Automation
A POPIA-Aware Checklist for Small-Business Automation
A practical checklist for the personal-information questions worth asking before you automate a workflow in South Africa, from data minimisation to when to get legal advice.
Jacque Swanepoel
·

Someone with the authority to make the call has reviewed the above.
When to get legal or security advice
If you’re mapping out an automation project and want the process side worked through properly, . We’ll help you identify what the workflow should and shouldn’t touch, though the compliance sign-off itself should still come from your own legal advisor.
Last verified: 5 September 2026
No software makes a business POPIA compliant. Compliance is a fact-specific legal assessment of what your business actually does with people’s information, not a checkbox a tool can tick for you. What follows is a practical checklist for the questions worth asking before you automate a process that touches personal information. It is not a substitute for advice from a qualified professional.
It’s a live area right now. POPIA’s regulations were amended with effect from April 2025, tightening consent requirements for direct marketing and expanding how complaints can be raised. The Information Regulator has been actively enforcing, including fines running into the millions of rand against organisations that didn’t respond to enforcement notices, and has named direct marketing and data breach handling as priority areas. None of that is a reason to panic. It’s a reason to actually work through the list below before you build, rather than after something goes wrong.
What personal information enters the workflow
Start by listing it, field by field. A lead-routing workflow might touch a name, an email, a phone number, a business name, and whatever the person typed into a message box. An onboarding workflow might touch considerably more. Write the actual list down: you can’t limit or protect what you haven’t identified.
The business purpose for each field
For every field on that list, ask what it’s actually for. “We might need it later” is not a purpose. If a field doesn’t have a clear, current reason to exist in the workflow, that’s a strong signal to drop it rather than collect it “just in case.”
The responsible party and operators involved
Under POPIA, your business is generally the responsible party for information it collects from its own customers and leads. Any third-party tool in the workflow (the automation platform, the CRM, the email service) is typically acting as an operator on your behalf, processing information under your instruction. That relationship needs to be reflected in your supplier agreements, not just assumed because a tool looks trustworthy.
Access and permission design
Decide, deliberately, who can see the personal information the workflow handles, not just who happens to have a login. This includes the people on your team, but also the automation platform’s own access model: which team members can open the workflow, view its execution logs (which often contain the actual data that passed through), or export data from the connected tools.
Data minimisation
This is the operating principle behind most of the checklist items above: collect the minimum information needed for the stated purpose, and nothing extra “in case it’s useful.” A smaller footprint of personal information is both a cleaner design and a smaller thing to have to defend if anyone ever asks what you’re holding and why.
Retention and deletion
Decide, before you launch, how long each type of information is kept and what happens after that. An enquiry that never became a client, a completed project’s records, and analytics data all have different practical retention needs. Pick periods you can actually justify and actually enforce, and build the deletion step into the workflow rather than leaving it as a manual task nobody gets to.
International service providers and transfers
Many automation tools, CRMs, and email platforms process data outside South Africa. That’s not automatically a problem, but it’s a question that needs an actual answer: which providers in your stack process information internationally, and what safeguards or legal basis apply to that transfer. This is one of the areas the Information Regulator has flagged as needing clearer guidance, which makes it worth revisiting as that guidance develops rather than treating it as settled.
Security compromise handling
Know, in advance, what happens if something goes wrong: a tool is compromised, a workflow misfires and exposes data it shouldn’t have, an account is breached. Recent regulatory changes have moved breach reporting onto a formal e-portal process, replacing informal notification. Have a plan for who gets told, how fast, and through what channel, before you need one.
Direct marketing and consent
If any part of the automation sends marketing communications, not just transactional confirmations, but genuine marketing, treat consent as its own deliberate step, not an assumption baked into a signup form. This is one of the two areas regulators have specifically named as a current enforcement priority, and the rules around it have recently tightened rather than loosened.
Human review for sensitive decisions
Automation is good at moving information and enforcing consistent rules. It’s a poor fit for decisions that affect someone meaningfully and depend on judgement, whether that’s assessing an application, handling a complaint, or anything where the “why” behind a decision matters. Keep a person genuinely in the loop for those, rather than automating past the point where judgement is actually required.
Documentation and supplier questions
Keep a simple written record of what the workflow does: what information it touches, why, where it’s stored, who can access it, and what your suppliers (the automation tool, the CRM, the email platform) have committed to in their own terms. This document is what you’d actually produce if a client, or a regulator, asked how a specific piece of information was handled.
Launch checklist
Before switching a data-handling workflow on, confirm:
Every field collected has a stated purpose.
Access is limited to the people who need it.
A retention and deletion plan exists and is actually enforced, not just written down.
International providers in the stack are known and accounted for.
A breach-response plan exists before you need one.
Marketing consent, if applicable, is genuinely separate from transactional communication.
Someone with the authority to make the call has reviewed the above.
When to get legal or security advice
Get advice before launch, not after: when the workflow touches sensitive categories of information, operates at meaningful scale, or when you’re genuinely unsure how a rule applies to your specific situation. A short conversation with a qualified professional before you build is cheaper than fixing a workflow, or responding to a regulator, after the fact. This article is a starting checklist, not that advice.
If you’re mapping out an automation project and want the process side worked through properly, explore business automation or book a free strategy call. We’ll help you identify what the workflow should and shouldn’t touch, though the compliance sign-off itself should still come from your own legal advisor.
Have a similar problem in your business?
Book a free strategy call to discuss what is slowing your business down.