The POPI Act the Act, section by section, free PAIA Guide ↗
The POPI Act / Sections / Section 19
Section 19

Security measures on integrity and confidentiality of personal information

Chapter 3 · Conditions for Lawful Processing · Condition 7, Security Safeguards

(1) A responsible party must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent, loss of, damage to or unauthorised destruction of personal information; and unlawful access to or processing of personal information.

(2) In order to give effect to subsection (1), the responsible party must take reasonable measures to, (a) identify all reasonably foreseeable internal and external risks to personal information in its possession or under its control; (b) establish and maintain appropriate safeguards against the risks identified; (c) regularly verify that the safeguards are effectively implemented; and (d) ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards.

(3) The responsible party must have due regard to generally accepted information security practices and procedures which may apply to it generally or be required in terms of specific industry or professional rules and regulations.

securityCCTV & biometricscondition 7risk assessmentoperators
Beyond the text

What this means for your estate

  • CCTV footage, biometric access logs, and visitor registers all need “reasonable technical and organisational measures”, an unlocked server room or a shared admin password doesn't meet subsection (2)(b).
  • Subsection (2)(a)-(d) is effectively a mandate for an ongoing risk assessment, not a once-off setup, “continually updated” is doing real work in that sentence.
  • If you use a managing agent or a third-party CCTV/access-control vendor, this obligation doesn't transfer away, it extends to them as your operator (see s.20-21).
Relevant tool

PopiGuard's Task Manager turns s.19's four sub-duties into tracked, deadlined tasks, identify, establish, verify, update.

See PopiGuard for estates →
Frequently asked
What security measures does POPIA actually require? ▾

Section 19 requires “appropriate, reasonable technical and organisational measures”, not a specific product or standard. Subsection (2) breaks this into four ongoing duties: identify risks, establish safeguards, verify they work, and keep updating them.

Is a once-off security setup enough to comply with section 19? ▾

No, subsection (2)(d) specifically requires safeguards to be “continually updated in response to new risks,” so section 19 is framed as an ongoing obligation, not a single project you complete and file away.