POPIA
Security and Operator

POPIA POPIASA-5: Security Safeguards, Encryption, Access Control, Operator Obligations

Per POPIA Sections 19-22: security safeguards + operator obligations + breach. Requirements include (a) implement Security Safeguards (Section 19) - responsible party must secure personal information against loss + damage + unauthorised destruction + access + by taking appropriate technical + organisational measures + (b) maintain Operator Obligations (Section 20-21) - operators process personal information only with knowledge or authorisation of responsible party + maintain confidentiality + secure processing + (c) implement encryption + access control + activity logging where appropriate + (d) implement Security Compromise Notification (Section 22) - notify Information Regulator + affected data subjects of security compromise without undue delay + (e) integrate with broader information security programme + (f) maintain operator due diligence.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.