The Protection of Personal Information Act has been fully in force since July 2021, and most small South African businesses have done very little about it — usually because the available guidance assumes a compliance function that a twenty-person company does not have. This is the technical side, in the order we would actually address it.
A necessary caveat: this covers the technical controls we implement. POPIA also imposes legal and procedural obligations, and for interpretation specific to your circumstances you should take advice from a qualified professional.
Start by knowing what you hold
You cannot protect information you have not located. Before any control, write down what personal information the business holds, where it lives, who can reach it, and why you have it. In practice this list is always longer than people expect — the CRM and the payroll system are obvious, but so are the shared drive, the WhatsApp group with customer addresses in it, the inbox holding eight years of ID copies, and the ex-employee's laptop in a cupboard.
The controls, in order of return
- Multi-factor authentication on email and every administrative account. Compromised credentials are the most common route to a personal-information breach, and this single control closes most of it.
- Remove access nobody needs. Former staff, former contractors, shared logins, and permissions granted for a project that ended two years ago. Access reviews are unglamorous and highly effective.
- Encrypt devices. Full-disk encryption on laptops and phones. A stolen encrypted laptop is an inconvenience; a stolen unencrypted one holding client records is a reportable incident.
- Fix backups. Personal information you cannot restore after ransomware is personal information you have failed to safeguard. Backups need to be offsite, isolated, and tested by actually restoring from them.
- Delete what you no longer need. POPIA requires you not to keep personal information longer than necessary. Old data you have deleted cannot be breached — this is the only control that reduces risk to zero.
- Write down who to call. If you are breached you may be required to notify the Information Regulator and affected people. Deciding who does that, during the incident, is how organisations get it wrong.
The one most people miss
Operators. If you send personal information to a third party who processes it on your behalf — payroll bureau, cloud provider, marketing agency, IT support company — POPIA expects a written arrangement covering how they secure it. That includes us, and any provider who is reluctant to sign something to that effect is telling you something useful.
What good enough looks like
POPIA asks for security safeguards appropriate to the harm that a breach would cause. A workshop holding customer names and phone numbers is not held to the same standard as a medical practice holding health records. The obligation is to think about it, act proportionately, and be able to show your reasoning. That last part matters: a documented, deliberate decision is defensible in a way that an accident is not.