How will PoPIA impact cloud providers?

Issue 4 2021 Security Services & Risk Management

While Covid-19 has seen organisations shift to cloud platforms overnight to help them remain operational while their workforces are operating remotely, too many are not up to speed with what this means in terms of their data.


Stuart Oberholzer.

This is particularly true now that the Protection of Personal Information Act (PoPIA) is coming into play, says Stuart Oberholzer, information security compliance manager at PaySpace.

Discussing the role and responsibility of cloud providers in regard to complying with the PoPIA, Oberholzer noted that although cloud providers and third parties such as managed service providers are obligated to protect any personal data they handle, process or store, when it comes to ensuring the safety of their information, the onus is on the organisation that contracted them.

“Primarily, cloud providers need to ensure that data is stored within South Africa’s borders. In fact, should any data be stored outside the country, they should seek legal advice and also get full consent from the data owners to make sure that any affected customers are aware of this,” he explains.

In addition, he says anyone who is storing data outside South Africa should make sure it is being stored in a territory that has either similar or stronger regulation in place than PoPIA. “In terms of data responsibility, it ultimately lies with the customer to make sure its data is safe and secure. Customers need to understand where their data is being stored and if they haven’t been contacted by their cloud provider yet, they should take the initiative and contact them.”

Speaking of what cloud providers themselves need to do to prepare for PoPIA, he says as with any other business, they need to understand their processes, such as how they are storing data and ensure they are not processing any data that they shouldn’t. “They can prepare themselves and their customers by fully understanding the requirements of the Act, in terms of what is required from them, as well as what their customers need to do.”

In addition, he says any cloud providers that are hosting data need to ensure that the data is being stored securely and that it can’t easily be breached by an attacker.

Oberholzer refers to sections 21(1) and (2) of the Act, which specifies: “A responsible party must, in terms of a written contract between the responsible party and the operator, ensure the operator, which processes personal information for the responsible party, establishes and maintains the security measures referred to in Section 19. The operator must notify the responsible party immediately where there are reasonable grounds to believe the personal information of a data subject has been accessed or acquired by any unauthorised person.”

He says to remember that cloud providers need to ensure there is clarity in terms of what is expected from each party. “By being prepared, they can help customers prepare. Ultimately, data protection in the cloud is a two-way street. The cloud provider is responsible for making sure data is stored correctly, that only the authorised people have access to it, that data is fully backed up and that service is uninterruptible.”

The customer, Oberholzer says, must ensure that their networks are secure and that all devices that are used to access their information are secure too. “Ultimately, it is a shared responsibility model. Cloud providers must inform their customers that PoPIA is happening, but at the end of the day, it is up to the customer to ensure that their own processes are compliant.”

Offering one more piece of advice, Oberholzer says cloud providers need to stay up to date with what the Information Regulator has to say and keep a close eye out for any updates. “As the PoPIA process is refined, there are bound to be announcements and amendments that will ultimately affect every organisation. Check the regulator’s website and follow any directives that are issued.”

This will not only help cloud providers protect their customers; it will also help to shield the provider from any reputational damage that might result from a possible leakage of data. “It is a common misconception among South African organisations when outsourcing to a third-party provider that any risk relating to a data breach transfers to that service provider, but this isn’t the case. PoPIA stipulates that the main responsibility of data protection lies with the company itself.”

The Information Regulator’s website is at www.justice.gov.za/inforeg/index.html




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SABRIC Annual Crime Statistics 2024
News & Events Security Services & Risk Management Residential Estate (Industry)
SABRIC has released its Annual Crime Statistics for 2024, reflecting a significant decline in financial crime losses, but also warning of the growing threat posed by artificial intelligence (AI) in fraud schemes.

Read more...
SA’s private security industry receives multi-million USD investment
News & Events Security Services & Risk Management
South Africa's private security sector has attracted significant international attention, with the world’s largest tactical flashlight manufacturer, Nextorch, announcing a major investment in its local operations, Nextorch Africa.

Read more...
Vetting people in security estates
iFacts Security Services & Risk Management Residential Estate (Industry)
In today’s security-conscious South Africa, estate management’s responsibility extends beyond gates and patrols; it involves ensuring that every resident, staff member, and service provider upholds the community’s safety standards.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
IVA AI Pro Visual Gun Detection
Products & Solutions Surveillance Security Services & Risk Management Residential Estate (Industry)
Bosch has announced the launch of the IVA AI Pro Visual Gun Detection analytics based on deep learning. It is designed for automatic detection and classification of people and brandished firearms.

Read more...
IP-based horn loudspeakers
Products & Solutions Surveillance Security Services & Risk Management Residential Estate (Industry)
Bosch has announced the launch of its new IP-based horn loudspeakers and amplifier module: the high-output LHN-UC15L-SIP horn (for long-throw applications), the compact LHN-UC15W-SIP horn (for wide-angle coverage) and the AMN-P15-SIP amplifier module.

Read more...
SMART Estate Security Conference KZN 2025
Arteco Global Africa OneSpace Technologies SMART Security Solutions Technews Publishing Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
May 2025 saw the SMART Security Solutions team heading off to Durban for our annual Estate Security Conference, once again hosted at the Mount Edgecombe Country Club.

Read more...
ProtecLink 2025 spotlights industry tensions and transformation
Magtouch Electronics t/a Ithegi Electronics Security Services & Risk Management News & Events
ProtecLink 2025, created and hosted by Ithegi Electronics, brought together key stakeholders from the security, finance, and innovation sectors under the theme "Connecting Security, Finance, and Innovation: Inspiring Transformation in the Industry."

Read more...
SSG Holdings acquired by Fidelity Services Group
News & Events Security Services & Risk Management
Fidelity Services Group has successfully acquired a majority shareholding in SSG Holdings. The acquisition builds on Fidelity’s track record of strategic expansion, including previous high-profile acquisitions.

Read more...
The role of drones in farm protection
Agriculture (Industry) Security Services & Risk Management
Laurence Palmer reminds us of the role drones play in agricultural security and offers a free security risk assessment template for downloading (link at the end of the article).

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.