POPIA compliance for South African SMEs: secure the personal information you hold

POPIA requires every business to protect the personal information it processes with appropriate, reasonable security. We handle the IT and cybersecurity side of POPIA, so you can show you're protecting client, staff and supplier data and reduce your risk of a costly breach.

Security gap assessmentData protectionBreach responseStaff trainingSection 19 safeguards
Book a POPIA security reviewHow we help
POPIA
Up to R10 millionMaximum administrative fine under POPIA
Since July 2021POPIA fully in force for all businesses
As soon as possibleBreaches must be reported to the Information Regulator and affected people

What POPIA requires

The Protection of Personal Information Act (POPIA) sets eight conditions for lawfully processing personal information. Condition 7, security safeguards, is where IT matters most, and it is where most businesses are exposed.

1

Accountability

The business is responsible for compliance.

2

Processing limitation

Collect only what you need, lawfully.

3

Purpose specification

Collect for a specific, defined purpose.

4

Further processing limitation

Use data only in line with that purpose.

5

Information quality

Keep personal information accurate and up to date.

6

Openness

Be transparent about what you collect.

7

Security safeguards

Protect data with appropriate technical and organisational measures. This is where we help.

8

Data subject participation

People can access and correct their information.

How we help you meet POPIA's security requirements

Security gap assessment

We review your systems against POPIA's security safeguards and give you a clear, prioritised list of risks to fix.

Find where personal data lives

We map where personal information is stored across your servers, Microsoft 365, laptops and cloud apps, so nothing is overlooked.

Access control and encryption

Multi-factor authentication, least-privilege access and encryption for laptops and sensitive data.

Microsoft 365 security →

Layered cybersecurity

SonicWall firewalls, ESET endpoint protection and email security to keep attackers out.

Our cybersecurity →

Backups stored in South Africa

Encrypted BackIT backups kept in South African data centres, so personal information stays under local jurisdiction.

Online backup →

Staff awareness training

Phishing simulations and short training, because most breaches start with a person clicking the wrong link.

Our POPIA security process

1

Assess

Review your IT systems, data and current security controls.

2

Report

A plain-language report of risks and priorities.

3

Protect

Put the right safeguards in place, within your budget.

4

Maintain

Ongoing monitoring, reviews and governance through our vCIO service.

Be ready if a breach happens

POPIA requires you to act quickly

If personal information is compromised, POPIA requires you to notify the Information Regulator and the affected people as soon as reasonably possible. We help you prepare before it happens and respond fast if it does.

  • An IT incident response plan tailored to your business
  • Help to contain the incident and restore systems from backup
  • Technical details to support your notification to the Regulator
  • Lessons learned and fixes to prevent it happening again

Please note: PursuIT Solutions provides the IT and cybersecurity measures that support POPIA compliance. We don't provide legal advice. For legal obligations such as appointing and registering your Information Officer, privacy policies and consent, work with your legal adviser, and we'll handle the technology side.

Frequently asked questions

Does POPIA apply to my small business?

Yes. POPIA applies to any business in South Africa that processes personal information, such as client, staff or supplier details, regardless of size.

What are the penalties for not complying with POPIA?

The Information Regulator can impose administrative fines of up to R10 million, and serious offences can carry imprisonment. A breach can also cause reputational damage and loss of client trust.

What does POPIA say about IT security?

POPIA's security safeguards condition requires you to secure personal information with appropriate, reasonable technical and organisational measures, and to identify and manage the risks to it. That means things like access control, encryption, backups, firewalls, antivirus and staff training.

Where should our backups be stored for POPIA?

Keeping backups in South Africa keeps personal information under South African jurisdiction and makes compliance simpler. Our BackIT backups are stored in South African data centres.

Can you make us fully POPIA compliant?

We cover the IT and cybersecurity side of POPIA, which is where most businesses are exposed. Legal requirements such as privacy policies and your Information Officer should be handled with your legal adviser.

Is your business protecting personal information properly?

Book a POPIA security review and find out where your risks are, with a clear plan to fix them.

Book a POPIA security review