Municipal Tenders and POPIA Compliance: What the NDZ Opening-Closing Register 2026-2027 Means for SA Businesses
Miss a compliance requirement and the municipality hands the contract to someone else
The Dr. Nkosazana Dlamini Zuma (NDZ) Municipality has published its Opening-Closing Register for 2026-2027, and the list includes something every South African SME that supplies to government should pay close attention to: a formal tender for a POPIA Compliance Assessment. The fact that a municipality is now procuring this service tells you exactly where the regulatory bar is moving. If the municipality itself is under pressure to comply with the Protection of Personal Information Act, so are you — especially if you handle any municipal, employee, or customer data as part of a government contract.
This is not a theoretical risk. Government supply chain management (SCM) processes in South Africa require suppliers to be compliant across multiple dimensions before a bid is accepted. Your Tax Compliance Status, CIPC standing, and increasingly your data protection posture all feed into whether you walk away with a contract or not.
What the NDZ Opening-Closing Register 2026-2027 actually contains
The register published on the NDZ Municipality website lists 18 procurement items open for the 2026-2027 financial year. These range from infrastructure and equipment to professional services. Among the most significant for compliance-aware businesses are:
- Item 1: Supply, installation, configuration and commissioning of an Active Directory Auditing Solution — directly linked to IT governance and data security.
- Item 2: Appointment of a service provider to conduct a POPIA Compliance Assessment and develop a Protection of Personal Information framework.
- Item 3: Supply, configure and activate additional Microsoft 365 Business Standard licences.
- Item 4: Electrical Engineering Consultant to provide Professional Engineering Services.
- Items 5–18: Cover a broad range of municipal needs including water tanks, fencing, protective clothing, kitchen equipment, community asset renovation, and an Energy Performance Certificate for a municipal building.
Each of these represents a real procurement opportunity for a qualifying South African SME. But qualifying means more than having the product or skill. It means being clean on the documents that SCM officials will check before your bid goes any further.
Why POPIA compliance is now a supplier issue, not just a corporate one
The NDZ Municipality is procuring a POPIA Compliance Assessment for itself. That single line item signals a broader shift in how South African public entities are approaching data protection obligations under the Protection of Personal Information Act 4 of 2013, which became fully enforceable from 1 July 2021.
The Information Regulator has the power to issue fines of up to R10 million and recommend criminal prosecution resulting in up to 10 years' imprisonment for serious violations. Municipalities and government entities that handle personal data — including supplier information, employee records, and citizen data — are directly exposed. When they procure POPIA compliance services, they are also, implicitly, signalling that their suppliers should be equally compliant.
If your business processes personal information on behalf of a municipality — whether you're providing IT services, HR support, engineering consulting, or even delivering goods that require capturing contact details — you may be classified as an operator under POPIA. Operators carry direct legal obligations and can be held liable for breaches. Winning a government contract without a basic data protection policy in place is increasingly a liability, not just an oversight.
The SCM compliance checklist that determines whether your bid survives
Before any South African municipality accepts a bid, the SCM unit runs through a compliance checklist. Failing any single item can result in disqualification — even if your price is the lowest and your product is the best. The standard requirements include:
A valid Tax Compliance Status (TCS) PIN issued by SARS. This is non-negotiable. SARS issues this through eFiling, and it reflects whether your company is up to date on VAT, PAYE, income tax, and provisional tax. An expired or invalid TCS PIN means your bid is disqualified at the administrative compliance stage — before anyone even looks at your price.
A valid CIPC registration with a company in good standing. Annual returns must be up to date. If your company is in deregistration, your bid is invalid.
Beneficial Ownership declarations where applicable, particularly for contracts above certain thresholds where the municipality needs to know who ultimately controls the bidding entity.
B-BBEE status, which affects how your bid is scored under the Preferential Procurement Regulations. A Level 1 contributor scores 20 preference points on an 80/20 bid; a non-compliant entity scores zero.
And increasingly, for technology and data-related tenders, evidence of POPIA compliance measures — policies, appointed Information Officers, and documented data processing agreements.
The VAT registration trap that catches growing SMEs
Here is where many South African businesses trip up specifically on tax compliance. If your business has crossed the R1 million compulsory VAT registration threshold — meaning your taxable turnover over any 12-month period has exceeded R1 million — you are legally required to register for VAT with SARS. Failure to register means you are trading illegally and accumulating a VAT liability you don't even know you owe.
The penalties are real. SARS can impose a 10% penalty on the VAT you should have collected and remitted, plus interest calculated at the prescribed rate (currently linked to the repo rate). For a business that crossed the threshold a year ago without registering, that could represent tens of thousands of rands in exposure before you've submitted a single return.
Voluntary registration is also possible from R50,000 in taxable supplies over 12 months — and for government suppliers, being VAT-registered often matters because municipalities process invoices differently for VAT vendors versus non-vendors. If you're billing a municipality and you're not VAT-registered when you should be, you have a problem on both sides of the transaction.
You can check your own VAT registration status and Tax Compliance Status directly on SARS eFiling. If you are unsure whether your turnover has crossed the threshold, or whether your current VAT returns are correctly filed, do not guess. Speak to a registered tax practitioner before you submit your next government bid.
What to do now if you plan to bid on NDZ or any municipal tenders in 2026-2027
The NDZ tender register for 2026-2027 is open now. Procurement windows close — often faster than SMEs expect. Here is a specific sequence to work through before you submit anything:
Step 1: Verify your CIPC standing. Check that your company's annual returns are up to date and that your status is not flagged for deregistration. If your Beneficial Ownership filing is outstanding, address it immediately — this is now a hard requirement under the General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act.
Step 2: Pull your Tax Compliance Status on SARS eFiling. Log in, navigate to the Tax Compliance Status section, and request a TCS PIN. If your status is not green, find out why before a municipality's SCM office finds out first. Common blockers include outstanding returns, unfiled provisional tax, and unresolved VAT audits.
Step 3: Confirm your VAT position. If your turnover is approaching or has exceeded R1 million, get formal advice on registration. If you are already registered, confirm that your returns are current and that you have no outstanding amounts due. For specific guidance on VAT thresholds and obligations, visit ClearComply's VAT help page.
Step 4: Appoint an Information Officer under POPIA. Every South African business that processes personal information must have a designated Information Officer registered with the Information Regulator. This is not optional. If you are bidding on the NDZ POPIA Assessment tender or any IT-related tender, the absence of an Information Officer registration is an obvious credibility gap.
Step 5: Document your data processing activities. A basic Record of Processing Activities (ROPA) is required under POPIA. For most SMEs, this is a straightforward document — but it must exist. If you don't have one, a POPIA specialist can produce a basic version relatively quickly.
Get connected to the right specialist before your next bid deadline
ClearComply does not file your tax returns, manage your SARS account, or conduct POPIA assessments. What we do is connect South African SMEs with the right accountants, tax practitioners, and compliance specialists — quickly, without the usual back-and-forth of finding someone credible on your own.
If you are looking at the NDZ 2026-2027 tender register and realising your compliance house is not fully in order, tell us what you need. We will connect you with a registered professional who can sort your Tax Compliance Status, VAT position, or POPIA readiness before your next deadline hits. The cost of getting it wrong — a disqualified bid, a SARS penalty, or an Information Regulator investigation — is significantly higher than a conversation with the right person now.