Compliance

POPIA, read as infrastructure.

The Protection of Personal Information Act says you must take "appropriate, reasonable technical and organisational measures" — and then declines to say what those are. This page answers that from the server side.

What POPIA is

POPIA is the Protection of Personal Information Act, Act 4 of 2013 — South Africa's data protection law, overseen by the Information Regulator. It governs how any public or private body collects, stores, uses and shares personal information, and it applies regardless of organisation size. There is no small-business exemption from the security obligations.

Most POPIA material online is written by law firms or by compliance software vendors, and it is good at telling you what the Act says. It is generally silent on what any of it means for a firewall ruleset, a patch cadence or a backup schedule — which is the part that actually gets built, and the part that fails an audit.

The eight conditions, briefly

POPIA sets eight conditions for lawful processing. Seven of them are largely governance and policy work. One is engineering:

Accountability
Someone is answerable for compliance — in practice, the appointed Information Officer.
Processing limitation
Collect lawfully, minimally, and with a justification for each field you hold.
Purpose specification
Collect for a defined purpose, and do not keep records longer than that purpose needs.
Further processing limitation
Do not quietly reuse data for something the person never agreed to.
Information quality
Keep it accurate, complete and up to date.
Openness
Document what you process, and tell people you are processing it.
Security safeguards
Section 19 — the condition this page is mostly about.
Data subject participation
People can ask what you hold about them, and can require correction or deletion.

Section 19 in technical terms

Section 19 requires you to secure the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures — identifying reasonably foreseeable internal and external risks, establishing safeguards against them, regularly verifying that those safeguards are effectively implemented, and updating them as new risks appear.

Read as infrastructure rather than as law, that is four obligations, and each one has a concrete technical equivalent:

  • Identify risks — you cannot secure an estate you have not inventoried. Asset register, external attack-surface review, and a documented view of where personal information physically lives.
  • Establish safeguards — firewall rules and network segmentation that reflect the inventory, access control on least privilege, encryption in transit and at rest, and a patch cadence you can evidence rather than describe.
  • Verify they work — this is the obligation most organisations skip. "Regularly verify that the safeguards are effectively implemented" is a testing requirement, and a policy document does not satisfy it.
  • Keep them current — logging and monitoring that surfaces new exposure, plus a review cycle so the safeguards move when the environment does.

Section 21 adds a related trap: where an operator processes personal information on your behalf — a hosting provider, a payroll bureau, an IT company — that arrangement must be governed by a written contract requiring them to maintain the same security measures. Section 19 obligations do not transfer with the data.

Section 22 and the evidence trail

Section 22 requires notification of the Information Regulator and the affected people as soon as reasonably possible after a security compromise is discovered, in writing, with enough detail for those people to take protective steps.

The practical difficulty is not the notification — it is answering the questions that follow it. What was accessed, when, by whom, and what had you already done to prevent it? An organisation with centralised logging, verified backups and a dated record of security testing can answer those in days. An organisation without them is guessing in public.

That is worth building before you need it, because the evidence trail cannot be created retrospectively.

How a penetration test produces section 19 evidence

Section 19's verification obligation — regularly confirming that safeguards are effectively implemented — is the one an assessment answers directly. A scoped penetration test produces a dated record of what was tested, what was found, what was remediated and what was retested. That is evidence of reasonable measures rather than an assertion of them, and it is the form of proof that survives a Regulator asking follow-up questions.

Systeque maps assessment reports to POPIA's security-safeguard obligations, so the same work doubles as compliance evidence. The scope options, deliverables and what drives the cost are set out on the penetration testing page .

Data residency

POPIA restricts transferring personal information outside South Africa unless specific conditions are met. Where data is hosted in South African data centres, those transborder-flow questions get considerably simpler to answer — one less section to reason about when you document your processing.

Systeque's hosting and backup are run from South African facilities for exactly this reason.

Common questions

What does POPIA stand for?
POPIA stands for the Protection of Personal Information Act, Act 4 of 2013. It is South Africa's data protection law, overseen by the Information Regulator.
What is POPIA?
POPIA is the South African law governing how organisations collect, store, use and share personal information. It sets eight conditions for lawful processing, gives people rights over their own data, and requires organisations to secure that data with appropriate, reasonable technical and organisational measures.
What does POPIA section 19 require?
Section 19 requires a responsible party to secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction and unlawful access. It requires identifying reasonably foreseeable internal and external risks, establishing and maintaining safeguards against them, regularly verifying that those safeguards are effectively implemented, and updating them as new risks emerge.
Who has to comply with POPIA?
Any public or private body that processes personal information in South Africa, regardless of size. There is no small-business exemption from the security obligations in section 19.

Practical next steps

This page is written as infrastructure guidance by an IT company, not as legal advice. POPIA obligations depend on what your organisation actually processes — take legal advice on your specific position.

Evidence, not assertions.

Book a free security assessment — it produces the documented view of risks and safeguards that section 19 asks you to maintain.