POPIA Compliance Hub – Liyatech Solutions
Reference · Cybersecurity Resources

POPIA Compliance Hub

Everything South African businesses need to know about the Protection of Personal Information Act — who it applies to, what it requires, and what happens if you get it wrong.

Enforced by the Information Regulator Fines up to R10 million

What is POPIA?

The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It was signed in 2013, but the bulk of the Act only became enforceable on 1 July 2021 after a grace period, and it is fully in force today. POPIA sets out how any organisation may lawfully collect, use, store and share personal information, and what must happen if that information is compromised.

It's enforced by the Information Regulator, an independent body with the power to investigate complaints, issue enforcement notices, and impose fines. POPIA shares a lot of its thinking with the EU's GDPR, so if you've dealt with GDPR before, the underlying logic will feel familiar — even though the specific obligations differ.

Who does it apply to?

POPIA applies to any "responsible party" — any person or organisation, in any sector or size — that processes personal information using automated or non-automated means in South Africa. That includes:

  • South African businesses of any size, from sole proprietors to large enterprises
  • Government departments and public entities
  • Foreign organisations that market to, or process the personal data of, people in South Africa — POPIA's reach isn't limited to companies registered locally

If your business holds employee records, customer contact details, CVs, financial information, or anything else that identifies a person, POPIA applies to you. There's no small-business exemption.

The 8 conditions for lawful processing

POPIA doesn't ban the use of personal information — it sets eight minimum conditions that must be met whenever it's processed.

CONDITION 1
Accountability
Your business is responsible for ensuring all eight conditions are met, and for demonstrating that compliance on request.
CONDITION 2
Processing Limitation
Personal information must be processed lawfully, reasonably, and without infringing the data subject's privacy more than necessary.
CONDITION 3
Purpose Specification
Data may only be collected for a specific, clearly defined, lawful purpose, and must be disposed of once that purpose is fulfilled.
CONDITION 4
Further Processing Limitation
Information can't quietly be reused for a new, unrelated purpose without a fresh lawful basis — the original purpose it was collected for still applies.
CONDITION 5
Information Quality
Reasonable steps must be taken to keep personal information accurate, complete and up to date.
CONDITION 6
Openness
Data subjects must be told what's being collected, why, and by whom — typically through a clear privacy policy.
CONDITION 7
Security Safeguards
Appropriate technical and organisational measures must be in place to protect information against loss, damage or unauthorised access — this is where cyber security and POPIA overlap directly.
CONDITION 8
Data Subject Participation
People have the right to know what information you hold on them, request corrections, and in many cases request that it be deleted.

What happens if you don't comply?

The Information Regulator has moved into active enforcement, and non-compliance carries real financial and, in serious cases, criminal exposure:

R10m
Maximum administrative fine per violation
10 yrs
Maximum imprisonment for the most serious offences
0
Small-business exemptions from the Act

Beyond the direct penalties, a publicly disclosed breach usually causes more lasting damage through lost customer trust and reputational harm than the fine itself.

Getting compliant: where to start

POPIA compliance is a programme, not a once-off project. These are the foundational steps most South African businesses still need to put in place:

Appoint an Information Officer
Every organisation must designate someone accountable for POPIA compliance, including handling data subject requests and breach reporting.
Run a data audit
Know exactly what personal information you hold, where it lives, who can access it, and why you have it in the first place.
Update your privacy policy
Clearly explain what you collect, why, how long you keep it, and how people can exercise their rights over it.
Put security safeguards in place
Condition 7 requires appropriate technical safeguards — this is where managed IT and cyber security controls directly support your legal obligations.
Prepare a breach response plan
POPIA requires you to notify the Information Regulator and affected individuals when a breach occurs — know in advance how that decision gets made and who makes it.
"POPIA compliance and cyber security aren't two separate projects — Condition 7 makes your security safeguards a legal requirement, not just good practice." Liyatech Solutions

Not sure where your business stands with POPIA?

Book a free Cyber Readiness Assessment — it covers the security safeguards POPIA requires, with a written summary of gaps.

Book a free assessment