Published: 3 September 2026 | By AOLC
South African businesses have embraced cloud storage at pace. Microsoft OneDrive, SharePoint, Google Drive, Dropbox, AWS S3 — these services make file sharing and collaboration faster and cheaper than ever. But here is a question too few IT managers are asking: does moving your data to the cloud relieve you of your POPIA obligations?
The short answer is no. The Protection of Personal Information Act (POPIA) applies to every byte of personal information your organisation processes, regardless of whether that data sits on a server in your Johannesburg office or in a Microsoft data centre in Dublin. If you collect, store, share, or use personal information — and almost every business does — POPIA applies. Cloud changes the tooling, not the liability.
POPIA does not distinguish between on-premises and cloud storage. Wherever your data lives, your duty of care as the responsible party travels with it — and the maximum administrative penalty for a serious breach is R10 million. Criminal liability can follow for wilful non-compliance.
Under POPIA, personal information is any data that can identify a living natural person — directly or indirectly. Where applicable, the Act also covers identifiable existing juristic persons (companies and other legal entities). This is a broad definition, and it almost certainly covers data your business already stores in the cloud:
Maximum administrative fine for a serious POPIA violation — and criminal liability can follow for wilful non-compliance. Cloud storage does not reduce this exposure.
POPIA draws a clear line between two roles. Understanding this distinction is the foundation of cloud compliance:
The Responsible Party is the organisation that determines the purpose and means of processing personal information — that is your business. If you collect customer data and store it in Google Drive, you are the responsible party. POPIA places the primary duty of care on you.
The Operator is any third party that processes personal information on your behalf — that is your cloud provider. Microsoft, Google, Amazon, Dropbox, and similar services are operators under POPIA. They process your data, but they do so under your instruction and on your behalf.
This matters because you remain liable for what your operator does with your data. If Microsoft suffers a breach that exposes your customer records, you — the responsible party — have reporting obligations to the Information Regulator and potentially to your affected customers. Your cloud provider's terms of service do not transfer that liability to them.
Tip
Before you sign up to any new cloud service that will process personal information, confirm the provider offers a data processing agreement (DPA) that references POPIA or GDPR compliance. Major providers like Microsoft and Google offer these. Smaller local SaaS vendors often do not — and that is a red flag.
Section 21 of POPIA requires you to have a written agreement with every operator that processes personal information on your behalf. This is not optional. If you are using a cloud service without a formal data processing agreement, you are already non-compliant.
A compliant operator agreement must include:
The good news: major cloud providers like Microsoft, Google, and Amazon all offer compliant data processing agreements as standard. The challenge is smaller, local, or niche SaaS products that have not yet aligned to POPIA requirements. These need special attention.
Most large cloud providers store data outside South Africa. Microsoft 365 data may sit in Netherlands, Ireland, or the United States. Google Workspace may route through multiple international jurisdictions. This triggers Section 72 of POPIA, which restricts cross-border transfers of personal information.
Under Section 72, you may only transfer personal information to a foreign country if:
Most South African businesses using major cloud platforms store data outside the country without realising it — and many have never assessed their cross-border transfer obligations under Section 72. For businesses using Microsoft 365 or Google Workspace, the providers' standard DPAs typically include Standard Contractual Clauses (SCCs) designed to meet this requirement — but you should verify that those clauses apply to your specific data flows and provide protection substantially equivalent to POPIA. The greater risk lies with smaller or niche cloud services that have not aligned to these requirements at all, or where businesses have never reviewed the terms.
POPIA requires that personal information be protected against risks such as loss, damage, or unauthorised destruction, and against unlawful access or processing. For cloud environments, this means your IT governance practices must include:
Tip
Microsoft 365 includes the Microsoft Compliance Manager tool, which maps your 365 settings against POPIA and other frameworks and gives you a compliance score. It is not a legal opinion, but it is a practical starting point for identifying gaps in your cloud configuration.
Use this checklist to assess your current cloud compliance posture. If you cannot answer "yes" to each item, you have work to do before the Information Regulator comes knocking.
Cloud platforms can be configured to be POPIA-compliant — but they do not come that way out of the box. Default settings on Microsoft 365, Google Workspace, and most SaaS platforms are designed for convenience, not compliance. Someone with IT and legal knowledge needs to configure them deliberately.
If you are uncertain about your cloud compliance posture, the safest first step is a structured assessment with an IT provider who understands both the technical landscape and the POPIA framework. AOLC's cloud and security services include POPIA readiness reviews for South African businesses — we assess your cloud configuration against the Act's requirements and give you a prioritised remediation plan.
Not sure if your cloud environment is POPIA-compliant? We will review your setup and give you a clear, actionable remediation plan.
Book a Security Assessment