Free

POPIA for Apps, SaaS and Software Products

You are already the Information Officer, your overseas hosting is a cross-border transfer, and every vendor touching user data needs a written contract. What actually applies when the personal information is the product.

12 min readUpdated 5 August 2026
Applies to:SaaS founders • App developers • Anyone storing user data

Most POPIA guidance is written for a company that keeps a customer list in a spreadsheet. If you are building an app, a SaaS product or a website that people log into, your position is different in one important way: the personal information is the product. It arrives continuously, it sits on infrastructure you rent from somebody else, and a good deal of that infrastructure is not in South Africa.

This guide covers the five things that actually catch software founders, in the order they catch them. None of it requires a lawyer to start.

You are already the Information Officer

For a private body, POPIA defines the information officer as the head of that body. It is not a role you appoint - it is one you hold, and must register.

Your hosting is a cross-border transfer

If your database sits in Frankfurt or Virginia, section 72 applies to you. Most founders have never read it.

Every vendor needs a written contract

Your host, your mailer, your analytics, your payment processor. Section 21 requires it in writing.

A breach has a reporting duty

You notify the Regulator and the affected users, as soon as reasonably possible after you discover it.

1. You are the Information Officer, and you have to register

POPIA does not ask a private company to appoint a data protection officer the way GDPR does. It defines the information officer of a private body as the head of that private body. If you are the founder of a one-person startup, that is you. If you run a company, it is the chief executive or equivalent. You already hold the role whether or not anyone has told you.

The part people miss is section 55(2): an information officer takes up their duties only after the responsible party has registered them with the Regulator. Registration is free and is done through the Regulator's online portal. It is the single cheapest compliance step available to a startup, and the most commonly skipped.

Do this one first
It costs nothing, takes under an hour, and it is the first thing an enterprise customer's procurement team asks you to evidence. If you do nothing else on this page this month, do this.
Information RegulatorRead the Information Officer guide

2. Your cloud hosting is a cross-border transfer

This is the section that applies to almost every software product built in South Africa and that almost no founder has read. Section 72 says a responsible party may not transfer personal information about a data subject to a third party in a foreign country unless one of five grounds is met.

Deploying to a region outside South Africa is such a transfer. So is a mailing list held by an overseas provider, an error-tracking service that captures user identifiers, an analytics product, and a support inbox hosted abroad. You do not escape section 72 by not thinking about it.

The five grounds in section 72(1)
  • (a) The recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection.
  • (b) The data subject consents to the transfer.
  • (c) The transfer is necessary for the performance of a contract between the data subject and you, or for pre-contractual measures taken at their request.
  • (d) The transfer is necessary for the conclusion or performance of a contract concluded in the data subject's interest between you and a third party.
  • (e) The transfer is for the data subject's benefit and it is not reasonably practicable to obtain their consent.

In practice most SaaS businesses rely on (a): the major cloud providers publish data processing addenda with standard contractual clauses, and signing that addendum is what puts a binding agreement in place. It is usually a checkbox in the account console rather than a negotiation. The failure is not that founders cannot meet the ground - it is that they never accepted the addendum and cannot show anything when asked.

Being accountable does not end at the border
You remain responsible for the personal information after it leaves the country. Choosing a foreign provider is allowed. Not knowing where your users' data physically sits is not a defence.

Write down every service that touches user data and the region it runs in - host, database, backups, mailer, analytics, error tracking, support desk, payment processorRequired

Write down every service that touches user data and the region it runs in - host, database, backups, mailer, analytics, error tracking, support desk, payment processor.

For each one, accept or sign the provider's data processing addendum and keep a copyRequired

For each one, accept or sign the provider's data processing addendum and keep a copy.

Say plainly in your privacy policy that data is processed outside South Africa, and on what basisRequired

Say plainly in your privacy policy that data is processed outside South Africa, and on what basis.

3. Every vendor that touches user data is an operator

POPIA calls a party who processes personal information on your behalf, under contract and not under your direct authority, an operator. Your hosting provider is an operator. So is your transactional email service, your analytics, your CRM, and the contractor who has production access on a Saturday.

Section 21 requires that this relationship be governed by a written contract requiring the operator to establish and maintain the security safeguards in section 19. For the large providers this contract already exists as a standard addendum. For the freelance developer with a copy of your database, it usually does not - and that is the gap that shows up in due diligence.

1

List your operators

Anyone who can read user data. Include contractors and agencies, not only SaaS vendors.

2

Get the standard addendum in place

For the big platforms this is a document you accept, not one you draft.

3

Paper the small ones

A short written agreement with a developer or agency covering confidentiality, security and deletion on termination is enough to close the obvious hole.

4

Remove access when it ends

Offboarding is part of security. Revoke keys and production access the day an engagement ends.

4. A breach carries a reporting duty, and the clock starts at discovery

Section 22 applies where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. You must notify the Regulator and the affected data subjects, as soon as reasonably possible after discovering the compromise. The only permitted delay is where law enforcement determines that notifying would impede a criminal investigation.

The notice must give enough information to act on, including:

A description of the possible consequences of the compromiseRequired

A description of the possible consequences of the compromise.

A description of the measures you intend to take or have takenRequired

A description of the measures you intend to take or have taken.

Recommendations on what the affected person can do to protect themselvesRequired

Recommendations on what the affected person can do to protect themselves.

The identity of the unauthorised person, if it is knownRequired

The identity of the unauthorised person, if it is known.

Write the template before you need it
Nobody drafts a clear breach notice at two in the morning. A one-page template and a named person to make the call turns a crisis into a procedure.

5. What actually happens if you get it wrong

There is a lot of loose talk about ten-million-rand fines. The accurate picture is a sequence, and knowing the sequence is more useful than knowing the maximum.

1

A complaint or a breach draws attention

The Regulator investigates and can assess whether a condition for lawful processing has been contravened.

2

An enforcement notice tells you what to fix

This is the practical stage. It sets out what must be done and by when. Complying ends the matter.

3

Ignoring the notice is an offence

This is where the penalties attach. Under section 109 the Regulator may serve an infringement notice where a responsible party is alleged to have committed an offence, with an administrative fine that may not exceed R10 million. You have 30 days to pay or to elect to be tried in court instead. Section 107 sets criminal penalties: a fine or imprisonment up to 10 years for the most serious offences, and up to 12 months for lesser ones.

What the first fine was actually for

The Regulator's first administrative fine - R5 million against the Department of Justice and Constitutional Development, issued on 3 July 2023 - was not for the underlying breach. It was for failing to comply with the enforcement notice that followed it, which had required proof that lapsed anti-virus, SIEM and intrusion-detection licences had been renewed. The department contested the fine.

The lesson for a small software business is not that the Regulator hands out eight-figure penalties. It is that the expensive outcome comes from ignoring correspondence, and the cheap outcome comes from answering it.

If you send marketing email from your product

Product email and marketing email are treated differently. A transactional message a user asked for - a password reset, a receipt, an alert they configured - is not direct marketing. A newsletter or a promotional campaign is, and electronic direct marketing has its own consent rules under POPIA.

Read the POPIA email marketing guide

A starting checklist

Register your information officer with the RegulatorRequired

Register your information officer with the Regulator.

List every service that touches user data, and the country it runs inRequired

List every service that touches user data, and the country it runs in.

Accept or sign each provider's data processing addendum, and keep copiesRequired

Accept or sign each provider's data processing addendum, and keep copies.

Put a short written agreement in place with contractors who can read production dataRequired

Put a short written agreement in place with contractors who can read production data.

Publish a privacy policy that says what you collect, why, and that data is processed abroadRequired

Publish a privacy policy that says what you collect, why, and that data is processed abroad.

Collect only the fields you actually useRequired

Every extra field is liability with no revenue attached.

Write the breach notification template now, and name who decidesRequired

Write the breach notification template now, and name who decides.

Revoke access the day someone stops working on the productRequired

Revoke access the day someone stops working on the product.

Common questions

Does POPIA apply to me if I only have a few users?

Yes. POPIA has no minimum size threshold. If you process personal information you are a responsible party. What changes with scale is how much is expected of you, not whether the Act applies.

Can I host outside South Africa?

Yes. There is no data localisation requirement in POPIA for ordinary personal information. What section 72 requires is that the transfer rests on one of its five grounds - most commonly a binding agreement with the provider giving an adequate level of protection.

Do I need to appoint an Information Officer?

For a private body the information officer is the head of that body, so the role already sits with you. What you do need to do is register with the Regulator, because an information officer takes up their duties only once the responsible party has registered them.

I am GDPR compliant. Am I POPIA compliant?

Largely, but not automatically. The two overlap heavily and work done for GDPR carries across. POPIA differs in specifics that matter - notably the registration of the information officer and its own cross-border transfer grounds - so treat GDPR work as a strong head start rather than a substitute.

What is the difference between a responsible party and an operator?

The responsible party decides why and how personal information is processed. That is you, for your product. An operator processes it on your behalf under a contract, without coming under your direct authority - your host, your mailer, your analytics. You stay accountable for what your operators do.

Where this fits

POPIA is one of several things that becomes real the moment your product has customers rather than users. If you are still deciding what to build, or costing the build itself, start with the other guides in this cluster.

POPIA compliance starterWhat an MVP actually costs to buildTech business ideas you can build in South Africa

Free check - about 3 minutes

Is your tech idea ready to build - and do you own what gets built?

For anyone building software: check whether you have evidence a customer wants this, whether the scope is decided enough to get an honest quote, whether the code and accounts are actually yours, and which POPIA obligations apply the moment you store a user's details.

Free, and you see your full result immediately. We ask for your name and an email or phone number so we can send you the scorecard.

Free check - about 3 minutes

Is your tech idea ready to build - and do you own what gets built?

For anyone building software: check whether you have evidence a customer wants this, whether the scope is decided enough to get an honest quote, whether the code and accounts are actually yours, and which POPIA obligations apply the moment you store a user's details.

Free, and you see your full result immediately. We ask for your name and an email or phone number so we can send you the scorecard.

Get compliance-ready without the runaround

Government is the biggest buyer in South Africa. These are free to browse.