What POPIA is
South Africa’s Protection of Personal Information Act (POPIA) sets rules for how organizations collect, store, process, and share personal information. It applies to any organization that processes personal information within South Africa, regardless of where that organization is headquartered.
Who it applies to
POPIA applies broadly: private companies, public bodies, and non-profits that handle personal information of South African data subjects, whether employees, customers, or website visitors. There is no small-business exemption based on size alone.
The core obligations
- Process personal information lawfully and only for a specific, defined purpose
- Collect only what is necessary (minimality)
- Keep information secure with appropriate technical and organizational measures
- Notify the Information Regulator and affected data subjects of qualifying security compromises
- Honor data subject requests to access or correct their information
How this maps to security controls
CyberNova’s Cybersecurity Fundamentals course treats POPIA as the natural outcome of sound security practice rather than a separate compliance exercise. Access control, encryption, logging, and incident response — the same controls covered in the Foundations and Network Defense modules — are what POPIA’s security safeguard condition actually requires in practice.
This article is general information, not legal advice. Organizations should consult a qualified professional to assess their specific POPIA obligations.