Privacy by design or by accident

February 2026 Security Services & Risk Management, Infrastructure

Every January, Data Privacy Day invites organisations and individuals to reflect on how they handle personal information. This year, two themes stand out. For organisations, the call is to prioritise privacy by design, building privacy into systems from the outset rather than adding it later. For individuals, the message is to take control of your data, understanding where it flows, who accesses it, and how it is protected.


Mwandu Mwelwa.

In Africa, privacy is not only a policy or awareness issue, but an operational one. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Privacy by design is cheaper than privacy retrofits

Privacy-by-design is a systems discipline. The principle is that security and privacy controls should be embedded in architecture, workflows, and default configurations, not added after deployment. Regulators and privacy authorities have long pushed this direction because retrofitting privacy controls into live environments is costly, disruptive, and often incomplete. An accessible overview of the principle is outlined by the Office of the Privacy Commissioner of Canada.

In practice, privacy-by-design means identity controls that enforce least-privilege access by default. It means encryption built into data storage and transport, continuous monitoring, audit trails, and policy enforcement that do not require manual intervention. Most importantly, it means visibility to know where sensitive data lives, how it moves, and when something deviates from normal behaviour.

For many African organisations, the challenge is the realities of infrastructure. Many businesses have distributed branches, limited on-site IT staff, shared networks, and an increasing reliance on cloud platforms and remote access. Without built-in controls and managed visibility, privacy risks accumulate quickly.

Individuals must take control, but systems must support them

The second global theme (encouraging individuals to take control of their data) is equally important. Simple actions, such as using strong passwords, enabling multi-factor authentication, limiting oversharing, and recognising phishing attempts, significantly reduce risk.

Organisations cannot rely on awareness alone. People make mistakes, devices are lost, links fail, and credentials are reused. Privacy-by-design accepts this and assumes human error will occur. Systems are then built to contain damage, limit lateral movement, and provide clear evidence when incidents happen.

In African environments, this combination of human behaviour and infrastructure variability makes managed, always-on controls even more important. A branch that loses connectivity or power should not become a blind spot. A temporary network workaround should not bypass the security policy. A remote user should not be granted broader access simply because identity controls are inconvenient to enforce.

Data centres matter, but the edge decides the outcome

Africa’s data centre ecosystem is expanding rapidly. New facilities, interconnection growth, and hyperscaler investment are strengthening local hosting, improving latency, and addressing data sovereignty requirements. Even the most resilient data centre only delivers privacy and security outcomes if the path between the user and the facility is reliable, visible, and protected.

This is where many privacy strategies fail. The core may be secure, but the edge (branch offices, retail sites, depots, clinics, and field locations) remains exposed. Privacy-by-design must therefore extend to the edge. Otherwise, privacy becomes dependent on good fortune rather than engineered control.

Turning privacy intent into operational control

At inq., we see privacy, security, and connectivity as inseparable. Visibility, monitoring, managed enforcement, and clear reporting are the foundation. Without them, privacy risk cannot be measured, let alone reduced.

That is why our managed connectivity and security services focus on delivering operational outcomes: continuous link monitoring, built-in threat protection, vulnerability visibility, identity-aware access, and evidence-driven incident reporting. These capabilities allow organisations to prove control rather than merely claim it.

For African organisations, this approach matters. It recognises that infrastructure constraints exist. It acknowledges that in-house security teams are often stretched thin. It replaces fragile manual processes with managed, automated controls that continue to function even under less-than-ideal conditions.

A practical next step

Data Privacy Day should not be treated as a one-off compliance reminder. It is an opportunity to ask, can we prove that our systems enforce privacy even when networks fail, devices move, and people make mistakes?

For organisations, this starts with reviewing where sensitive data resides, who has access, and what controls are enforced by default. For individuals, it begins with understanding digital habits and tightening basic hygiene. For technology leaders, this means ensuring that privacy-by-design is not a document on a shelf, but a property of the architecture itself.

Privacy that works only in ideal conditions is not privacy. In Africa, systems must be designed to succeed in real situations. That is where trust is built and where it is most easily lost.

For more information, visit www.inq.inc.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
Identity recovery matters most
Security Services & Risk Management
As cyberattacks grow more targeted, more destructive, and increasingly aimed at the very fabric of trust within the enterprise, the ability to restore identities has become just as critical as restoring data.

Read more...
ISO 27701 helps demonstrate privacy compliance beyond POPIA
Security Services & Risk Management
ISO 27701 include privacy-specific controls and provides a structured way to manage Personally Identifiable Information (PII) throughout its lifecycle, giving organisations a way to demonstrate how privacy is managed.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
Increase in cyberattacks on the manufacturing sector
Security Services & Risk Management News & Events Industrial (Industry)
According to a new Kaspersky ICS CERT report, in the first quarter of 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19,6% globally.

Read more...
Next-generation cash-in-transit vehicle
News & Events Security Services & Risk Management
Fidelity Services Group has unveiled a new, purpose-engineered Cash-in-Transit (CIT) vehicle designed to redefine crew protection, deter threats, and enhance operational resilience in an increasingly complex criminal environment.

Read more...
The risk at the edge of South Africa’s agriculture supply chain
Security Services & Risk Management Agriculture (Industry) Logistics (Industry)
Research from ESET has found that a significant number of South African agritech operators and farmers continue to believe their companies are not attractive targets for cybercriminals. Unfortunately, that belief is precisely what makes them one.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.