Is Your Data Legal?
The Protection of Personal Information Act (POPIA) came into full effect in July 2021, but years later, many South African businesses are still winging it. "We're too small to worry about that" is something we hear weekly. It's also something that won't hold up when the Information Regulator comes knocking.
POPIA isn't just paperwork; it's about trust. If you lose a client's personal data through negligence, the fine is painful (up to R10 million), but the reputation damage is often fatal. Customers don't forgive breach notifications.
The Must-Haves
- Lawful Consent: Stop adding random people to your newsletter because you met them at a networking event. You need active, informed opt-in consent before processing personal information. Pre-ticked boxes don't count. Silence doesn't count. You need a clear "Yes, I want to receive this" action from the person.
- Encryption at Rest: If a laptop is stolen from your employee's car, is the hard drive encrypted? (BitLocker for Windows, FileVault for Mac). If yes, it's an annoying hardware loss and you need to buy a new laptop. If no, it's potentially a data breach reporting event, and you have 72 hours to notify the Information Regulator and affected individuals. The difference is massive.
- Encryption in Transit: Data moving across the internet must be encrypted. This means HTTPS on your website, TLS for your email servers, and VPN or encrypted connections for remote access to company systems. No excuses.
- The Information Officer: You legally must designate someone as your Information Officer responsible for data protection in your organisation. If you haven't formally appointed someone, it defaults to the CEO. That CEO is then personally accountable. Most businesses delegate this to a senior manager or compliance officer, but it must be documented and registered.
- Data Retention Policies: Delete those CVs from applicants you didn't hire three years ago. Hoarding data you don't need isn't an asset, it's a liability. Every record you hold is a potential breach vector. If you don't need it for a legitimate business purpose, delete it. Document your retention periods and actually enforce them.
- Processing Agreements: Any third party that handles your customer data needs a formal operator agreement. This includes your IT provider, your accountant, your marketing agency, your cloud services, everyone. These agreements must specify how they protect data and what happens if they breach.
The Often-Overlooked Items
- Your Website Privacy Policy: "We respect your privacy" is not a privacy policy. You need to specifically state what data you collect, how you use it, who you share it with, how long you keep it, and how people can request access or deletion. Your current policy was probably copied from a template in 2018. It needs updating.
- Employee Training: Your receptionist, your sales team, your delivery drivers, everyone who handles personal information needs basic training on data protection. Knowing not to leave client files in an Uber is data protection. Update this training annually.
- Subject Access Requests: If someone asks you "What data do you hold about me?", you must respond within 30 days with a complete answer. Do you have a process for this? Most businesses don't, until they receive their first request and panic.
- Breach Response Plan: If data is compromised, what happens? Who makes decisions? Who contacts the regulator? Who drafts the notification to affected people? Having a plan before you need it is the difference between a contained incident and a public relations disaster.
Getting Started
POPIA compliance isn't a once-off project, it's an ongoing process. Start by:
- Auditing what personal data you actually hold and where it lives
- Documenting your lawful basis for processing each category of data
- Implementing technical controls (encryption, access control, backup)
- Training your staff
- Reviewing and updating your policies annually
If this feels overwhelming, you're not alone. Most businesses need external help for the initial setup. But the investment is far cheaper than the alternative. Start with our printable POPIA compliance guide, or book a POPIA compliance assessment and let us map the gaps for you.