Guide
A POPIA readiness checklist South African SMEs can actually finish
Twelve practical checks covering operator agreements, access logs, and breach contacts—without drowning a small team in paperwork.
Many Cape Town and Johannesburg SMEs start POPIA work with a thick template pack and stop halfway. Readiness is less about collecting every possible policy and more about proving you know where personal information sits, who can touch it, and what happens when something goes wrong.
Begin with a processing inventory limited to the five flows that matter most: onboarding customers, paying staff, using cloud tools, sharing data with accountants or marketing partners, and storing CCTV or visitor logs. If a flow is not on that list yet, schedule it for a later cycle rather than blocking progress.
Next, confirm that every operator—payroll bureau, CRM host, courier with delivery notes—has a written agreement that mentions purpose, security expectations, and breach notice timing. Verbal habits do not survive a customer due-diligence questionnaire.
Access reviews are often the weakest link. Ask each system owner for a current user list, remove departed staff, and note who can export bulk personal information. Keep the evidence: a dated spreadsheet is enough for many first-year programmes.
Finally, appoint a reachable incident contact and rehearse a short script: contain, assess, notify if required, and record decisions. Page Willowhub’s readiness assessments use a similar sequence so teams leave with a 90-day list instead of an abstract maturity score.