
PPOPIA compliance is not simply about adding a privacy statement to your website. Instead, organisations need to consider how they collect, process, store, protect and ultimately dispose of personal information. To start, use this POPIA compliance checklist to work through the key steps you need to take.
The Protection of Personal Information Act 4 of 2013 (POPIA) establishes requirements relating to how South African organisations process and protect personal information. The Act includes conditions relating to accountability, processing limitation, purpose specification, information quality, openness, security safeguards and data-subject participation. As a result, organisations need to consider both their information-handling practices and the technical controls protecting that information.
Ultimately, businesses should review privacy, governance, people, processes and cybersecurity controls together.
Important: This checklist provides general cybersecurity and compliance information and is not a substitute for legal advice.
1. Identify what personal information you process
You can’t protect data you don’t know exists. Therefore, the first step in your POPIA compliance checklist is to identify personal information held across email, CRM platforms, ERP systems, HR systems, finance platforms, cloud storage, customer databases, backups, physical records, and third-party applications. In addition, document where the information originates, where it’s stored, and who can access it.
2. Confirm why personal information is being collected
First, review whether personal information is being collected for a defined and legitimate business purpose. In addition, avoid collecting information simply because it might become useful later. Furthermore, data minimisation can also reduce cybersecurity exposure.
3. Review access control
Next, determine who has access to personal information and whether that access is still necessary.
- Role-based access
- Multi-factor authentication
- Strong password controls
- Privileged access management
- Regular account reviews
- Immediate removal of access when employees leave
By regularly reviewing access, organisations can reduce the risk of unnecessary permissions exposing personal information.
4. Review cybersecurity safeguards
Section 19 of POPIA addresses appropriate safeguards relating to the integrity and confidentiality of personal information and requires responsible parties to identify reasonably foreseeable risks, establish safeguards and regularly verify that those safeguards are effectively implemented.
For example, organisations should consider controls such as:
- Endpoint protection
- Firewalls
- Vulnerability management
- Patch management
- Email security
- Encryption
- Data loss prevention
- Security monitoring
- Backups
- Incident response
- Penetration testing
Together, these controls can help organisations identify, prevent and respond to cybersecurity risks affecting personal information.
5. Review third-party processors and operators
In addition, many businesses share personal information with outside organisations. Review what information each provider receives, why they receive it and what safeguards exist.
- Payroll providers
- Cloud providers
- Managed IT companies
- Marketing platforms
- CRM providers
- Backup providers
As part of this review, organisations should also consider whether third-party arrangements and security practices remain appropriate for the information being processed.
6. Review your privacy notices
Similarly, individuals should understand how their information is processed. Review privacy notices for accuracy and ensure operational practices correspond with what the organisation tells customers, employees and other data subjects.
This helps ensure that documented privacy practices remain aligned with what happens to personal information in practice.
7. Establish retention and deletion rules
Personal information should not remain indefinitely without a business or legal reason. For this reason, establish retention schedules covering different categories of data and ensure information is securely deleted or appropriately de-identified when no longer required.
8. Prepare for security incidents
Additionally, POPIA contains obligations relating to notification of security compromises. As such, businesses should have a documented incident-response procedure before an incident occurs.
This should establish:
- Who receives security alerts
- Who investigates incidents
- Who makes regulatory and legal decisions
- How affected systems are contained
- How evidence is retained
- How communications are coordinated
By establishing these responsibilities in advance, organisations can respond more efficiently when a security incident occurs.
9. Train employees
Beyond technical controls, employees also play an important role in protecting personal information. Training should cover phishing, password security, sensitive information handling, email security, social engineering and incident reporting. Additionally, regular phishing simulations can help identify where additional awareness is required.
10. Test whether your cybersecurity controls work
Having controls on paper is not enough. Instead, organisations should regularly test whether those controls work as intended. Consider vulnerability assessments, penetration testing, security configuration reviews, backup recovery tests, incident-response exercises and continuous security monitoring.
As a result, regular testing can help identify weaknesses before they contribute to a security incident.
POPIA adherence is an ongoing programme
Technology, employees, suppliers and cyber threats continually change. Therefore, POPIA should not be treated as a once-off compliance project. Organisations should periodically review their information-processing activities and the security controls protecting personal information.
Over time, regular reviews can help organisations maintain visibility of their data, identify emerging risks and keep their security practices aligned with changing business requirements.
How Prima Secure can assist
Prima Secure supports South African organisations with cybersecurity risk assessments, penetration testing, vulnerability management, security monitoring, security awareness and other technical controls that can support an organisation’s broader POPIA security programme.
By combining technical assessments with ongoing security controls, organisations can gain greater visibility into the risks affecting their personal information and identify areas requiring additional protection.
Contact Prima Secure to assess the cybersecurity controls protecting your organisation’s personal information.
