POPIA - the Protection of Personal Information Act - applies to every South African business that collects personal information, and a cannabis store collects more of it than most retail. ID numbers for age verification, delivery addresses, phone numbers, purchase history tied to loyalty accounts. None of that is unique to cannabis, but the volume and sensitivity of it is higher than a shop selling t-shirts.
This isn't legal advice - if you need a definitive read on your specific setup, that's a conversation with a lawyer, not a blog post. What follows is the operational shape of POPIA: the parts that actually change how a store runs day to day.
What POPIA actually asks for
- Collect only what you need. If a sale doesn't require an ID number, don't store one just in case.
- Say what you're collecting it for, and don't quietly use it for something else later.
- Keep it secure - which for a POS system means access controls, not just a password on the front door.
- Let people ask what you hold on them, and correct or delete it on request.
- Don't keep it forever. Data with no current purpose is a liability sitting on a hard drive, not an asset.
Where cannabis retail adds risk
Age verification means ID documents pass through the till at every sale. If that information sits in a spreadsheet on a shared computer, or in a notebook behind the counter, it's collected but not protected - which is the exact gap POPIA is aimed at. The fix isn't complicated: role-based access (a cashier doesn't need admin's view of customer records), and a system that logs who looked at what, rather than a shared login everyone uses.
Consignment and vendor relationships add a second layer: licence numbers, banking details for payouts, and business information that also counts as personal information under POPIA if it's tied to an individual rather than a registered company. Worth checking which of your vendor records fall into that category.
What to actually check
- Who on your team can see full ID numbers, and does that access match their actual job
- Where customer data lives - one system, or scattered across a POS, a spreadsheet, and a notebook
- Whether you have a written answer for "what happens to my data if I ask you to delete it"
- Whether your POS logs access, or whether every login sees the same thing
Budstack is built with these principles in mind - role-based access by design, and customer data that lives in one system rather than scattered across tools. That's a starting point, not a substitute for your own compliance review.
Related reading
See how Budstack handles this
Fifteen minutes, a walkthrough of the platform, and a number scoped to the stores you actually run.