SA SMBs on PayFast face POPIA Regulator, SARB payment rules, PCI-DSS v4.0, SARS 15% VAT, NCA, FICA. Real 2026 SA payment gateway stack.
A South African SMB evaluating any payment-gateway vendor is answering five questions, not one, and general 'best payment gateway' comparisons address only the fifth. First: does the tool support POPIA (Protection of Personal Information Act 4 of 2013) compliance — registration of the Information Officer with the Information Regulator, lawful basis for processing personal information under §11, data subject rights (access, correction, deletion) under Chapter 3, cross-border transfer restrictions under §72 requiring adequate-protection assessment or data subject consent for transfers, breach notification to the Information Regulator and affected data subjects under §22 without unreasonable delay, plus §107 administrative fines up to R10,000,000 (approximately US$530,000 at exchange rate ~19 ZAR/USD 2026) or 10 years' imprisonment for the most serious violations? Second: does the gateway operate under South African Reserve Bank (SARB) authorisation for payment-system operation — the National Payment System Act 78 of 1998 plus SARB Payment System Directives establish that payment aggregators processing card and EFT transactions must be authorised by SARB or operate through a SARB-authorised system operator (the merchant typically does not require SARB authorisation directly but must contract with a SARB-authorised aggregator)? Third: does the gateway support PCI-DSS v4.0 obligations for the merchant's card acceptance — Self-Assessment Questionnaire (SAQ) appropriate to volume for small merchants, full audit for larger, plus contractual pass-through requirements from the acquirer? Fourth: does the gateway integrate with SARS 15% VAT obligations — VAT registration is mandatory for merchants with annual turnover above R1,000,000 (approximately US$53,000), voluntary registration between R50,000 and R1,000,000, monthly VAT filing for larger and bi-monthly for smaller, with tax invoice format specified under the Value-Added Tax Act 89 of 1991? Fifth: does the gateway support the general merchant-integration workflow — checkout flow, EFT support, mobile payment, subscription handling — that any SA SMB may need? A purely feature-driven comparison answers only the fifth. The exposure is measured in Information Regulator administrative fines (up to R10,000,000) and criminal enforcement, SARB action against unauthorised payment operation, PCI-DSS breach exposure with acquirer fine pass-through, SARS back-tax plus 10-200% penalty under Tax Administration Act 28 of 2011, and NCA / FICA enforcement action.
PayFast's positioning describes a South African-market online payment gateway supporting credit-card, EFT (Electronic Funds Transfer), Instant EFT (with Ozow-adjacent competitor SiD SecureEFT), Zapper, SnapScan, Masterpass, Samsung Pay, RCS (Retail Credit Solutions), and cryptocurrency for South African merchants, headquartered in Cape Town and part of the Network International group after 2022 acquisition. Per-transaction fees are typically around 3.5% + R2 for credit card with volume-tier discounts and different rate cards for EFT and mobile-payment methods (verify current at payfast.io/fees). Founded in 2007, PayFast is one of the longest-established online payment gateways for the South African market. The target customer profile is South African e-commerce and SMB operators wanting a single gateway covering the range of South African payment methods including Instant EFT (which remains a meaningful share of South African online payment volume alongside card). PayFast is a legitimate and capable SA payment gateway. What it is not: a global-market gateway with cross-border-native pricing (SA-first with limited cross-border-native support); an all-in-one POS-plus-online-plus-inventory system (that would be Yoco or iKhokha); a pure Instant EFT specialist (Ozow's core positioning); a developer-first API-only gateway (Stitch's positioning); a subscription-billing specialist (that would be a Chargebee / Recurly plus PayFast setup). The PayFast alternative decision is contextual — it depends on which of these gaps the SMB is trying to close.
South Africa's Protection of Personal Information Act 4 of 2013 (POPIA) took full effect on 1 July 2020 with the one-year grace period ending 30 June 2021, and enforcement by the Information Regulator has been active since then. Key requirements applicable to any South African SMB accepting payments and thus processing personal information: registration of the Information Officer (typically the CEO or designated officer) with the Information Regulator using the online eServices portal; lawful basis for processing personal information under §11 (consent, contract, obligation, protection of legitimate interest of data subject, obligation of law, public interest, legitimate interests of responsible party); data subject rights under Chapter 3 including access (§23), correction (§24), and deletion (§24); cross-border transfer restrictions under §72 requiring adequate-protection assessment for the recipient country, contractual protection, or data subject consent for transfers outside South Africa; breach notification under §22 requiring notification to the Information Regulator and to affected data subjects 'as soon as reasonably possible' after the responsible party has reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person; §107 administrative fines up to R10,000,000 (approximately US$530,000) or imprisonment up to 10 years for the most serious offences (verify current amounts with Information Regulator). Direct marketing under §69 requires consent for direct marketing to data subjects with whom the responsible party has no prior relationship, with specific consent-format requirements. A payment gateway is a data processor for the merchant under §21 — the merchant remains responsible and must maintain the responsible party posture including a written processing agreement with the gateway.
The South African Reserve Bank (SARB) regulates the National Payment System under the National Payment System Act 78 of 1998 plus continuing SARB Payment System Directives. For a South African SMB accepting card, EFT, or Instant EFT payments, the practical implications are: the payment aggregator (PayFast, Peach Payments, Ozow, Yoco, PayGate, Netcash, iVeri, Stitch, Adumo, PayU) must be authorised by SARB or operate through a SARB-authorised system operator; the merchant typically does not require direct SARB authorisation but must contract with a SARB-authorised aggregator to ensure lawful payment operation; the aggregator handles interchange with the four major SA banks (Standard Bank, FNB, Nedbank, Absa) plus Capitec, Investec, and Discovery Bank; SARB rules on merchant service charges, chargeback handling, and disputes framework apply through the aggregator's terms; unauthorised payment operation exposes the merchant to SARB regulatory action plus criminal exposure under the National Payment System Act. The Payment Association of South Africa (PASA) is the industry body for payment system participants and publishes market conduct guidelines. SARB's ongoing modernisation programme (SAMOS system, Rapid Payments Programme with PayShap launching in 2023) continues to reshape SA payment infrastructure — verify current authorisation and directive status with SARB before contracting.
Beyond POPIA and SARB, several other SA regulatory frameworks apply. PCI-DSS v4.0 (Payment Card Industry Data Security Standard, current standard) applies to any merchant accepting card payments, with Self-Assessment Questionnaire (SAQ) requirements calibrated to the merchant's card-transaction volume — SAQ A for merchants outsourcing all card handling to a PCI-DSS-compliant service provider, SAQ B for imprint-only or terminal-only, SAQ C for merchants with payment processing on their systems, SAQ D for merchants with card data storage. Level 4 merchants (<20,000 e-commerce transactions per year) typically complete SAQ A or SAQ A-EP; Level 1 (>6 million card transactions per year) require full audit by a Qualified Security Assessor. The South African Revenue Service (SARS) enforces 15% VAT under the Value-Added Tax Act 89 of 1991 with mandatory registration for merchants above R1,000,000 annual turnover and voluntary registration between R50,000 and R1,000,000; monthly filing for turnover above R30,000,000, bi-monthly for smaller; tax invoice format specified under §20. Non-compliance under Tax Administration Act 28 of 2011 exposes to back-tax plus 10-200% administrative penalty depending on violation severity. The National Credit Act 34 of 2005 (NCA) applies to any credit-adjacent product (buy-now-pay-later at scale, in-store credit, layby exceeding certain thresholds), with National Credit Regulator (NCR) enforcement and mandatory NCA registration for credit providers. FICA (Financial Intelligence Centre Act 38 of 2001) imposes know-your-customer, transaction monitoring, and reporting obligations on accountable institutions listed in Schedule 1 (banks, payment aggregators, some other categories), with the Financial Intelligence Centre (FIC) enforcement.
The South African payment gateway category ships eight to twelve credible SARB-authorised aggregator choices depending on merchant size, sector, and payment-method mix. Broad market aggregators: Peach Payments (broad merchant coverage, developer-friendly, part of PayFast-adjacent competitor set), Ozow (Instant EFT specialist, growing card and payment-methods coverage), Yoco (POS-plus-online, popular SMB with hardware terminal), PayGate (broad, part of Network International group with PayFast), Netcash (broader payment aggregator plus merchant services), iVeri (older enterprise-oriented from Nedbank / Standard Bank ecosystem), Stitch (developer-first API-only for embedded payments), Adumo (broad merchant services), PayU (Naspers/Prosus subsidiary, broad merchant coverage, cross-border capable). QR and mobile-payment: SnapScan (Standard Bank-backed QR, popular for cafés and small merchants), Zapper (QR payment, cross-industry), Masterpass (Mastercard mobile wallet). POS-focused: Yoco (broadest SMB POS with card reader), iKhokha (SMB POS with card reader), Kazang (informal merchant terminal, ex-Cash-based). Bank direct: Standard Bank Business Now, FNB Business Now, Nedbank Business Central, Absa CIB. Cross-border-capable: PayU, Peach Payments, Adumo, plus international aggregators (Stripe entered SA 2024, Adyen for larger merchants). A defensible small SA online SMB stack is Yoco or Peach Payments or PayFast plus a POPIA-compliant data-processing posture. A defensible SMB with QR / in-person + online is Yoco / iKhokha for POS plus Peach Payments or PayFast for online. A defensible larger SA e-commerce operator is Peach Payments or PayU or Adyen for card plus Ozow or SiD for Instant EFT plus PCI-DSS SAQ D or full audit.
The critique above does not deprecate PayFast — it is a legitimate and capable South African payment gateway with 15+ years of market history and broad payment-method coverage. PayFast fits well when: the SMB wants a single gateway covering the range of South African payment methods including Instant EFT (which is a meaningful share of South African online volume alongside card); the SMB prefers a well-established Cape Town-based provider with local support and account management; the merchant-integration effort should be minimal (PayFast plug-ins exist for WooCommerce, Shopify, WordPress, Magento, and other common e-commerce platforms); the SMB accepts a standard-tier per-transaction fee (around 3.5% + R2 for credit card, verify current) and does not need custom pricing available at higher volume through direct acquirer relationships; the SMB does not need cross-border-native processing (SA-first orientation). The PayFast alternative decision is contextual to a specific gap — Instant EFT specialisation pushes toward Ozow; POS-plus-online integration pushes toward Yoco; developer-first API-only pushes toward Stitch; enterprise-scale custom pricing pushes toward Peach Payments, PayU, or direct acquirer relationships with Standard Bank, FNB, Nedbank, or Absa; cross-border volume pushes toward PayU, Stripe (SA-launched 2024), or Adyen for large-enterprise scale.
For a South African SMB in 2026, a defensible payment stack has five layers. Primary payment aggregator: PayFast, Peach Payments, Ozow, Yoco, PayGate, Netcash, iVeri, Stitch, Adumo, or PayU depending on payment-method-mix and merchant size, all SARB-authorised, with the merchant contracting under a written service agreement that reflects POPIA data-processor terms. Alternative payment methods: QR-and-mobile through SnapScan, Zapper, or Masterpass for in-person or QR-based flows; Instant EFT through Ozow or SiD SecureEFT for the meaningful SA Instant EFT market share; card processing through the primary aggregator plus fallback. POPIA compliance: Information Officer registered with the Information Regulator, written processing agreement with every payment aggregator under §21, data-processing register maintained, cross-border transfer assessment for personal information leaving SA, breach notification workflow tied to §22 'as soon as reasonably possible' standard. PCI-DSS v4.0 posture: Self-Assessment Questionnaire (SAQ) appropriate to volume (SAQ A for small e-commerce outsourcing all card handling; SAQ D or full audit for larger), quarterly network scans where required, PCI-DSS obligations documented. SARS VAT and FICA compliance: VAT registration for merchants above R1,000,000 turnover (voluntary between R50,000-R1,000,000), monthly or bi-monthly VAT filing per Value-Added Tax Act 89 of 1991, tax invoice format compliant with §20, FICA know-your-customer where accountable-institution obligations apply, NCA registration for credit-adjacent products. This stack is not the simplest possible; it is the honest one for a South African SMB in 2026.
Data + numbers referenced in this article are sourced from these public documents:
BossBot is exploring African-market integration paths. For confirmed South African payment fit today — SARB-authorised aggregator, POPIA data-processor terms, PCI-DSS SAQ, SARS 15% VAT tax invoice — work with a SA-authorised aggregator plus locally-documented POPIA posture.
See BossBot's African-market pathNot ready to sign up yet? Try the free demo →