Abstract dark navy and purple graphic representing data privacy compliance in South Africa
|

POPIA Three Years In: Where South African Businesses Are Still Exposed

POPIA has been enforceable since July 2021. Most South African businesses have done something about it — a privacy policy here, a data register there. Very few have done enough.

The Information Regulator has been relatively quiet since enforcement began, which has created a false sense of security in some organisations. Quiet does not mean inactive. The Regulator is building capacity, receiving complaints, and investigating. The enforcement actions that have happened have been significant.

Where most businesses are exposed

The most common gaps we find when doing POPIA assessments are not exotic. They are mundane. Customer data sitting in spreadsheets with no access controls. Email marketing lists with no documented consent basis. Third-party suppliers processing personal information with no data processing agreement in place. HR records retained indefinitely with no retention policy.

None of these are difficult to fix once identified. The challenge is that most businesses have never systematically looked. They passed their audit, they published their privacy policy, and they moved on. The problem with that approach is that POPIA compliance is not a milestone you reach and then forget. It is an ongoing practice that needs to keep up with how your business actually handles data day to day.

Consider the tools your team uses now compared to three years ago. Slack channels where attachments get shared freely. Cloud storage accounts that someone set up for a project and never closed. Marketing automation platforms that hold years of contact data with no clear record of where consent came from. Each of these is a POPIA exposure that did not exist when your privacy policy was written.

What a practical POPIA review looks like

A practical POPIA review is not a legal audit. It is a structured look at how personal information actually flows through your business — where it comes in, where it goes, who has access, how long it is kept, and what happens when someone asks you to delete it. The output should be a short list of prioritised gaps with practical actions, not a 60-page report.

We typically structure a review in three stages. First, we map where personal data enters the business — web forms, customer onboarding, supplier registrations, employee records. Second, we trace where it goes — who can access it, what systems process it, which third parties receive it. Third, we check what happens at the end — retention schedules, deletion procedures, and whether subject access requests can actually be fulfilled within the 30-day window POPIA requires.

The cost of inaction

The Information Regulator can impose administrative fines of up to R1 million per instance, and that is before considering the cost of a data breach itself. A single complaint from a data subject can trigger an investigation that covers your entire data handling practice, not just the one incident. The reputational cost of being found non-compliant after a breach is harder to quantify but often more damaging than the fine.

More practically, the businesses that handle POPIA well tend to be the ones that handle data well in general. Clean data, clear retention, proper access controls — these are operational benefits that pay for themselves long before the Regulator comes knocking. Compliance is not the goal. Good data hygiene is the goal, and compliance follows from it.

Where to start if you have not done enough

If you are not sure where you stand, start with three things. First, list every place personal data is stored, from your CRM to the spreadsheet on someone’s desktop. Second, check whether each of those has documented access controls and a retention schedule. Third, verify that you can actually respond to a subject access request — not in theory, but in practice, within 30 days.

If any of those three steps reveal gaps, you are not alone. Most South African businesses are in the same position. The difference between being exposed and being compliant is not a massive project — it is a structured review and a prioritised action list. The most expensive option is doing nothing. The same applies to cheap IT support — the savings on the retainer vanish the moment something goes wrong.

The enforcement gap

The Information Regulator has been slow to enforce, but that is changing. Recent fines and public enforcement actions signal that POPIA is no longer a paper exercise. Organisations that have treated compliance as a tick-box are now facing questions they cannot answer. The regulator is asking for evidence of compliance, not a statement of intent.

For most businesses, the gap is not in policy — it is in practice. The PAIA manual exists, the privacy policy exists, the consent forms exist. But when the regulator asks for evidence that those policies are followed, the answer is often silence. Compliance is what you do, not what you wrote down.

POPIA asks for reasonable security. A scan shows where yours stands. We run a free attack-surface scan for South African companies. It’s passive, so nothing gets touched. You get a plain English report in your inbox. Start here: free security scan

Need Help With Your Security or IT?

We work with South African businesses to assess, deploy, and manage security and IT that actually fits. No jargon, no scare tactics. Practical advice and real support.

Contact Us →

See what hackers can see about your business

Get your free security scan

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *