cloud service providers
  • Software platforms

Ask:

"Who can access my customers' information, and do they actually need that access?"

Access should be limited to what is necessary.


8. Stop keeping information forever

Take a quick look at your old files.

Do you still have:

  • Old customer spreadsheets?
  • Previous enquiry forms?
  • Outdated copies of ID documents?
  • Old employee information?
  • Old email exports?
  • Customer information stored on old computers?
  • USB drives containing historical data?

If you no longer need personal information for a legitimate purpose, keeping it indefinitely can create unnecessary risk.

Less data = less data to protect.


9. Know what happens if you have a breach

Imagine this:

You lose your laptop.

Or your email account is hacked.

Or someone accidentally sends a customer list to the wrong person.

Do you know what you would do?

You should have a simple data breach response process.

At minimum, know:

  1. How to contain the incident.
  2. What information may have been exposed.
  3. Who needs to be notified internally.
  4. Whether affected data subjects need to be notified.
  5. Whether the Information Regulator needs to be notified.
  6. What steps will prevent the incident from happening again.

The Information Regulator's eServices portal provides a facility for reporting personal-information security compromises.


10. Know who your Information Officer is

POPIA provides for Information Officers, and the Information Regulator states that Information Officers must be registered before assuming their duties.

For a small business, this is particularly important because there may not be a separate privacy or compliance department.

Don't assume that being a one-person business means POPIA doesn't apply to you.

Check your responsibilities and make sure your business has dealt with the Information Officer requirement appropriately.

The Information Regulator also provides online POPIA self-assessment services through its eServices portal.


Your 10-Minute POPIA Checklist

Before you finish, ask yourself:

CheckQuestion
Do I know what personal information I collect?
Do I know why I collect it?
Do I tell people how I use their information?
Do I have an appropriate privacy notice/policy?
Have I checked my website forms?
Is MFA enabled on important accounts?
Do I know who has access to customer information?
Have I removed unnecessary old information?
Do I have a basic data-breach response plan?
Have I addressed my Information Officer responsibilities?

If you can confidently tick every box, you're off to a much better start.

If several boxes are still empty, don't panic.

Start with the biggest risks first.


POPIA Isn't Just a Legal Problem

It's easy to think of POPIA as paperwork.

But there's another way to look at it.

POPIA is also a cybersecurity issue.

Protecting personal information means protecting the systems, accounts, devices and processes that hold that information.

A small business doesn't need an enormous IT department to improve its security.

It needs good habits, sensible processes and the right technology.


One Final Question

Take a look at your business today and ask:

"If my laptop disappeared tomorrow, would my customers' personal information still be safe?"

If you're not completely confident about the answer, that's a good place to start.

For practical technology support, cybersecurity guidance, cloud solutions and technology advice for small businesses, visit Cybertaries.

Important: This article is intended as a practical starting point and is not legal advice. POPIA compliance depends on your specific business, the information you process and how you process it. For legal or compliance questions, obtain appropriate professional advice.

Comments

Popular posts from this blog

Is Your Email Account Compromised? 7 Warning Signs to Act On

Top 3 Tech Mistakes South African Small Businesses Make

How to Keep Your Computer Virus-Free Without Paying for Expensive Software