POPIA: security awareness, training & human risk

If your organisation processes personal information in South Africa, you are a responsible party under the Protection of Personal Information Act (POPIA) — and your Information Officer is accountable for showing that your people, not just your firewalls, protect that information. This page explains what POPIA actually expects on the human side of security, and how AfriPhish helps you produce the evidence rather than the promises.

What POPIA requires on staff awareness and human risk

POPIA does not contain a clause labelled "run a security awareness programme". What it contains is stricter: a set of obligations that are impossible to meet without one.

Condition 7 — security safeguards (section 19). You must secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures against loss, unlawful access and unauthorised processing. The section is explicit about the lifecycle: identify reasonably foreseeable risks, establish and maintain safeguards against them, regularly verify that the safeguards are effectively implemented, and update them in response to new risks. Phishing and social engineering are reasonably foreseeable risks for any organisation with an inbox — so an untrained workforce is a gap in your section 19 safeguards, and an unverified training programme fails the "regularly verify" test.

People acting under your authority. POPIA requires that employees and operators process personal information only with your authorisation and treat it as confidential. Staff can only honour obligations they know about — which is why documented training and acknowledged policies matter.

Section 22 — notification of security compromises. Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, you must notify the Information Regulator and affected data subjects as soon as reasonably possible. In practice, the clock starts with an employee noticing something and reporting it. A workforce that recognises phishing and knows the reporting channel directly shortens that window.

Information Officer duties. The POPIA Regulations task Information Officers with ensuring a compliance framework is in place and that internal awareness sessions are conducted on the Act, its regulations and applicable codes of conduct. That is one of the few places in South African data protection law where awareness activity is named outright — and it is the Information Officer, personally, who must be able to show it happened.

The obligations AfriPhish helps you evidence

AfriPhish is built around a simple principle: every awareness activity should leave an audit trail. Here is how the platform maps to POPIA's expectations.

POPIA expectationAfriPhish moduleEvidence produced
Organisational safeguards (Condition 7)Security awareness training in English, French and ArabicPer-user completion records, quiz scores, assignment dates
"Regularly verify" safeguard effectivenessPhishing simulations across realistic scenario familiesClick, credential-submission and report rates, trended per campaign
Foreseeable-risk identificationHuman risk scoringA per-user and per-department risk score that moves with behaviour
Confidentiality and authorised processingPolicy management with e-signature attestationVersioned, timestamped signature registers showing who acknowledged what
Section 22 readinessSimulation reporting behaviour and coachingRecords of who reports suspicious mail, and targeted coaching for those who do not
Information Officer awareness dutiesReports and analyticsExportable programme reports covering the whole awareness cycle

Because training completion, simulation outcomes and policy signatures all live in one platform, your Information Officer answers "show me your organisational measures" with a report, not a reconstruction.

What auditors and regulators typically ask for

When the Information Regulator, an external auditor or an enterprise customer probes your human safeguards, the requests are predictable:

  • Training logs — who was assigned which module, who completed it, when, and with what assessment result.
  • A policy attestation register — which version of your acceptable-use or data protection policy each employee signed, with timestamps.
  • Simulation trend reports — evidence that you test staff against realistic phishing and that failure rates are measured and falling, not guessed at.
  • Reporting-channel records — proof that employees know how to escalate a suspected compromise, and that reports actually flow.
  • Coverage of new joiners — evidence that awareness is continuous, not a one-off induction slide deck.

Every one of these artefacts is a standard export from AfriPhish. None of them needs to be assembled by hand the week before an audit.

See where your organisation stands

Before you build or buy anything, measure. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your current awareness programme against what POPIA's security safeguard condition implies, and tells you exactly where the gaps are.

Prefer to talk it through? Book a demo and we will walk through your POPIA evidence file together.