Skip to content
GLOSSARY

POPIA

ALSO CALLED: PROTECTION OF PERSONAL INFORMATION ACT

Definition

POPIA is the Protection of Personal Information Act, South Africa's data-protection law, in force since 2021. It sets conditions for how any organisation collects, stores, uses and shares personal information about people — customers, staff, drivers, the individuals at your suppliers. Information must be collected for a stated purpose, kept secure, kept no longer than it is needed, and made available to the person it describes on request. Every business holds personal information, so the Act applies whether or not a business thinks of itself as handling data.

WHY IT MATTERS FOR AN SA FOOD BUSINESS

What it changes in practice.

An operations business holds more personal information than it realises: driver names on delivery notes, staff rosters and hours, customer contact numbers in a WhatsApp group, the individual at a supplier whose cellphone number is on every order. All of it is in scope.

It also shapes what you should expect from any software you connect to that data — where it is stored, who at the vendor can see it, and what happens to it if you leave. Those are fair questions to ask before an integration, not after one.

AS A FINDING

What it looks like when Finch catches it.

DOC-UNEW
Delivery notes carry driver names and cell numbers. Retention was never set.
Personal information held with no stated purpose
1 document setPOPIA · RETENTION · AUG
Set a retention rule·Read the privacy policy·Dismiss
ILLUSTRATIVE EXAMPLE
KEEP READING

← All glossary terms

Start with a one-week Operations Audit.

R2,000, credited to your first month. We tell you where the money is leaking — whether you sign or not.

Book your audit