Skip to main content
← All guides

South Africa, POPIA & local trade

POPIA for e-commerce operators: a practical guide

The Smart Station team11 min read

The Protection of Personal Information Act is shorter and more readable than most people expect. It is also frequently over-complicated by consultants, and under-implemented by businesses who assume it is somebody else's problem. This is what it actually asks of a South African online retailer.

This is a practical summary, not legal advice. Where the answer materially affects your business, get a qualified opinion.

What POPIA covers

POPIA governs the processing of personal information about a natural or juristic person. "Processing" is deliberately broad: collecting, storing, using, sharing and deleting all count.

For an online retailer the personal information in scope is usually narrower than expected:

  • Customer names, email addresses, phone numbers and delivery addresses
  • Staff records in whatever systems hold them
  • Anything identifying a contact person at a business customer
  • Behavioural data that can be linked to an identifiable person

Your product data is not personal information. Descriptions, specifications, part numbers and datasheets fall entirely outside POPIA. This matters, because it means the largest data set in a distribution business is not the compliance problem.

The eight conditions, plainly

  1. 01Accountability — somebody is responsible, and that somebody is named.
  2. 02Processing limitation — collect only what you need, with a lawful basis, and with consent where consent is the basis.
  3. 03Purpose specification — be clear why you are collecting it, and do not quietly reuse it for something else.
  4. 04Further processing limitation — new uses need a new justification.
  5. 05Information quality — keep it accurate and current.
  6. 06Openness — tell people what you hold and why, in a notice they can find.
  7. 07Security safeguards — protect it, and report breaches.
  8. 08Data subject participation — people may see what you hold, and have it corrected or deleted.

The four things to do first

If you have done nothing, these four have the highest ratio of risk reduced to effort spent.

1. Appoint and register your information officer. By default this is the head of the business, whether or not anyone has told them. The role can be delegated but not abdicated. Registration is with the Information Regulator and is not onerous.

2. Write a privacy notice somebody can read. It must say what you collect, why, who you share it with, how long you keep it, and how someone exercises their rights. A four-thousand-word document copied from an American template satisfies nobody and misstates your position.

3. List your sub-processors. Every SaaS product that touches customer data is processing on your behalf: your storefront, email platform, payment gateway, accounting system, helpdesk. You need to know who they are and where they process. Most businesses have never made this list, and making it takes an afternoon.

4. Decide what happens when somebody asks. A data subject request starts a thirty-day clock. Knowing in advance who fields it, how identity is verified and where the information lives turns a fire drill into a routine task.

The cross-border question

Section 72 restricts transferring personal information outside South Africa. In practice almost every SaaS product does this, so the question is not whether you transfer but whether you have a lawful basis.

The available bases include the data subject's consent, necessity for performing a contract with them, and the recipient being subject to a law or binding agreement providing an adequate level of protection. Most vendor data processing agreements are drafted to establish the third.

The practical step: ask each vendor where they process, and get the answer in writing. A vendor who cannot answer that question quickly is telling you something useful.

What this means for supplier product content

A question that comes up specifically in distribution: does POPIA apply to product data scraped or copied from supplier websites?

Almost never. Product descriptions and specifications are not personal information. The exception is where a supplier page contains a named contact person — a technical representative, for instance — in which case that name is personal information and should not be carried into your catalogue.

The real legal question about supplier product content is copyright and your distribution agreement, not POPIA. That is a different conversation, and worth having separately.

Common questions

Does POPIA apply to product data?
Almost never. Product descriptions, specifications, part numbers and datasheets are not personal information. The exception is where a supplier page names a contact person, such as a technical representative — that name is personal information and should not be carried into your catalogue.
Who is the information officer under POPIA?
By default the head of the business, whether or not anyone has told them. The role can be delegated but not abdicated, and registration is with the Information Regulator.
Can we use software that stores South African customer data overseas?
Yes, if you have a lawful basis under section 72. The available bases include the data subject's consent, necessity for performing a contract with them, and the recipient being subject to a law or binding agreement providing an adequate level of protection. Most vendor data processing agreements are drafted to establish the third.
How long do we have to answer a POPIA data subject request?
Thirty days. Knowing in advance who fields it, how identity is verified and where the information lives turns it from a fire drill into a routine task.

Where to next

Who wrote this

The Smart Station team

Written by the engineering and delivery team at Smart Station (Pty) Ltd, the South African software company that builds GetShopSync. The material here comes from building catalogue systems for distributors — it is what we have measured and what we have got wrong, not a survey of the literature.

See it against your own catalogue.

Thirty minutes. Bring three supplier URLs and we will capture them live, so you are judging the output rather than the pitch.