TL;DR
- POPIA applies if you hold personal information about customers or staff. Every Johannesburg SME does.
- The Act expects reasonable technical and organisational safeguards. A backup job that has never been restored is hope, not a safeguard.
- Our POPIA checklist already names untested backups as one of the four gaps SMEs most often miss.
- Load-shedding and a single office make “backup on the same server” a Johannesburg-specific failure mode.
- Start with the ungated scorecard or book a free IT audit. This is general guidance, not legal advice.
Johannesburg SMEs usually have something that looks like a backup: a USB disk, a cloud sync, or a vendor tick-box. POPIA still asks whether that something would actually return personal information after a crash, theft, or ransomware event.
The Protection of Personal Information Act 4 of 2013 requires responsible parties to secure personal information with appropriate, reasonable technical and organisational measures. The Information Regulator enforces that duty. This post is not a new legal framework. It is the backup half of the checklist we already publish.
Why do untested backups fail POPIA?
They fail because “we have a backup” is not the same as “we can restore the personal information we hold.”
POPIA does not prescribe a brand of backup software. It does expect you to know what personal information you hold, where it lives, and how you would get it back. If the only copy sits on the same machine, or the last restore was never tried, you do not have a reasonable safeguard. You have a story.
Our plain-English POPIA checklist already lists the four gaps SMEs most often miss: no data inventory, no test-restored backups, ex-employees still holding access, and a privacy policy that does not match reality. This post stays on the second gap.
What does a reasonable backup look like for a Gauteng SME?
It looks like a named inventory, a second location, and a restore you have actually run.
Work these questions at your desk. They match the backup and POPIA rows on the free IT audit checklist:
- What personal information do you back up (customers, staff, invoices, email)?
- Where does the copy live (another building, another cloud tenant, not only the same office)?
- When was a restore last tested, and who can run it if the usual person is away?
- Would load-shedding, fire, or theft of the office take the only copy with it?
If you cannot answer those without guessing, the POPIA gap and the operational gap are the same job.
Why does Johannesburg make this worse?
A single office, one fibre line, and load-shedding will take an on-site-only backup down with the building.
The checklist already asks whether critical gear has UPS or inverter backup, and whether backups live in a second location rather than the same room. That is not a scare statistic. It is the same local constraint we publish for network and continuity work.
If your “IT person” vanished tomorrow, could someone else restore payroll, customer records, and email? If the answer is no, documentation is part of the safeguard, not an extra.
What happens when backups have already failed?
You find out during an incident, when there is no recent restore path.
On a published engagement, AJM Engineering had usable backups that stopped in 2023. Recovery then meant reclaiming Active Directory, SQL Server, and a neglected RAID array over a weekend, then putting backups back on a managed cadence. We are not repeating that as a market-wide percentage. It is one named example of what “we thought we had backups” looks like in Gauteng.
How should you close the gap this month?
Map the data, test one restore, then decide whether you want a second pair of eyes.
- List the personal information systems (email, payroll, CRM, accounting, file shares).
- Confirm a copy exists off the same building or the same tenant.
- Restore one file or one mailbox and write down the date.
- Remove access for people who have left. Stale accounts sit next to backup failure on the POPIA list.
- Keep the privacy policy aligned with what you actually do.
Need a structured pass? Download the IT Audit Scorecard (PDF), then book a free IT audit. The free audit is a no-obligation triage and written summary. It is not the paid Detailed IT Audit Report (R2,500).
If the reds are security and compliance, see cybersecurity and POPIA support. If you want ongoing monitoring and backup discipline without a lock-in, start on managed IT services.