Registering Your Information Officer with the Information Regulator
Of all POPIA’s duties, information officer registration is the simplest — and the most neglected. Thousands of small businesses are walking around with an unregistered information officer they do not know they have: the owner. This guide explains who the officer is, what the role actually carries, and how to register in one sitting.

- ✔The information officer exists automatically — it is the head of the business, no appointment needed.
- ✔Registration with the Information Regulator is free and done online.
- ✔The officer is personally accountable for the business’s POPIA compliance.
- ✔A deputy information officer can carry the daily workload — appoint in writing.
- ✔Registration details must be updated when the officer or business details change.
Who your information officer is — automatically
POPIA does not let you choose whether to have an information officer: the Act assigns the role to the head of the organisation — the CEO of a company, the sole proprietor, the managing member of a close corporation, the senior partner. No resolution or appointment letter creates the role (though documenting it is good practice); it exists because the Act says it exists. What requires action is the registration of that person with the Information Regulator.
A deputy information officer may be designated in writing to carry the operational load — the bookkeeper who handles payroll data, the office manager who runs HR files. Delegation moves the work, not the accountability: the information officer remains answerable for compliance.
What the information officer is responsible for
- Compliance framework: the business’s POPIA policies, privacy notices (employee privacy notice) and procedures.
- Operator agreements: written contracts with everyone processing personal information for you — payroll bureaus, HR platforms, IT providers.
- Security safeguards: appropriate technical and organisational measures, reviewed as the business changes.
- Data subject requests: access, correction and deletion requests answered within reasonable time.
- Breach response: notification to the Regulator and affected people (breach response guide).
- Staff awareness: making sure the people who touch personal information know the rules.
POPIA’s eight conditions start with accountability — and the information officer is where it lands. In a Regulator investigation, the first question is ‘who is your information officer and where is the registration?’
In practice, the small-business information officer’s year looks like this: register once, keep the privacy notice current as practices change, review operator agreements when providers change, refresh the retention-and-destruction round annually, and be the named person if an employee asks to see their file or the Regulator ever writes. It is a hat, not a job — but it must be a named hat, on a registered head.
Registering with the Information Regulator: the process
The whole exercise takes under half an hour. Pair it with the rest of the POPIA starter kit — privacy notice, retention schedule, operator agreements — and the compliance skeleton is in place. The full kit is mapped in the POPIA pillar guide.
Always confirm current requirements with the official source — rules and deadlines change.
- ✔Admin Boss handles registrations, filings and payroll admin
- ✔Registered tax practitioner · 20+ years experience
- ✔Fully remote — all 9 provinces
Frequently asked questions
Who is the information officer of a small company?
Automatically the head of the organisation — the CEO, owner or managing member. The role exists by law; what you must do is register that person with the Information Regulator and equip them to carry the duties.
Does information officer registration cost anything?
No — registration on the Information Regulator's online portal is free. It requires your business details and the officer's details, and should be updated when either changes.
Can the information officer be an employee?
The information officer is always the organisation's head by default. Daily duties can be delegated to a deputy information officer — often the office manager or bookkeeper — appointed in writing, but accountability stays with the head.
What happens if my information officer is not registered?
You are non-compliant with a basic POPIA duty, and it is the first gap any Regulator investigation finds. Registration takes under half an hour online — it is the cheapest compliance fix in the Act.
When did information officer registration become required?
POPIA has been fully enforceable since 1 July 2021, and the Information Regulator expects every responsible party — including small businesses — to be registered on its portal. If you have never registered, doing it now closes the gap.
Last reviewed: July 2026 · How we research our guides
EmployerGuide.online provides general information about South African employer obligations — not legal, tax or professional advice for your specific situation. Laws, rates and deadlines change; confirm current requirements with the official sources linked above, or ask Admin Boss. See our disclaimer.