Menu

POPIA Section 19: Mapping Security Safeguards to ISO 27001

POPIA Section 19: Mapping Security Safeguards to ISO 27001

POPIA Section 19 requires a responsible party to protect the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures. The section does not name ISO 27001, but each of its duties lines up with a specific part of ISO 27001:2022. Risk identification maps to clause 6.1.2, safeguards map to the Annex A controls, verification maps to clauses 9.1 to 9.3, and continual updating maps to clause 10.

The mapping covers information security only. ISO 27001 does not address consent, purpose specification or data subject rights, and POPIA does not treat certification as automatic proof of compliance.

Strengthen Information Security With ISO/IEC 27001 Certification. Build Stakeholder Confidence With INTERCERT.

What Is POPIA Section 19 on Information Security Safeguards

Purpose of Section 19 Within POPIA

Section 19 sits under Condition 7 (Security Safeguards) in Chapter 3 of the Protection of Personal Information Act. It sets the baseline duty to keep personal information secure while it is held or processed. Other conditions govern why and how information may be collected and used. Section 19 governs how well it is protected.

Responsible Parties and Operators Covered by Section 19

The Section 19 duty falls on the responsible party, which is the public or private body that decides the purpose and means of processing. Operators process personal information on behalf of a responsible party. Their obligations arise mainly through Sections 20 and 21. These require processing only with authority, a written contract, security measures that match the responsible party’s duties, and prompt notice of any suspected compromise.

A responsible party cannot pass its Section 19 duty to a vendor by contract alone. It remains accountable for the information it hands over.

Why Security Safeguards Matter for South African Organisations

The Information Regulator enforces POPIA. Section 22 requires notification of the Regulator and affected data subjects after a security compromise. Administrative fines of up to R10 million can apply under Section 109, and data subjects can pursue civil claims for damages under Section 99.

Procurement teams across South Africa and the wider African market also ask for proof of security controls before they award contracts. A recognised framework gives that proof a clear structure.

POPIA Section 19 Information Security Safeguards Explained

Integrity and Confidentiality of Personal Information

Section 19(1) requires measures that prevent two outcomes. The first is loss of, damage to or unauthorised destruction of personal information. The second is unlawful access to or unlawful processing of it. These correspond to availability and integrity on one side and confidentiality on the other, which is the same triad that ISO 27001 is built around.

Reasonable Technical and Organisational Measures

The Act does not list specific controls. Reasonableness is judged against the risk, the sensitivity of the information and accepted industry practice. Technical measures include encryption and access restrictions. Organisational measures include policies, training and supplier contracts. A credible position needs both types.

Identifying Reasonably Foreseeable Internal and External Risks

Section 19(2)(a) requires the responsible party to identify foreseeable internal and external risks to the personal information it controls. Internal risks include excessive access rights and careless handling by staff. External risks include ransomware, phishing and supplier failure. The risk picture must be recorded and kept current.

Establishing and Maintaining Safeguards Against Identified Risks

Section 19(2)(b) ties safeguards directly to the risks found. A control chosen without reference to an identified risk is hard to defend. Safeguards must also be maintained, so a control that exists on paper but has lapsed in daily operation does not satisfy the section.

Regular Verification and Updating of Safeguards

Sections 19(2)(c) and 19(2)(d) require regular verification that safeguards work, and continual updating when new risks or deficiencies appear. A one-time review is not enough. The organisation needs a repeatable cycle that produces records.

Following Generally Accepted Information Security Practices

Section 19(3) requires due regard to generally accepted information security practices and procedures, including any industry or professional rules that apply. This is where ISO 27001 enters the picture. It is the most widely recognised information security management standard, which makes it a credible reference point for what “generally accepted” means in practice.

How ISO 27001 Relates to POPIA Section 19

ISO 27001 as a Recognised Information Security Framework

ISO 27001 sets out requirements for an information security management system (ISMS). It is risk-based, which suits Section 19 well because the Act also ties safeguards to identified risks. Annex A control 5.31 requires organisations to identify applicable legal and regulatory requirements, so POPIA belongs in the ISMS legal register.

Overview of ISO 27001 Annex A Controls

ISO 27001:2022 Annex A contains 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. Annex A is a reference set. The organisation selects the controls that treat its own risks and records its decisions in the Statement of Applicability. It may also add controls that Annex A does not list.

Where ISO 27001 Aligns with POPIA and Where It Does Not

The two frameworks align on risk assessment, access control, supplier oversight, incident management, monitoring and continual improvement. They diverge on lawful processing grounds, consent, purpose specification, data subject participation, cross-border transfer conditions and information officer duties. These sit in other POPIA conditions, and Annex A does not cover them. Organisations that need a privacy-specific layer often look at ISO/IEC 27701, which extends the ISMS to privacy information management.

POPIA Section 19 ISO 27001 Mapping

Mapping Approach and Control Alignment Method

A reliable POPIA Section 19 ISO 27001 mapping follows three steps. First, break Section 19 into its separate duties. Second, match each duty to the relevant ISO 27001 clause and Annex A control. Third, confirm that the control operates on personal information specifically and that evidence exists.

A mapping that stops at step two shows intent but not compliance.

Risk Identification and Assessment Mapped to ISO 27001 Requirements

Section 19(2)(a) maps to clauses 4.1 and 4.2, which require the organisation to understand its context and interested parties, including regulators and data subjects. It also maps to clause 6.1.2, which requires a defined risk assessment process. Controls 5.7 (threat intelligence), 5.9 (inventory of information and associated assets) and 5.12 (classification of information) feed that process.

The asset inventory should show where personal information sits. Without that, the risk assessment will miss it.

Safeguard Establishment Mapped to Annex A Controls

Section 19(2)(b) maps to clause 6.1.3, which covers risk treatment, the Statement of Applicability and the risk treatment plan. The selected Annex A controls are the safeguards. Control 5.34 (privacy and protection of PII) is the most direct Annex A reference to personal information.

Verification and Continual Improvement Mapped to ISO 27001

Section 19(2)(c) maps to clause 9.1 (monitoring and measurement), clause 9.2 (audits the organisation runs on its own ISMS) and clause 9.3 (management review). Controls 5.35 (independent review of information security) and 5.36 (compliance with policies, rules and standards) add further checks.

Section 19(2)(d) maps to clause 10.1 (continual improvement) and clause 10.2 (nonconformity and corrective action).

Mapping POPIA Security Safeguards to ISO 27001 Controls

Organisational Controls

Organisational controls carry most of the governance weight. Relevant references include 5.1 (policies), 5.2 (roles and responsibilities), 5.9, 5.12, 5.19 to 5.22 (suppliers), 5.24 to 5.28 (incidents), 5.31 (legal requirements) and 5.34 (PII protection). Together they establish accountability, which Section 19 assumes but does not spell out.

People Controls

People controls address the internal risks named in Section 19(2)(a). They include 6.1 (screening), 6.2 (terms and conditions of employment), 6.3 (awareness, education and training), 6.6 (confidentiality agreements), 6.7 (remote working) and 6.8 (event reporting). Staff who handle personal information need training that refers to POPIA obligations, not generic security awareness alone.

Physical Controls

Physical controls protect against loss, damage and unauthorised access to records and equipment. Relevant references include 7.1 (physical security perimeters), 7.2 (physical entry), 7.3 (securing offices), 7.5 (protecting against physical and environmental threats), 7.7 (clear desk and clear screen), 7.10 (storage media) and 7.14 (secure disposal or re-use of equipment).

Technological Controls

Technological controls deliver most of the technical measures. Key references include 8.2 (privileged access rights), 8.3 (information access restriction), 8.5 (secure authentication), 8.7 (protection against malware), 8.8 (management of technical vulnerabilities), 8.12 (data leakage prevention), 8.13 (information backup), 8.15 (logging), 8.16 (monitoring activities), 8.20 (network security) and 8.24 (use of cryptography).

ISO 27001 Annex A Controls for POPIA Compliance

Access Control and Authentication

Unlawful access under Section 19(1)(b) is addressed by controls 5.15 (access control), 5.16 (identity management), 5.17 (authentication information), 5.18 (access rights), 8.2, 8.3 and 8.5. Access to personal information should follow least privilege, with regular reviews of who holds rights. Multi-factor authentication on systems that hold personal information is a widely accepted practice.

Cryptography and Data Protection

Control 8.24 requires rules for the use of cryptography, including key management. POPIA does not name encryption, but protecting personal information at rest and in transit is generally accepted practice and is hard to omit for sensitive data. Controls 8.11 (data masking), 8.12 (data leakage prevention) and 5.14 (information transfer) add further protection.

Logging, Monitoring, and Vulnerability Management

Section 19(2)(c) requires verification that safeguards work. Controls 8.15 (logging), 8.16 (monitoring activities) and 8.8 (management of technical vulnerabilities) produce the evidence. Logs showing who accessed personal information, together with records of vulnerability scans and penetration tests, are strong proof that verification takes place.

Supplier and Operator Relationships

Controls 5.19 to 5.22 cover information security in supplier relationships, supplier agreements, the ICT supply chain and monitoring of supplier services. Agreements with operators should reflect the written contract requirement in Section 21. Monitoring should run throughout the contract, not stop after onboarding.

Information Security Incident Management

Controls 5.24 to 5.28 cover incident planning, assessment, response, learning and evidence collection, and control 6.8 covers event reporting. ISO 27001 does not set a deadline or name who must be told. Section 22 requires notification of the Regulator and data subjects as soon as reasonably possible, so the incident procedure needs a POPIA notification step added.

Secure Disposal and Retention of Personal Information

Section 14 limits how long records may be kept and requires destruction, deletion or de-identification once retention is no longer authorised. Controls 8.10 (information deletion), 7.10, 7.14 and 5.33 (protection of records) address the technical side. The retention periods themselves must come from the organisation’s POPIA analysis, not from Annex A.

POPIA Security Safeguards and ISO 27001 Annex A Mapping

Section 19 Requirement to Annex A Control Reference

Section 19(1)(a) requires measures that prevent loss of, damage to or unauthorised destruction of personal information. The matching ISO 27001:2022 references are control 5.33 (protection of records), 7.5 (protecting against physical and environmental threats), 8.7 (protection against malware), 8.13 (information backup) and 8.14 (redundancy of information processing facilities).

Section 19(1)(b) requires measures that prevent unlawful access to or processing of personal information. This maps to controls 5.15 to 5.18, 8.2, 8.3, 8.5, 8.12, 8.15 and 8.24.

Section 19(2)(a) requires identification of reasonably foreseeable internal and external risks. The relevant references are clauses 4.1, 4.2 and 6.1.2, with controls 5.7, 5.9, 5.12 and 5.34.

Section 19(2)(b) requires safeguards that are established and maintained against the risks identified. This maps to clause 6.1.3, the Statement of Applicability and the Annex A controls selected from the four themes. The risk treatment plan shows how each safeguard links back to an identified risk.

Section 19(2)(c) requires regular verification that safeguards work. The matching references are clauses 9.1 to 9.3 and controls 5.35, 5.36, 8.8 and 8.16.

Section 19(2)(d) requires safeguards to be updated as risks and deficiencies emerge. This maps to clauses 10.1 and 10.2, with controls 5.7 and 5.27 (learning from information security incidents) feeding the updates.

Section 19(3) requires due regard to generally accepted information security practices. ISO 27001 serves as the recognised framework for this duty, and controls 5.1 and 5.31 keep POPIA visible within the ISMS.

Two related sections also affect the mapping. Section 21 requires a written contract and security measures for operators, which aligns with controls 5.19 to 5.22. Section 22 requires notification of security compromises, which aligns with controls 5.24 to 5.28 and 6.8, with a POPIA notification step added to the procedure.

These references show typical alignment, not a fixed one-to-one equivalence. Control selection should always be checked against the organisation’s own risk assessment and Statement of Applicability.

Evidence of Compliance and Independent Assurance

Demonstrating Section 19 Safeguards Through ISO 27001 Certification

An ISO 27001 certificate shows that an independent body has audited the ISMS against the standard. The risk assessment, Statement of Applicability, monitoring records and corrective action records give the organisation a ready body of evidence for the Section 19(2) duties.

Role of Accredited Certification Bodies in Assurance

A certification body audits the ISMS in two stages, then runs annual surveillance audits and a recertification audit every three years. This cycle keeps verification active and gives regulators, customers and boards an impartial view.

INTERCERT is a globally accredited certification and assurance organisation serving 10,000+ clients across 28+ countries. As a certification body, INTERCERT audits an ISMS against the standard. It does not design or build it, which keeps the assurance impartial.

Limits of ISO 27001 Certification as Proof of POPIA Compliance

A certificate does not confirm POPIA compliance on its own. The certified scope may exclude systems that hold personal information, and controls may be excluded in the Statement of Applicability. The audit also does not test lawful processing grounds, consent or data subject rights. Only the Information Regulator determines compliance with POPIA.

Common Mapping Gaps Between POPIA Section 19 and ISO 27001

Controls Not Covering Personal Information Specifically

Many ISMS controls protect information in general. If the asset inventory and risk assessment do not tag personal information, the controls may not be tuned to it. The classification scheme should include a clear personal information category.

Operator and Third-Party Oversight Gaps

Supplier agreements often contain general security clauses but omit the Section 21 requirements and the duty to notify the responsible party of a compromise. Oversight also tends to weaken after onboarding, so the supplier review cycle should be tested.

Incomplete Records of Safeguard Verification

Section 19(2)(c) expects regular verification. Missing records of access reviews, vulnerability scans, restore tests and management reviews make the claim hard to prove, even when the work was carried out.

Protect Business Information With ISO/IEC 27001 Certification. Demonstrate Your Security Commitment With INTERCERT.

POPIA Section 19 and ISO 27001 Alignment Checklist

Start with scope and legal requirements. POPIA should appear in the legal and regulatory register under control 5.31, and the ISMS scope should cover every system and process that holds personal information. The asset inventory and classification scheme should identify personal information clearly.

Next, check the risk work. The risk assessment should name internal and external risks to personal information, and the Statement of Applicability should record which Annex A controls treat those risks.

Then review third parties and incidents. Supplier and operator agreements should reflect Section 21 requirements. The incident procedure should include notification of the Regulator and data subjects under Section 22. Retention and deletion rules should follow Section 14.

Finally, confirm that evidence exists. Records of access reviews, monitoring and management review should be retained, and corrective actions should be tracked and closed under clause 10.2.

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved