Most POPIA compliance advice is written by lawyers for the business that owns the data. A South African MSP sits on the other side of that advice: the client signs the privacy policy, and you are the one who has to make section 19 true on an ordinary Tuesday. Section 19 demands working technical controls, verified regularly and updated when they stop working. Here is what the Act says, what the Information Regulator has enforced, and which parts of your stack answer each duty.
What does POPIA section 19 require?
Section 19 of POPIA requires a responsible party to secure the integrity and confidentiality of personal information by taking “appropriate, reasonable technical and organisational measures” to prevent loss, damage, unauthorised destruction, and unlawful access or processing.
Section 19(2) turns that into four continuing duties. Identify all reasonably foreseeable internal and external risks to personal information. Establish and maintain appropriate safeguards against those risks. Regularly verify that the safeguards are effectively implemented. Ensure the safeguards are continually updated in response to new risks or deficiencies in earlier ones.
Read those four as a service catalogue. Risk assessment, control implementation, control verification, control improvement. An MSP already sells most of that list, just not under POPIA’s name.
Section 19(3) adds the benchmark: “due regard to generally accepted information security practices and procedures”. POPIA names no standard, so ISO 27001, the NIST Cybersecurity Framework and sector rules such as PCI DSS become the yardstick for what counts as reasonable.
Why is POPIA compliance an MSP problem?
POPIA compliance becomes an MSP problem because section 21 pushes the section 19 duty down to anyone who processes personal information on a client’s behalf. Section 21(1) requires a written contract between the responsible party and each operator, ensuring the operator establishes and maintains the section 19 measures.
If you host a client’s mailboxes, run their backups or manage the servers their customer records sit on, you are very likely an operator. Their contract should bind you, and your own subcontractors should be bound in turn.
Dis-Chem shows what a gap in that chain costs. The Regulator issued an enforcement notice in August 2023 after roughly 3.6 million records were accessed through a database managed by an operator. The remedy ordered was written contracts with all operators, compelling them to maintain the same or better section 19 measures.
There’s a commercial side to this too. Most guides on the subject come from law firms, auditors and HR consultancies, and they compress the whole security condition into one line about appropriate technical and organisational measures. Your client finishes the legal work, files the manual, and still has nobody running the controls. That gap is the service you sell, and you can talk to our team about partner enablement if you want it mapped to a vendor stack.
What has the Information Regulator actually enforced?
The Information Regulator’s clearest section 19 action is the Department of Justice and Constitutional Development case, and it reads like a failed managed service. After a security compromise, the Regulator issued an enforcement notice on 9 May 2023 requiring the department to prove within 31 days that it had renewed three things: its Trend anti-virus licence, its SIEM licence and its Intrusion Detection System licence.
The department did not respond. On 3 July 2023 the Regulator issued an infringement notice with a R5 million fine, on the stated basis of failure to comply with the enforcement notice. The matter has since been challenged in court, so treat the fine as issued rather than finally settled.
Look at what triggered it. Three renewals that nobody processed. Licence tracking is the dullest thing an MSP does, and it is the thing this case turned on.
TransUnion is the second lesson. The Regulator found failures in access control and failure-detection controls, unlawful access through compromised credentials and a weak password, and a failure to implement safeguards and security policies the company already had. TransUnion complied with the notice and was not fined.
Which controls answer each section 19 duty?
Each of the four section 19(2) duties maps to something a partner can deliver and to a product line Loophold distributes. No single vendor covers all four, which is why the mapping matters more than the brand.
Identify the risks. Start with a written risk assessment for each client, because the Regulator’s fining factors ask about it by name. No product does this for you. It is an afternoon with the client and a document you can produce on request.
Establish safeguards. The safeguards are the stack itself. SonicWall firewalls at the network edge, Barracuda Email Protection for email security, and immutable backup from Arcserve, Barracuda or Wasabi, so that a stolen administrator password can’t delete the recovery copy. Our guide to cloud backup solutions for MSPs covers the immutability modes.
Regularly verify. Failure detection was one of the TransUnion findings, and verification is the duty clients least often pay for. Managed detection is how a small team proves its controls are working at 03:00. Barracuda Managed XDR and SonicWall’s SonicSentry MXDR both put a 24/7 SOC behind your service, and our managed XDR build-or-buy guide compares how each vendor publishes its response times.
Continually update. Own the renewals. Keep a licence register for every client with a named owner and an expiry date, and patch on a schedule you can evidence. Certified engineers make that easier to stand behind, which is what our vendor training is for.
What is the actual penalty for a section 19 failure?
Breaching section 19 is not itself a criminal offence, and that is the single most common error in South African POPIA commentary. Sections 19 to 22 appear nowhere in the section 107 penalty list.
The enforcement chain runs like this. A security failure exposes the responsible party to an enforcement notice under section 95. Section 103(1) then makes it an offence to fail to comply with that notice. Section 103(1) is in the section 107(a) list, which carries a fine or imprisonment not exceeding 10 years. Only at that point can the Regulator issue an infringement notice with an administrative fine, which under section 109(2)(c) may not exceed R10 million.
So the R10 million attaches to ignoring the Regulator, not to the breach. That explains why TransUnion and Dis-Chem paid nothing while the Department of Justice was fined for silence.
Two of the factors the Regulator must weigh when setting a fine are worth knowing. Section 109(3)(f) asks whether the party could have prevented the contravention. Section 109(3)(g) asks about “any failure to carry out a risk assessment or a failure to operate good policies, procedures and practices to protect personal information.” Both reward the MSP that can hand its client a documented, verified control programme.
NEED THE SECURITY HALF OF POPIA MAPPED TO REAL CONTROLS?
We help South African partners match section 19 obligations to the products that satisfy them.
Start my partner enquiry
How many security compromises are being reported?
The Information Regulator reported in August 2026 that it had received more than 8,000 security compromise notifications in total since POPIA’s enforcement provisions commenced, with more than 1,220 reported since 1 April 2026 alone. It projected the year would exceed 3,000 and described the rate as very alarming.
The trend is steepening. In the 2024/25 financial year the Regulator recorded 2,374 compromises, averaging 198 per month. From April 2025 the rate rose to roughly 284 per month, an increase of about 40%. The Regulator named inadequate security controls, employee negligence, weak passwords and ransomware as the causes.
For a partner, those figures are the demand signal. Every client board that reads them asks its IT provider the same question, and the provider with a section 19 answer keeps the account.
Where should an MSP start?
An MSP should start with section 19(2)(c), the verification duty, because it is the one almost nobody does and the one the Department of Justice case turned on. For every client, check that what you believe is running is running, that its licence is current, and that someone owns the renewal.
Then put the risk assessment from 19(2)(a) in writing. A risk assessment you can’t produce is, for enforcement purposes, one you didn’t do.
After that, check the contract. An operator without a written section 21 agreement leaves both itself and the client exposed, and it takes a page to fix.
Section 19 never finishes. Safeguards must be continually updated in response to new risks, which makes this a state you maintain for a client every month. Recurring obligations suit recurring revenue.
BUILDING A SECURITY PRACTICE AROUND SOUTH AFRICAN COMPLIANCE?
Loophold distributes SonicWall, Barracuda, Arcserve and Wasabi to South African partners, with the training and enablement behind them.
Become a Loophold partner




