14 August 2026 · 6 min read
POPIA and WhatsApp Business: A Practical Guide for South African SMEs
If your business runs on WhatsApp, POPIA applies to you. The Protection of Personal Information Act covers every South African business that processes personal information, and a WhatsApp chat with a customer is exactly that: names, numbers, addresses, photos of their kitchen, sometimes payment details.
The good news is that complying is mostly a matter of doing ordinary things deliberately. This guide covers what the Act expects from a small service business on WhatsApp, in plain terms. It is practical guidance, not legal advice; for edge cases, speak to a professional.
What POPIA actually regulates
POPIA sets conditions for how you handle personal information: collect it for a clear purpose, use it for that purpose, keep it accurate and secure, do not keep it forever, and respect the rights of the person it belongs to. The Information Regulator enforces the Act and handles complaints.
For a WhatsApp-first business, "personal information" includes at least your customers' names and numbers, chat history, addresses for callouts, and any documents or photos they send you. If you use software to manage those chats, that software is processing personal information on your behalf, and you are responsible for choosing a provider that handles it properly.
The eight conditions, translated for a WhatsApp business
POPIA structures its requirements as eight conditions for lawful processing. Here is what each one looks like when your business runs in a chat:
- Accountability. Someone in the business owns compliance. In a small business that is usually the owner, formally called the Information Officer, and registration with the Information Regulator's portal is part of the housekeeping.
- Processing limitation. Collect what you need for the job and no more. A callout needs an address; it does not need an ID number.
- Purpose specification. Use the information for the reason you collected it. A number given for a quote is not automatically a marketing list entry.
- Further processing limitation. New uses need to be compatible with the original purpose, or need fresh consent.
- Information quality. Keep records accurate. A CRM that updates the contact from the conversation beats a contacts app full of stale entries.
- Openness. Tell people what you do with their information. A short privacy notice linked from your profile or website covers this.
- Security safeguards. Reasonable technical and organisational measures: encryption, access control, and a provider you have actually vetted.
- Data subject participation. People can ask what you hold, have it corrected, or have it deleted, and you respond properly.
None of this requires a compliance department. It requires tidy habits and software that makes the tidy habit the default.
Everyday chats: mostly common sense
Answering an enquiry, booking a job, sending a quote and invoicing the work are all processing with an obvious lawful basis: the customer asked you to do it. POPIA does not require a consent form before you reply to "how much for a callout?".
Where small businesses slip up is the informal stuff around the chat:
- Forwarding a customer's message or photos to a group chat that includes people who do not need it.
- Keeping years of chat history on a personal phone that is not backed up, secured or ever cleaned up.
- Sharing a customer's number with another business without asking them.
The habit that fixes most of this is keeping customer information in one controlled place rather than scattered across staff phones. A shared system with logins beats seven personal WhatsApp accounts, both for POPIA and for running the business.
Direct marketing: the strict part
Section 69 of POPIA is the part most likely to bite. Electronic direct marketing, which includes WhatsApp broadcasts, is opt-in:
- You may market to a person who gave you consent.
- You may market to an existing customer, but only for similar products or services, only if you collected their details in the course of a sale, and only if you gave them a chance to opt out at collection and in every message after.
- Every marketing message must identify who it is from and offer an opt-out.
Meta's WhatsApp Business Platform policies point the same way: opt-in is required, opt-outs must be honoured, and numbers that generate spam reports get restricted or banned. So the compliant path and the path that protects your WhatsApp number are the same path.
Practical rule: keep an opt-in list, record when and how each person opted in, and never broadcast to a list you bought or scraped. If your broadcast tool does not handle opt-outs automatically, treat that as disqualifying.
Storing chats and customer records
POPIA expects reasonable security and a retention discipline. For a WhatsApp business that means:
- Access control. Staff see what their role needs. A leaving employee should lose access to customer chats the day they leave, which is impossible if the chats live on their personal phone.
- Encryption and hosting. Ask where your CRM stores data and whether it is encrypted. Lunchbox stores customer data encrypted, does not sell it, and documents its providers in its privacy policy.
- Retention. Keep records as long as you have a business or legal reason, such as SARS requirements for invoices, and delete what you no longer need.
- Requests. Customers may ask what you hold about them, ask you to correct it, or ask you to delete it. Have a simple way to answer, and document your response.
What happens if you get it wrong
The Information Regulator can investigate complaints, issue enforcement notices and, for serious offences, impose administrative fines that run into millions of rand. For a small business, though, the realistic risks arrive earlier and smaller: a customer complaint that costs you a relationship, a staff member walking out with your customer list on their personal phone, or Meta restricting your WhatsApp number because broadcast recipients reported spam.
That last one deserves emphasis. Your WhatsApp number is business infrastructure. The behaviours POPIA requires, opt-in lists and honoured opt-outs, are the same behaviours that keep your number in good standing with Meta. Cutting corners risks the channel your whole business runs on, which is a far more immediate penalty than any regulator.
A practical POPIA checklist for WhatsApp businesses
- Use the official WhatsApp Business API (or app), never grey-market bulk senders.
- Keep customer records in one secured system, not on personal phones.
- Broadcast only to opted-in contacts, with an opt-out in every message.
- Write down what you collect and why; put it in a short privacy notice.
- Have one person responsible for handling data requests and complaints.
- Choose software that does the above by default rather than by discipline.
When you evaluate that software, ask the vendor three direct questions: where is the data hosted and is it encrypted, can you delete a contact and their history completely when asked, and does the broadcast feature enforce opt-outs automatically? A vendor who answers those crisply has thought about POPIA; a vendor who waffles is outsourcing the risk to you.
Get started with Lunchbox
Lunchbox is built for exactly this setup: a South African service business that lives on WhatsApp and wants the admin, and the compliance, handled. Customer data is stored encrypted and never sold, broadcasts are opt-in with automatic opt-outs, and every conversation lives in one shared, access-controlled inbox instead of on someone's personal phone. Pricing starts at R997 per month with no setup fees and no long contracts.
Start a 14-day trial at lunchbox-crm.com today. Connect your WhatsApp number in minutes and let the agent handle your next enquiry while you focus on the work itself.
Frequently asked questions
Is it legal to run my business on WhatsApp under POPIA?
Yes. POPIA does not prohibit any particular channel. It regulates how you collect, use, store and share personal information, whichever channel you use. A business that handles customer information responsibly on WhatsApp is in a better position than one that handles it carelessly by email.
Do I need consent to message a customer on WhatsApp?
For ordinary service communication with an existing customer, such as confirming a booking or sending an invoice they asked for, you are processing their information to perform a contract, which POPIA permits. Direct marketing by electronic message is stricter: you need the person's consent, or an existing customer relationship, and every marketing message must offer a way to opt out.
Can I send WhatsApp broadcast marketing under POPIA?
Yes, to people who have opted in. Section 69 of POPIA treats electronic direct marketing as opt-in, and Meta's own rules for the WhatsApp Business Platform require opt-in and honoured opt-outs as well. Broadcast tools built on the official API, like Lunchbox, enforce the opt-out on every send.
What should I do if a customer asks me to delete their information?
Treat the request seriously, act on it, and document what you did. Delete the contact record and conversation history unless another law requires you to keep specific records, such as invoices for SARS. Tell the customer what you deleted and what you must retain and why.
Does POPIA apply to a one-person business?
Yes. POPIA applies to anyone processing personal information in the course of business, regardless of size. The practical burden scales with your operation, though: for a solo operator, a secure system for customer records, opt-in broadcasts and a willingness to honour deletion requests cover most of the ground.