Compliance · · 3 min read
POPIA checks raise pressure on South African SME suppliers
South African SMEs are facing tougher POPIA scrutiny as customers demand stronger supply-chain security and the Information Regulator steps up compliance monitoring.
South African small and medium-sized businesses that process personal information are entering a more demanding phase of POPIA enforcement, according to reporting by cbn.co.za. The Information Regulator has moved beyond general preparation and guidance, contacting companies directly and asking them to demonstrate that they comply with the law.
The change matters beyond the regulator’s offices. Large organisations are increasingly treating the smaller companies in their supply chains as part of their own security perimeter. SMEs that provide software, services or other support may therefore need to show both that they can protect customer information and that they have the agreements and records required under POPIA.
The pressure is growing as attackers target trusted suppliers rather than trying to penetrate well-defended companies directly. A supplier’s update mechanism, remote-access system, email account or invoice can provide a route into a larger organisation because those connections are already accepted by the customer’s systems.
Enforcement and breach reports rise
The Information Regulator is now in its tenth year of operation, while POPIA’s enforcement provisions have been in effect for five years. During that period, reported security compromises rose from 202 in 2021/2022 to 2,898 in 2025/2026. More than 1,200 reports were received during the first half of the latter year alone.
The figures are being recorded against a broader increase in supply-chain attacks. Verizon’s 2026 Data Breach Investigations Report found that third-party involvement in breaches had risen by 60% compared with the previous year, appearing in 48% of all breaches. The World Economic Forum, meanwhile, found that 65% of large organisations identify third-party and supply-chain exposure as their main resilience challenge.
South African examples cited in the report include Satrix, Bidvest Bank and EasyEquities, where data exposure has been linked to third-party service providers. These incidents illustrate why a company can face consequences from weaknesses outside its own core infrastructure.
Chris Ogden, RubiBlue’s chief executive and founder, said attackers could use trusted supplier connections to gain access instead of confronting an enterprise’s main defences. The company’s assessment is that ordinary business tools and relationships can become attack routes when they are not adequately controlled.
For an SME, this creates a commercial risk as well as a technical one. Larger customers are placing security requirements in contracts, requesting data-processing agreements and asking prospective suppliers for evidence of compliance before awarding work. A business that cannot provide that evidence may find it harder to win or retain a place in an established supply chain.
Six steps for smaller businesses
The report identifies six areas where SMEs can strengthen their position and create evidence of responsible data handling:
- Create a data map. Businesses should identify the personal information received from clients, where it is stored and which people or systems can access it.
- Set out responsibilities in writing. Data-processing agreements should cover each client and subcontractor relationship, so the duties of every party are understood.
- Secure common access points. This includes applying software updates, managing remote-access tools and requiring multi-factor authentication for accounts that handle client information.
- Limit access and protect backups. Sensitive systems should be available only to authorised users, while at least one backup should remain inaccessible through supplier credentials.
- Test for weaknesses. Regular vulnerability scans and penetration tests can identify problems that need to be corrected before they are exploited.
- Keep proof and prepare for incidents. Records should explain how information is protected, retained and deleted. Businesses also need a plan for responding to and reporting breaches.
These measures are intended to make security demonstrable rather than dependent on assurances. Documentation can help an SME respond when a customer asks how information is managed, or when the regulator requests proof of compliance.
Security becomes part of doing business
RubiBlue says it applies such controls to platforms handling sensitive policyholder information for more than 1,000 funeral parlours and reaching more than 12 million policyholders. It also offers services to SME suppliers, including vulnerability reporting, penetration testing, patch management and preventative monitoring.
The article does not suggest that any system can be made completely safe. Its central warning is that third-party providers need to follow sound security practices and build information protection into their internal culture. That responsibility is becoming harder to separate from commercial survival as customers scrutinise the suppliers connected to their data.
For SMEs, preparing before a questionnaire, contract review or regulatory enquiry arrives may be less disruptive than trying to establish controls after a breach. As POPIA monitoring becomes more active and supply-chain attacks become more prominent, the ability to show how information is protected is increasingly becoming a condition of participation in the market.