Most mid-sized South African companies have “done POPIA” the easy way: a privacy policy on the website, a clause in the employment contracts, maybe a workshop in 2021. That version of compliance survives exactly until something goes wrong — a laptop theft, a mis-sent spreadsheet, a ransomware note.
POPIA is operational law, not paperwork. When the Information Regulator asks questions, they ask about what you do: what you collect, where it lives, who can touch it, and what happened when it leaked. Here is where we tell clients to spend their effort.
Know what you hold (data mapping)
You cannot protect what you haven’t found. A data map answers four questions per system: what personal information is in it, why you process it, who accesses it, and how long you keep it. Include the unglamorous places — shared drives, email attachments, that Excel export the sales team refreshes weekly. The map drives everything else, and its gaps are usually the audit findings.
Control who can touch it (access management)
The Regulator’s section 19 requires “appropriate, reasonable technical and organisational measures”. In practice, the first measures examined are access controls. Multi-factor authentication everywhere, role-based access instead of shared logins, and a working joiner-mover-leaver process — the ex-employee whose account still works six months after resignation appears in more incident reports than any hacker.
Paper your processors (operator agreements)
Every third party that processes personal information on your behalf — payroll bureau, marketing platform, IT support company, cloud provider — is an “operator” under POPIA, and you remain responsible for what they do. Operator agreements with security obligations are not optional garnish; their absence converts a supplier’s breach into your liability, unmanaged.
Rehearse the bad day (incident response)
Section 22 requires notifying the Regulator and affected people “as soon as reasonably possible” after a compromise. Companies without a plan lose days deciding who decides. A one-page incident runbook — who assesses, who notifies, who speaks — rehearsed once a year, is the difference between a controlled disclosure and a scramble that becomes its own story.
The honest sequencing
Data map first, access controls second, operator agreements third, incident plan fourth. Policies matter, but they document reality — writing them before fixing reality just creates evidence of what you knew and didn’t do. Start where the risk is.