ATG Digital Warns SA Business - “POPIA Certified” Has No Legal Standing
Written by: ATG Digital Save to Instapaper
[Johannesburg, 13 May 2026] The Information Regulator has not authorised any certification scheme — businesses relying on third-party “Certified” badges are left exposed to significant legal and financial risk.
ATG Digital, a provider of access control and data compliance solutions for gated environments, has published an alert to South African organisations.
It warns about a growing and potentially costly misconception: that terms like “POPIA Certified” and similar certificates do not confer any legal protection under the Protection of Personal Information Act 4 of 2013 (POPIA).
The Information Regulator of South Africa—the only body empowered to monitor and enforce POPIA compliance—has not created, endorsed, or authorised any certification system.
There is no approved process or official stamp that declares a business “POPIA certified.”
Leading data protection law firm Michalsons has stated publicly on its website that no one can currently provide a valid POPIA certification, as the Act specifies no process for it, and the Information Regulator has not established one.
“The danger is real,” said the ATG Digital compliance team.
“When a business believes it is ‘certified’, it often stops doing the actual work of compliance. Policies go unreviewed. Staff are not trained. No Information Officer is appointed. When the Information Regulator comes knocking—or worse, when a data breach occurs—that certificate offers zero protection.”
Compliance Versus “Certification”
POPIA compliance means an organisation is actively fulfilling what the law requires:
Lawfully collecting personal information
Protecting it appropriately
Giving data subjects control over their information
Governing the entire process responsibly on an ongoing basis
Compliance is demonstrated through policies, practices, people, and conduct—not through a piece of paper.
Red Flags For Businesses
ATG Digital advises organisations to be cautious of the following:
“Guaranteed” certification. No legitimate advisor can promise this.
Official-looking certificates from vendors. A product can be designed with privacy in mind, but a vendor certificate cannot replace an organisation’s own compliance programme.
One-and-done promises. POPIA compliance is ongoing. Any service claiming permanent compliance via a single purchase or training session is not being truthful.
Specific Implications For Gated Access Operators
For businesses operating in the access control space—estates, office parks, and warehousing facilities—the compliance picture is particularly well defined.
The draft Code of Conduct for Gated Access translates POPIA’s conditions for lawful processing into specific, operational requirements for access-controlled environments, covering purpose, data minimisation, retention, and safeguards at the point of capture.
Operators in this sector are not left to interpret broad privacy principles: the Code does that work for them.
The Hallmarks Of Genuine Compliance
POPIA compliance involves real, ongoing work.
ATG Digital recommends organisations focus on the following priority steps:
Appoint and register an Information Officer with the Information Regulator via the eServices Portal (a non-negotiable under Section 55 of POPIA).
Review and update policies, including privacy notices, PAIA manuals, and internal data processing agreements.
Train staff Employees are simultaneously a compliance asset and a compliance risk.
Build an ongoing governance programme with regular gap analyses, policy reviews, and a compliance roadmap that evolves with the business.
Penalties for non-compliance under POPIA include fines of up to R10 million and imprisonment of up to 10 years.
The Information Regulator is not waiting.
Businesses that have mistaken a vendor certificate for compliance need to act now, before a breach or an investigation makes the distinction unavoidable.
ATG Digital actively monitors developments in POPIA legislation and enforcement, engaging directly with its access control and visitor management clients to ensure their compliance keeps pace with the law.
Get new press articles by email
Deescribe Communication provides copywriting services to agencies: Website content: On-page, SEO-ready web content; blog; opinion pieces; FAQs and self-help sections. Press releases, media statements, business articles, and thought leadership pieces. Corporate communications: newsletters and mass mailers. Social Media: Written content for LinkedIn, Facebook, X (Twitter), and Instagram.... Read More
Latest from
- Park Village Auctions Sweeps Top Honours at 2026 SAIA Awards
- ATG Digital Leads Webinar on South Africa’s Draft Gate Access Code
- Estates Warned - POPIA Gated Access Code Targets ‘Clipboard Security’
- Exclusive Books Now Stocks South African Tech Brand PEACHZ
- Workplace Fraud Surge Spurs SA Companies to Modernise Reception
- Matrix Vehicle Tracking Launches FireStop Private Firefighting Service
- SOLD! A Redeeming R34,500,000 Realised in Gupta Saxonwold Matter
- be.UP Cresta Celebrates a Strong First Month – Invites Families for Youth Day Fun
- Must-Have Hydration - Skyglow Is Coming In Hot This Winter
- Professional-Grade Phone Mount Hits the Market for SA’s Delivery Bike Fleets
- Gravity-Defying Fun - be.UP Park Launches At Cresta
The Pulse Latest Articles
- Medical Cannabis In Sa: What Section 21 Means (May 14, 2026)
- Mega Evolution Returns With Chaos Rising (May 14, 2026)
- Setting The Beat Of Water: 125 Years Of Hansgrohe Innovation (May 14, 2026)
- Opinion Piece: Why The Best Leaders Start With Themselves. (May 12, 2026)
- If Ai Is Doing The Work, Should We Still Pay For The Results? (May 11, 2026)
