POPIA Compliance: What South African Businesses Must Do Now
When POPIA's grace period ended in June 2021, many organisations breathed a sigh of relief and assumed the Act was largely theoretical. That view has changed rapidly. The Information Regulator has become increasingly active, investigations are underway, and the Act's enforcement mechanism — including penalties of up to R10 million and criminal prosecution — is very much operational.
What POPIA Requires
POPIA governs how organisations collect, store, use, share, and dispose of personal information. At a minimum, compliance requires:
- Appointing an Information Officer (registered with the Information Regulator)
- Conducting a personal information audit to understand what data you hold and why
- Implementing appropriate technical and organisational security measures
- Establishing data subject rights procedures (access, correction, objection, deletion)
- Creating a data breach response plan with mandatory notification obligations
- Publishing a PAIA Manual (required under the Promotion of Access to Information Act)
The IT Dimension
POPIA compliance is not only a legal matter — it has a significant IT dimension. Access controls, encryption, audit logging, data retention policies, endpoint security, and secure email are all technical controls that directly underpin POPIA obligations.
Organisations that achieve ISO 27001 certification have a significant head start on POPIA compliance because the information security management framework required by ISO 27001 maps closely to POPIA's security conditions.
Where to Start
If your organisation has not yet completed a formal POPIA gap assessment, that is the right starting point. Understand what personal information you hold, where it flows, and what controls are in place. From there, a prioritised remediation plan becomes straightforward to develop.

