Personal Privacy Principles

13 foundational principles to guide your personal privacy practices

These principles underpin the Personal Privacy Score self-assessment. They are drawn from the requirements of the Protection of Personal Information Act (POPIA) and best-practice data protection standards. Understanding and applying these principles in your daily life will help you protect your personal information and respect the privacy of others.

01
Collect Only Necessary Data
Only collect and retain personal information that is genuinely necessary for a specific, defined purpose. Regularly review what you hold and securely delete anything that is no longer needed. Unnecessary data is unnecessary risk.
02
Ensure Data Accuracy and Security
Verify that the personal information you hold is accurate, complete, and up to date. Store it securely — using encryption, access controls, and locked storage where appropriate — to prevent unauthorised access or accidental disclosure.
03
Use Strong Security Measures
Protect your accounts and devices with strong, unique passwords, full-disk encryption, and multi-factor authentication (MFA). These three measures alone eliminate the majority of common attack vectors used to compromise personal information.
04
Update Privacy Settings and Software Regularly
Periodically review and tighten the privacy settings on your online accounts, devices, and applications. Ensure your operating systems and apps receive security updates promptly — patches address known vulnerabilities that attackers actively exploit.
05
Be Cautious with Personal Information Online
Avoid sharing sensitive personal information on public forums, comment sections, and social media. Before posting anything about another person, consider whether you have their consent — POPIA requires it. Once information is online, it is extremely difficult to fully retract.
06
Avoid Unsecured Transactions and Downloads
Never conduct sensitive transactions — banking, accessing work systems, submitting personal information — over public Wi-Fi without a VPN. Only download apps and software from official, verified sources. Unverified downloads are a leading cause of malware infections and data theft.
07
Obtain Consent Before Sharing Others' Data
Always obtain explicit, informed consent before sharing another person's personal information with third parties. Under POPIA, consent must be specific — the person must know what information is being shared, with whom, and for what purpose. In the event of a data breach, notify affected individuals and the Information Regulator promptly.
08
Know and Exercise Your Privacy Rights
Under POPIA, you have the right to access, correct, and object to the processing of your personal information. If an organisation misuses your data, you can lodge a complaint with the Information Regulator at inforegulator.org.za. Knowing your rights is the first step to enforcing them.
09
Use Reliable Security Software and Back Up Your Data
Install reputable antivirus and anti-malware software on all your devices and keep it updated. Maintain regular backups of important personal data using both cloud and physical storage. A current backup is the most effective protection against ransomware and device loss.
10
Verify Information Before Sharing It
Confirm the accuracy of information before sharing it online. Misinformation containing personal details about real people can cause serious harm — reputational, financial, and physical. Use credible sources and fact-checking tools such as Africa Check before sharing anything that involves another person's information.
11
Avoid Unsecured Channels for Data Sharing
Never share personal information — ID numbers, banking details, passwords, medical records — via standard SMS or unencrypted email. Use end-to-end encrypted messaging platforms, password-protected documents, or secure file transfer services. The channel matters as much as the content.
12
Be Vigilant Against Phishing Attacks
Be alert to emails, SMS messages, and websites that impersonate trusted institutions and request personal information. Verify unexpected requests through official channels before clicking any link or providing any details. South Africa has one of the highest rates of phishing attacks in Africa — vigilance is essential.
13
Stay Informed About Privacy Laws and Regulations
Keep up to date with POPIA and related privacy legislation. The Information Regulator publishes guidance, enforcement notices, and regulatory updates at inforegulator.org.za. Understanding the law empowers you to hold organisations accountable and to make informed decisions about your own personal data.