Skip to main content

Does Cyber Crucible comply with South Africa's POPIA?

Short answer: Yes. POPIA restricts cross-border transfer unless the destination offers substantively similar protection or the data subject consents. Cyber Crucible minimizes what is processed to begin with, and can be deployed so no transfer occurs.

What the law requires

South Africa's Protection of Personal Information Act (2013) prohibits transferring personal information outside the country without the data subject's consent, or unless the recipient jurisdiction is subject to a law providing substantively similar protection.

What specifically applies here

The "substantively similar protection" test is an assessment you must be able to evidence. Two things make that assessment simpler:

  1. The scope is small. Encryption keys, credentials, session tokens, and file contents are never collected. What remains is behavioural telemetry, pseudonymized where it could identify an individual.
  2. Contractual protections — processing occurs under a written DPA with security, confidentiality, and breach notification terms, extended to any sub-processor.

Or avoid the test entirely

Regional staging keeps processing in South Africa. The air-gapped deployment produces no outbound flow at all, in which case the transfer provisions are simply not engaged — usually a faster path than evidencing adequacy.

Status at time of writing — confirm with local counsel.