Most conversations about staying safe online focus on what you should do — stronger passwords, fewer clicks on suspicious links. POPIA (the Protection of Personal Information Act) is different: it's about what companies are legally required to do with your information, and what you're entitled to ask of them.
The basic idea
POPIA says any organisation that collects your personal information — your bank, your medical aid, the retailer you bought a fridge from — has to handle it responsibly: collect only what it actually needs, use it only for the purpose you agreed to, keep it secure, and get rid of it once there's no longer a legitimate reason to hold onto it. It's enforced by the Information Regulator, a body that can investigate complaints and issue penalties.
Rights you actually have
A few of these are worth knowing because they're things you can act on:
- The right to know what's held about you. You can request access to the personal information a company has on file for you.
- The right to correction. If a company has your details wrong, you can ask them to fix it.
- The right to deletion, in many circumstances, once the original purpose for collecting your data no longer applies.
- The right to object to your data being used for direct marketing — this is why "unsubscribe" links and opt-outs exist, and why they're supposed to actually work.
Why this matters for everyday safety
There's a direct link between POPIA and the scam-prevention advice you've probably already heard. A lot of convincing scams work because the scammer has real details about you — your full name, your ID number, your account number — obtained from a data breach at some company that held more of your information than it needed to, for longer than it should have. POPIA exists precisely to reduce how much of that kind of data is sitting around waiting to leak.
What to actually do with this
You don't need to file a formal request every time a company asks for your ID number. But a few habits are worth adopting:
- Notice when a form asks for more than it needs — a competition entry asking for your ID number is a reasonable thing to question.
- If a company you've dealt with suffers a publicised data breach, that's a legitimate moment to request what they held on you and confirm it's been secured or deleted.
- If a company ignores a reasonable request about your data, you can lodge a complaint with the Information Regulator — this is a real, usable option, not just a theoretical one.
The honest limitation
POPIA governs South African organisations; it has no reach over an overseas scam operation or a fake online store registered elsewhere. It won't stop every scam. What it does is reduce the amount of real, exploitable personal data sitting in company databases in the first place — which quietly makes every other precaution on this site more effective, because there's simply less real information available for a scammer to use as convincing "proof" that they know who you are.