Since the full implementation of the Protection of Personal Information Act (POPIA), businesses across South Africa have been expected to take data privacy far more seriously. The legislation was introduced to protect personal information and ensure that organisations collect, store, and process data responsibly.

However, despite increased awareness around compliance, many businesses still violate POPIA, sometimes knowingly, but often unintentionally. In many cases, organisations underestimate how broad the law actually is or assume that compliance only applies to large corporations.

The reality is that any business handling personal information has responsibilities under POPIA, regardless of size.

Here are three of the most common POPIA violations still being committed by South African businesses today.

1. Collecting Personal Information Without Proper Consent

One of the most frequent POPIA violations is collecting or using personal information without obtaining valid consent from the individual involved.

Many businesses gather customer data through:

  • Website contact forms
  • Marketing sign-ups
  • Social media campaigns
  • Loyalty programs
  • WhatsApp communication

However, businesses often fail to clearly explain:

  • What information is being collected
  • Why it is being collected
  • How it will be used
  • Whether it will be shared with third parties

Under POPIA, organisations cannot simply collect personal data because it may become useful later. There must be a lawful and specific purpose for collecting the information.

A major issue occurs with direct marketing. Some businesses automatically add customers to mailing lists or promotional campaigns without proper permission. Others make it difficult for users to unsubscribe or opt out.

This creates both legal and reputational risk.

Why this is a problem

Customers are becoming increasingly aware of privacy rights. Businesses that misuse personal information risk:

  • Customer complaints
  • Damage to brand trust
  • Investigations by regulators
  • Financial penalties

How businesses can avoid this

Businesses should:

  • Use clear consent forms
  • Explain data usage transparently
  • Keep records of consent
  • Make opt-out processes simple and accessible

Consent should never be vague, hidden, or assumed.

2. Poor Cybersecurity and Weak Data Protection

Another extremely common POPIA violation involves failing to properly secure personal information.

Many South African businesses still rely on:

  • Weak passwords
  • Shared logins
  • Outdated software
  • Unsecured Wi-Fi networks
  • Poor access control practices

POPIA requires organisations to take “appropriate, reasonable technical and organisational measures” to protect data from loss, unauthorised access, or cyberattacks.

Unfortunately, many businesses only think about cybersecurity after a breach has already happened.

This is particularly dangerous because cybercriminals increasingly target smaller businesses, knowing they often lack dedicated IT security resources.

Examples of weak protection

Common issues include:

  • Employee laptops containing unencrypted customer data
  • Sensitive files shared through insecure channels
  • Lack of backup systems
  • Staff falling victim to phishing emails

Even accidental exposure of customer information can constitute non-compliance under POPIA.

Why this matters

A data breach can lead to:

  • Loss of customer trust
  • Financial losses
  • Operational disruption
  • Mandatory reporting obligations
  • Potential regulatory consequences

How businesses can improve

Businesses should invest in:

  • Strong password policies
  • Multi-factor authentication
  • Employee cybersecurity training
  • Regular software updates
  • Secure cloud and backup solutions

POPIA compliance is closely tied to cybersecurity readiness.

3. Keeping Personal Information for Too Long

Many businesses collect customer information and then simply keep it indefinitely. This is another common POPIA issue.

Under POPIA, organisations should not retain personal information longer than necessary for the purpose it was collected.

However, businesses often store:

  • Old customer records
  • Outdated employee information
  • Unused marketing databases
  • Historical application forms

without proper retention policies.

The longer sensitive information is stored, the greater the risk of exposure during a breach.

Why over-retention is risky

Holding unnecessary data increases:

  • Cybersecurity risk
  • Storage costs
  • Compliance exposure
  • Potential liability during breaches

Businesses often underestimate how much personal data they actually possess.

What businesses should do

Organisations should:

  • Create formal data retention policies
  • Regularly delete unnecessary information
  • Archive records securely where legally required
  • Review stored information periodically

Good data management is a major part of POPIA compliance.

Why POPIA Compliance Matters More Than Ever

POPIA is not simply a legal formality, it reflects growing global concern around data privacy and digital security.

Customers increasingly expect businesses to:

  • Handle information responsibly
  • Communicate transparently
  • Protect sensitive data properly

Businesses that fail to adapt may face not only legal consequences, but also reputational damage that is far harder to recover from.

Compliance is becoming part of customer trust.

Final Thoughts

Many POPIA violations happen because businesses underestimate their responsibilities or treat compliance as a once-off checklist exercise. In reality, data protection requires ongoing attention, proper systems, and employee awareness.

The most common POPIA issues, poor consent practices, weak security, and excessive data retention, are often preventable with the right policies and training.

As digital business continues growing in South Africa, organisations that take privacy seriously will be in a far stronger position than those that ignore it.