POPIA compliance for South African SMEs: secure the personal information you hold
POPIA requires every business to protect the personal information it processes with appropriate, reasonable security. We handle the IT and cybersecurity side of POPIA, so you can show you're protecting client, staff and supplier data and reduce your risk of a costly breach.
What POPIA requires
The Protection of Personal Information Act (POPIA) sets eight conditions for lawfully processing personal information. Condition 7, security safeguards, is where IT matters most, and it is where most businesses are exposed.
Accountability
The business is responsible for compliance.
Processing limitation
Collect only what you need, lawfully.
Purpose specification
Collect for a specific, defined purpose.
Further processing limitation
Use data only in line with that purpose.
Information quality
Keep personal information accurate and up to date.
Openness
Be transparent about what you collect.
Security safeguards
Protect data with appropriate technical and organisational measures. This is where we help.
Data subject participation
People can access and correct their information.
How we help you meet POPIA's security requirements
Security gap assessment
We review your systems against POPIA's security safeguards and give you a clear, prioritised list of risks to fix.
Find where personal data lives
We map where personal information is stored across your servers, Microsoft 365, laptops and cloud apps, so nothing is overlooked.
Access control and encryption
Multi-factor authentication, least-privilege access and encryption for laptops and sensitive data.
Microsoft 365 security →Layered cybersecurity
SonicWall firewalls, ESET endpoint protection and email security to keep attackers out.
Our cybersecurity →Backups stored in South Africa
Encrypted BackIT backups kept in South African data centres, so personal information stays under local jurisdiction.
Online backup →Staff awareness training
Phishing simulations and short training, because most breaches start with a person clicking the wrong link.
Our POPIA security process
Assess
Review your IT systems, data and current security controls.
Report
A plain-language report of risks and priorities.
Protect
Put the right safeguards in place, within your budget.
Be ready if a breach happens
POPIA requires you to act quickly
If personal information is compromised, POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. We help you prepare before it happens and respond fast if it does.
- An IT incident response plan tailored to your business
- Help to contain the incident and restore systems from backup
- Technical details to support your notification to the Regulator
- Lessons learned and fixes to prevent it happening again
Please note: PursuIT Solutions provides the IT and cybersecurity measures that support POPIA compliance. We don't provide legal advice. For legal obligations such as appointing and registering your Information Officer, privacy policies and consent, work with your legal adviser, and we'll handle the technology side.
Frequently asked questions
Does POPIA apply to my small business?
Yes. POPIA applies to any business in South Africa that processes personal information, such as client, staff or supplier details, regardless of size.
What are the penalties for not complying with POPIA?
The Information Regulator can impose administrative fines of up to R10 million, and serious offences can carry imprisonment. A breach can also cause reputational damage and loss of client trust.
What does POPIA say about IT security?
POPIA's security safeguards condition requires you to secure personal information with appropriate, reasonable technical and organisational measures, and to identify and manage the risks to it. That means things like access control, encryption, backups, firewalls, antivirus and staff training.
Where should our backups be stored for POPIA?
Keeping backups in South Africa keeps personal information under South African jurisdiction and makes compliance simpler. Our BackIT backups are stored in South African data centres.
Can you make us fully POPIA compliant?
We cover the IT and cybersecurity side of POPIA, which is where most businesses are exposed. Legal requirements such as privacy policies and your Information Officer should be handled with your legal adviser.
Is your business protecting personal information properly?
Book a POPIA security review and find out where your risks are, with a clear plan to fix them.
Book a POPIA security review