Skip to content
NewHost
Menu

What Makes Hosting POPIA Compliant? A Guide for SA Businesses

POPIA compliant hosting explained - operator agreements, section 19 security, server location, access control and backups, plus the questions to ask any host.

By NewHost team · · 6 min read

There is no official "POPIA-compliant hosting" certificate. The Protection of Personal Information Act 4 of 2013 places duties on you, the responsible party, and on your host as your operator. Hosting supports compliance when the host signs up to operator obligations in writing, secures the platform to a reasonable standard, controls who can access your data and tells you promptly if something goes wrong. This guide explains each of those and gives you a checklist to take to any provider.

Your role and your host's role

Under POPIA, the responsible party decides why and how personal information is processed. That is you: the business whose website collects enquiries, orders or customer accounts. A hosting company that stores and serves that data on your behalf, under a contract, is an operator.

The Act splits the work like this:

  • You remain accountable for meeting all eight conditions for lawful processing, including collecting only what you need, telling people why, and letting them access or correct their information.
  • Your host, as operator, must process the information only with your knowledge or authorisation, treat it as confidential (section 20) and maintain the security measures required by section 19.
  • Both of you need a written contract that requires those security measures (section 21).

This is why the marketing phrase "POPIA-compliant hosting" can mislead. A host can be a good operator, but it cannot make your contact form, your mailing list or your staff processes compliant.

1. A written operator agreement (section 21)

Section 21 requires the responsible party to ensure, by written contract, that the operator establishes and maintains the section 19 security measures. It also requires the operator to notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

Look for this in your host's terms of service, privacy policy or a separate data processing agreement. It should cover:

  • that the host processes your data only to provide the service
  • confidentiality obligations for its staff
  • the security measures it maintains
  • prompt notification of security compromises
  • what happens to your data when you cancel
  • which sub-processors (for example, a domain registrar or payment gateway) are involved

At NewHost, we act as the customer's operator for hosted content, and our privacy policy sets out how we handle it.

2. Reasonable security (section 19)

Section 19 requires "appropriate, reasonable technical and organisational measures" to prevent loss of, damage to and unlawful access to personal information. It does not list specific products. What is reasonable depends on the sensitivity of the data and on generally accepted practice. For hosting, that typically includes:

Area What to look for
Encryption in transit Free SSL on every site, automatic renewal
Account security Two-factor sign-in on the hosting dashboard, alerts on password changes
Secrets Encrypted environment variables rather than credentials in code
Isolation Apps and databases separated between customers
Patching Operating system and platform updates handled by the host
Backups Automatic backups with a known retention period, and a restore process
Staff access Support access limited to what is needed to help you

On NewHost, SSL is free via Let's Encrypt, environment variables are encrypted, backups run weekly or daily depending on your plan, and you can switch on two-factor sign-in with an authenticator app. See two-factor authentication with an authenticator app for why that matters.

A common belief is that POPIA requires data to be stored in South Africa. It does not. POPIA has no general data-localisation rule. What it does have is section 72, which controls transfers of personal information to a third party in a foreign country. Such a transfer is allowed if, among other grounds, the recipient is bound by law, binding corporate rules or a binding agreement providing an adequate level of protection, or the data subject consents, or the transfer is necessary for a contract with the data subject.

So hosting overseas can be lawful. Hosting in South Africa simply removes one layer of analysis for your main data store: you don't have to assess a foreign recipient's protections for that part of your processing. Our article on data residency in South Africa explains this in more detail. Note that sector rules (for example, in financial services) or client contracts may impose location requirements separately from POPIA.

NewHost's servers are in Johannesburg.

4. Access control on your side

Most real-world data leaks come from weak access, not from exotic attacks: a shared password, a former employee still on the account, an agency that never handed back credentials. Good hosting makes it easy to do this properly:

  • individual logins instead of one shared account
  • roles, so the bookkeeper sees invoices but not the database
  • the ability to remove a person immediately

NewHost's Business and Agency plans include team seats with admin, developer, billing and viewer roles.

5. Backups, retention and deletion

Backups are part of section 19 (they protect against loss) but they also hold copies of personal information, so they need a known lifespan. Ask:

  • How often are backups taken and how long are they kept?
  • Where are they stored?
  • What happens to backups after I cancel?

On NewHost, the Starter plan keeps weekly backups for 4 weeks, Developer keeps daily backups for 7 days, and Business and Agency keep daily backups for 30 days. You can also take on-demand backups. Read a website backup strategy that works for how to layer your own copies on top.

Questions to ask any hosting provider

  1. Do you act as an operator under POPIA, and where is that written down?
  2. Will you notify me immediately of a suspected security compromise?
  3. Where are my website, database and backups physically stored?
  4. Which third parties process my data as part of your service?
  5. Is two-factor sign-in available for the control panel?
  6. How long are backups kept, and what happens to my data when I leave?
  7. Who on your team can access my data, and when?

A provider that answers these clearly is showing you the kind of transparency POPIA expects.

Frequently asked questions

Is any hosting provider officially POPIA certified?

The Information Regulator does not certify hosting providers as POPIA compliant. Treat claims of "certification" with care and focus on the operator agreement and actual security measures.

Does my website need to be hosted in South Africa for POPIA?

No. POPIA has no general requirement to keep data in South Africa. Transfers abroad must meet section 72, and some contracts or industry regulations may add location rules, so check those separately.

What must my host do if there is a breach?

Under section 21, an operator must notify the responsible party immediately when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. You, as responsible party, then notify the Information Regulator and affected people under section 22.

Do I still need a privacy policy if my host is compliant?

Yes. Openness (sections 17-18) is your obligation. Your website needs its own privacy notice explaining what you collect, why and who you share it with. For your specific circumstances, consider getting advice from a privacy professional.

If you're looking for a South African host that acts as your operator, keeps data in Johannesburg and offers two-factor sign-in, team roles and automatic backups, compare our plans or contact us with your questions.

Related guides

Ready to launch on NewHost?

Choose a plan and go live today, or tell us what you need and we'll recommend the right setup.