KITE 2025 New Product Award — Local IT | SACEEC
Privacy and access

POPIA, broken into the eight conditions and the controls behind them

POPIA is usually summarised as a privacy policy and an information officer. In practice it is eight conditions for lawful processing, each with its own operational obligations, plus a security duty and a breach notification duty with a clock attached. Dimeri holds each one as a tracked obligation with evidence.

What POPIA requires

The Protection of Personal Information Act 4 of 2013 gives effect to the constitutional right to privacy by regulating how personal information is processed. Most of its substantive provisions commenced on 1 July 2020, with a one year grace period that ended on 1 July 2021. Since then the Information Regulator has been an operating regulator: receiving complaints, issuing enforcement notices and pursuing matters where organisations have failed to secure personal information.

The Act is built around eight conditions for lawful processing. Accountability places responsibility on the responsible party. Processing limitation requires that processing be lawful, minimal and justified, usually by consent or another listed ground. Purpose specification requires a defined, lawful purpose and limits retention. Further processing limitation requires compatibility with that original purpose. Information quality requires the information to be complete, accurate and current. Openness requires documentation of processing and notification to the data subject. Security safeguards, in section 19, require appropriate, reasonable technical and organisational measures. Data subject participation gives individuals rights of access and correction.

Two duties generate most of the operational work. Section 19 is deliberately open ended: appropriate and reasonable is judged against generally accepted information security practices and the harm that could result, which means the organisation must be able to show what it considered and what it implemented. Section 22 requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible after a security compromise, which means the breach response has to be ready before it is needed.

The obligations Dimeri tracks

Dimeri holds POPIA as conditions and sections rather than as a single compliance line, so a gap points at a specific obligation and a specific owner.

Sections 8 and 55, condition 1

Accountability and the information officer

The responsible party must ensure the conditions are complied with, and the information officer carries specific duties including registration with the Information Regulator.

  • Information officer and deputies recorded with their duties
  • Registration status and renewal dates tracked
  • Compliance framework and assessments held with dates
  • Awareness and training records by individual
Sections 9 to 12, conditions 2 and 3

Processing limitation and purpose specification

Processing must be lawful, adequate, relevant and not excessive, justified on a listed ground, for a specific defined purpose, with retention limited accordingly.

  • Processing register with the lawful ground per activity
  • Consent records linked to the processing they authorise
  • Purpose statements held against each activity
  • Retention periods with scheduled disposal
Sections 15 to 18, conditions 4 to 6

Further processing, quality and openness

Compatibility of further processing with the original purpose, information that is complete and current, documented processing and notification to data subjects.

  • Compatibility assessments recorded for new uses
  • Data quality controls with testing evidence
  • Processing documentation maintained and versioned
  • Collection notices held against each channel
Sections 19 to 21, condition 7

Security safeguards

Appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information and unlawful access.

  • Risks to personal information identified and assessed
  • Safeguards mapped to the risks they treat
  • Control effectiveness tested on a schedule
  • Operator contracts with the required security terms
Section 22

Security compromise notification

Notification to the Information Regulator and to affected data subjects as soon as reasonably possible after there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

  • Incident register with detection and assessment times
  • Notification decision recorded with its reasoning
  • Regulator and data subject notifications evidenced
  • Post incident actions tracked to closure
Sections 23 to 25, condition 8

Data subject participation

The right to know what personal information is held, to access it and to request correction or deletion.

  • Request register with statutory deadlines
  • Identity verification evidence held with the request
  • Response and any refusal grounds recorded
  • Escalation before a deadline is reached

How Dimeri covers POPIA

POPIA failures are rarely failures of intent. They are failures to show what was done, when, and by whom. Dimeri is built around that evidence problem.

Security safeguards you can defend

Section 19 asks for appropriate and reasonable measures. Dimeri holds the risk assessment that identified the threat, the safeguard selected, the reason it was considered appropriate, and the test results showing it operates. That is the record an enforcement notice tests.

Breach notification with the clock running

Section 22 notification is time sensitive and judgement heavy. The incident workflow records when the compromise was detected, when reasonable grounds arose, what was decided and when each notification went out, so the timeline can be reconstructed exactly.

Requests that do not go past their date

Data subject access and correction requests are logged with their statutory deadline, owner and escalation. Requests that arrive by email into one person's inbox are the most common way a deadline is missed.

Shared credit with PAIA and ISO 27001

The information officer role, the processing documentation and the security controls all do double duty under PAIA and information security standards. Map the control once and it counts across each.

Getting POPIA coverage in place

  1. 1

    Build the processing register

    Every processing activity is recorded with its purpose, lawful ground, categories of data subject and information, recipients, retention period and the operator involved. Everything else in POPIA hangs off this.

  2. 2

    Map safeguards to risks

    Risks to personal information are assessed and existing safeguards attached. What is left is the section 19 gap list, prioritised by the harm that would result rather than by how easy each fix is.

  3. 3

    Stand up the request and incident workflows

    Data subject requests and security compromises get their own intake, deadlines, owners and escalation, so neither depends on an individual remembering.

  4. 4

    Report and review

    The information officer reports from live data: obligation coverage, control effectiveness, open requests, incidents and remediation, with the same record feeding the board and the Regulator.

POPIA questions

Who has to register an information officer?

Every responsible party has an information officer, and in a private body the head of the organisation holds the role by default unless it is delegated. Information officers are required to register with the Information Regulator, and deputies may be designated. Dimeri tracks who holds the role, the delegations and the registration status, and your legal advisers should confirm the current registration requirements.

What does section 19 actually require?

Section 19 requires appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information and unlawful access to or processing of it. It also requires the responsible party to identify reasonably foreseeable internal and external risks and to have regard to generally accepted information security practices. It is a standard you demonstrate rather than a list you complete.

How quickly must a data breach be reported?

Section 22 requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible after the discovery of the compromise, with a limited allowance for delay where a public body or the Regulator determines it would impede a criminal investigation. Because the standard is reasonableness rather than a fixed number of hours, the record of when you knew and what you did matters a great deal.

How is this different from the POPIA software page?

This page describes the framework itself and how Dimeri maps its obligations. The POPIA compliance software page covers the product in more depth, including the data subject request workflow and the information officer reporting. Both draw on the same underlying platform.

Is this a substitute for legal advice?

No. POPIA obligations depend on what you process and why, and the Information Regulator's guidance continues to develop. This page describes how Dimeri structures the obligations for tracking and evidence. Your legal advisers should confirm what applies to you.

Put POPIA on one register

Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.