Security
POPIA IT checklist for a South African small business
Use this operational checklist to make personal-information handling more defensible before a breach or regulator question. It is not legal advice; the responsible information officer and qualified advisers control the legal decision.
Map where personal information lives
Write down the systems that hold customer, employee, supplier, prospect, and lead data. Include email inboxes, cloud drives, phones, accounting tools, website forms, messaging apps, CRM exports, spreadsheets, and backups.
Record the owner, purpose, access group, retention expectation, supplier, and recovery method for each system. You cannot protect data that nobody can locate.
Control identity and access
Use individual accounts, multi-factor authentication, least privilege, screen locks, administrator separation, and a documented offboarding process. Remove access when a person leaves or changes role.
Review shared mailboxes, external sharing, forwarding rules, connected applications, browser extensions, and stale devices. A shared password makes accountability and offboarding harder.
Protect devices and connections
Patch operating systems, browsers, routers, and business software. Encrypt laptops where supported, protect phones with a passcode or biometric lock, and use a controlled process for lost, stolen, or retired devices.
Keep a current inventory of devices, users, operating systems, support owners, and wipe or replacement procedures. Record exceptions and an end date instead of allowing unsupported devices indefinitely.
Control forms and sharing
Review what website forms collect, who receives the information, where it is stored, how long it is retained, and whether a third-party provider is involved. Collect only what the stated business purpose requires.
Check email forwarding, shared links, downloads, exports, and personal devices. A convenient transfer can create a copy of the data outside the control of the intended system.
Back up and test recovery
Keep a recovery path for important records and separate at least one copy from the main administrator account or environment. Synchronisation is not automatically an independent backup because deletion or encryption can propagate.
Restore a real file, record the time, and confirm who can perform recovery. Include SaaS, website, accounting, and exported lead data where the business depends on it.
Prepare an incident route
Keep an incident log and clear escalation path for a lost device, stolen password, suspicious attachment, compromised mailbox, or unexpected payment instruction. Preserve evidence, contain clearly compromised access, and record the person, time, and reason for each action.
If personal information may have been accessed or acquired by an unauthorised person, the Information Regulator guidance and qualified legal advice should control the notification decision.
Check suppliers and ownership
Ask IT, hosting, software, CRM, email, and lead providers where data is stored, who can access it, how it is recovered, what subcontractors are used, and how the business receives or deletes data when the agreement ends.
Keep domains, cloud tenants, administrator accounts, backups, exports, documentation, and recovery contacts under business control. Ask for written scope and an exit process.
Review the checklist regularly
Review the map, access, devices, suppliers, backups, forms, retention, incidents, and staff training after a system change, new service, staff change, suspected incident, or material change in the business.
Small Business IT SA provides an operational starting point, not a POPIA compliance certificate. Use the current Information Regulator guidance and qualified advice for the legal boundary.
Sources and further reading
Back to all guides Compare support options Compare software Compare hosting