Most businesses treated POPIA as a paperwork exercise. A privacy policy went up on the website, a consent checkbox appeared on the contact form and the file was closed. The uncomfortable truth is that the Protection of Personal Information Act makes demands that no policy document can satisfy on its own. Section 19 requires responsible parties to secure personal information through appropriate technical measures, and technical measures live in your IT environment, not in your filing cabinet.
What the Act actually asks of your systems
Stripped of legal language, POPIA’s security requirements come down to a handful of practical questions. Do you know what personal information you hold and where it sits? Can you control who accesses it? Would you know if it was compromised? Could you recover it if it was lost? If any of those questions produces an uncomfortable pause, the checklist below is for you.
The practical checklist
Know your data. Map where personal information lives across your business: CRM, email, accounting software, spreadsheets on shared drives, old backups and the laptop of that employee who left in March. You cannot protect what you have not located, and forgotten data stores are a common source of breaches.
Control access. Apply the principle of least privilege, meaning staff access only the information their role requires. Remove access the day someone leaves, not the month after. Enforce strong passwords and switch on multi-factor authentication for every system that holds personal information.
Encrypt what matters. Laptops and mobile devices should have full-disk encryption enabled, which is free and built into modern operating systems. Personal information travelling over the internet should move through encrypted channels only.
Back up and test. POPIA requires that you can restore personal information that is lost or damaged. A backup that has never been test-restored is a hope, not a safeguard. Follow a proper backup regime and run restore tests on a schedule.
Manage your third parties. Every operator that processes personal information on your behalf, from your payroll provider to your email marketing platform, needs a written agreement covering their security obligations. Their breach becomes your notification duty.
Prepare for the bad day. Section 22 requires notification to the Information Regulator and affected data subjects when a compromise occurs. Draft the process now: who assesses the incident, who notifies, what gets logged. Writing this during an actual breach is the worst possible time.
Retire data properly. Personal information kept beyond its purpose is a liability. Old databases, former client records and departed employee files should be securely deleted on a defined retention schedule, and hardware should be properly wiped before disposal.
Compliance as a by-product of good IT
The pattern worth noticing is that almost everything on this list is simply good IT practice with a legal deadline attached. Businesses with well-managed environments find POPIA compliance largely comes free. Businesses with sprawling, unmanaged systems find it painful, because the Act is exposing problems that were already there.
Enyuka ICT helps South African businesses build the technical foundations that POPIA assumes you have. If you would struggle to answer the Regulator’s questions after an incident, a compliance-focused IT assessment is the sensible next step. Get in touch with our team to arrange one.


