POPIA for Small Businesses: The IT Checklist
Published: September 20, 2026 | By Code Masters | 9 min read
The Protection of Personal Information Act 4 of 2013 (POPIA) has been fully in force since 1 July 2021. If your business holds names, ID numbers, medical records, payroll files or client matters, it applies to you, and the Information Regulator enforces it. Most owners of an accounting practice, law firm, medical practice, estate agency, school or shop know this. Fewer know what to actually do about it on the IT side.
This article is that list. It is IT guidance, not legal advice; speak to your attorney about the legal side. Here are the controls that matter, why POPIA cares, and how a business without an IT department gets them done.
What POPIA Actually Asks of Your IT
Three parts of the Act drive almost everything on this checklist:
- Section 19 requires "appropriate, reasonable technical and organisational measures" to secure personal information against loss, damage, unauthorised destruction and unlawful access. It does not prescribe products; it expects reasonable safeguards for the risks you face.
- Section 22 requires you to notify the Information Regulator and the affected data subjects when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. The Act says this must happen "as soon as reasonably possible" after discovery. It sets no fixed number of hours; do not rely on a 72-hour rule you read elsewhere.
- The Information Officer. Every business must have one, by default the head of the business, and registered with the Regulator.
Penalties can include administrative fines of up to R10 million and, for certain offences, imprisonment. The bigger day-to-day risk is simpler: a breach you cannot contain, explain or recover from.
The IT Checklist
1. Know What Personal Information You Hold and Where
What it is: a one-page data map listing each type of personal information (client records, payroll, CVs, patient files), where it lives (server, Microsoft 365, accounting package, laptop, filing cabinet) and who can reach it. Why POPIA cares: you cannot secure, correct, delete or report on information you have not located, and the first question after a breach is what was exposed. How: an hour with each department head, written down and updated twice a year.
2. Least-Privilege Access on Shared Drives
What it is: staff see only the folders their job requires; payroll, HR and client financials sit in restricted folders, not a wide-open company share. Why POPIA cares: unlawful access includes the receptionist who opens the salary spreadsheet, and broad access means one phished account exposes everything. How: group permissions by role, remove "Everyone" from sensitive folders, and review access quarterly and whenever someone leaves.
3. Multi-Factor Authentication on Email and Cloud
What it is: a second check (an app prompt or code) when signing in to Microsoft 365, your accounting platform and remote access. Why POPIA cares: stolen passwords are the most common way into a small business, and your mailboxes hold years of personal information. How: turn on MFA for every user, the boss included. Our Microsoft 365 support team sets this up as standard.
4. Encrypted Laptops and Phones
What it is: full-disk encryption: BitLocker on Windows, FileVault on Mac, and the built-in encryption on iPhone and Android behind a screen lock. Why POPIA cares: a stolen laptop with a readable drive is a security compromise; an encrypted one with the key kept safe exposes far less. How: enable BitLocker, store recovery keys centrally (Microsoft Entra or a password manager), and require a PIN on every phone that reads work email.
5. Patched Systems
What it is: Windows, macOS, browsers, Office, your practice software and firewall firmware kept current. Why POPIA cares: most intrusions exploit a known flaw whose fix was never installed; "reasonable measures" is hard to argue when a two-year-old patch was missing. How: automatic updates on every workstation, a monthly server patch window, and retire anything unsupported, such as Windows 10.
6. Endpoint Protection
What it is: modern endpoint protection on every computer and server, centrally managed, with alerts that somebody actually reads. Why POPIA cares: ransomware encrypts personal information, which is loss and unauthorised access under Section 19 and usually notifiable under Section 22. How: one product, every device, managed from one console. Free consumer antivirus with no central visibility does not count.
7. A Firewall With Logging
What it is: a business-grade firewall between your office and the internet that blocks inbound traffic by default and keeps logs. Why POPIA cares: Section 22 asks you to report what happened; without logs you are guessing about when and how. How: replace the ISP router-as-firewall with a proper unit, close unused ports (especially remote desktop), and keep at least 90 days of logs.
8. Secure Wi-Fi With a Guest Network
What it is: WPA2 or WPA3 with a strong passphrase for staff, and a separate guest network for visitors that cannot reach your server or printers. Why POPIA cares: a visitor's infected laptop on the same network as your server is a direct path to personal information. How: most business access points support a second, isolated network; change the staff password when someone leaves.
9. Email Security: SPF, DKIM, DMARC and Anti-Phishing
What it is: DNS records that stop criminals sending mail as your domain, plus filtering that catches phishing before staff see it. Why POPIA cares: invoice fraud and credential theft nearly always start with an email, and a spoofable domain puts your clients at risk too. How: publish SPF, DKIM and DMARC, enable your mail platform's anti-phishing and safe-link features, and flag external emails with a banner.
10. Tested Backups With a Retention Policy
What it is: automatic backups of the server, Microsoft 365 and any line-of-business database, kept off-site and test-restored at least quarterly. Why POPIA cares: the Act treats loss and destruction as seriously as theft, a backup you have never restored is a hope rather than a control, and the Act expects you not to keep personal information longer than you need it. How: follow the 3-2-1 rule (three copies, two media, one off-site), write down how long each data type is kept, and schedule a restore test. Our disaster recovery service covers this end to end.
11. Secure Disposal of Drives and Paper
What it is: wiping or physically destroying drives, phones and copier hard disks before they leave the building, and shredding paper records. Why POPIA cares: discarded information is still personal information; a retired PC at a second-hand dealer is a breach waiting to happen. How: use a certified wipe tool or a destruction service, keep a disposal register, and put a shredder next to the printer.
12. Contracts With Operators (Vendors and Cloud)
What it is: any outside party that processes personal information for you (payroll bureau, cloud host, IT provider) is an "operator" under POPIA and must process it only on your instruction and with adequate security. Why POPIA cares: their breach is still your breach to report. How: list your operators, get a written agreement covering confidentiality and security, and ask each where your data is stored and how they would notify you of an incident.
13. Staff Training and a Phishing Drill
What it is: short, regular training on phishing, passwords and what to do when something looks wrong, followed by a simulated phishing email to see who clicks. Why POPIA cares: "organisational measures" in Section 19 means people, not only software, and most incidents start with a click. How: a 30-minute session at induction and once a year, a quarterly simulated phish, and a no-blame rule so people report mistakes quickly.
14. A Written Incident Response Plan
What it is: a two-page document that says who does what when a compromise is suspected: isolate the machine, call the IT provider, preserve logs, work out which personal information was involved and whose, notify the Information Regulator and the affected data subjects as soon as reasonably possible, and record the sequence with times. Why POPIA cares: Section 22 lands on your desk on a bad day with no time to think. How: write it, print it, add the Information Officer's and IT provider's numbers, and walk through it once a year.
15. Logging and Review
What it is: sign-in logs for Microsoft 365, firewall logs, file-access auditing on sensitive folders, and a monthly look at them. Why POPIA cares: the difference between "we believe three records were accessed" and "we do not know" is logging. How: enable audit logging in your cloud platform, keep firewall logs, and review MFA failures and unusual sign-in locations monthly.
What a Breach Actually Looks Like in a 20-Person Office
It is rarely dramatic. A bookkeeper receives an email that looks like it is from the bank, signs in on a copied page, and hands over a password. With MFA off, the attacker reads the mailbox for three weeks, learns which clients pay when, and sends a "new banking details" email from the real account. They also download the mailbox: ID numbers on FICA documents, salary schedules, medical certificates.
Now count the POPIA questions. What was accessed? Without mailbox audit logs, you do not know. Who is affected? Everyone whose details were in that mailbox. When did it start? Unknown. You must now notify the Regulator and the data subjects, as soon as reasonably possible, and explain what safeguards were in place. Three controls from the list (MFA, logging and an incident plan) would have turned a month-long crisis into a contained afternoon.
Start Here This Week: The Five Cheapest Controls
- Turn on MFA for every email and cloud account. Cost: about an hour.
- Enable BitLocker on every laptop and a PIN on every phone. Cost: an afternoon.
- Switch on automatic updates and retire unsupported machines. Cost: mostly nothing.
- Write the one-page data map and the two-page incident plan. Cost: a morning.
- Split the Wi-Fi into staff and guest networks. Cost: usually a setting on your existing access point.
Together, these five close the doors most small-business breaches walk through.
Getting It Done Without an IT Department
Most SMEs do not need a consultant to tick this list; they need someone to configure it and keep it configured. Code Masters includes cybersecurity (firewalls, endpoint protection, access control), Microsoft 365 administration with MFA, tested backups, encrypted laptops and a written incident plan in managed IT support from R750 per user per month. Our cybersecurity checklist for South African SMEs is a good companion, and our IT support team in Pretoria and Centurion can review your office against it.
Need Help With Your POPIA IT Controls?
257 Jean Avenue, Centurion. Helpdesk 07:00 to 18:00 weekdays, emergencies 24/7. Call 060 131 5099 or send us a message and we will walk through this checklist with you.
Call 060 131 5099Contact Us