POPIA is not optional for enterprise comms
The Protection of Personal Information Act (POPIA) applies to every organisation that processes personal information of South African data subjects — including customer phone numbers, email addresses, and conversation history in your support inbox.
Five non-negotiables when evaluating platforms
1. Data residency
Customer data should be processed and stored in South African data centres. OneDash hosts primary infrastructure in Johannesburg with Cape Town disaster recovery.
2. Encryption
Data in transit (TLS 1.2+) and at rest (AES-256) protects conversation content and contact records.
3. Access controls
Role-based access control (RBAC) with module-level permissions ensures only authorised staff see sensitive customer data. Full audit trails log every action.
4. Data Processing Agreement
Enterprise clients should receive a formal DPA outlining processor obligations, sub-processors, and breach notification procedures.
5. Consent and opt-out
WhatsApp and SMS channels require explicit consent for marketing messages. Your platform should support opt-out tracking and template compliance.
OneDash's compliance posture
POPIA and GDPR aligned data processing
Multi-tenant isolation with strict account boundaries
Meta-certified WhatsApp Business Platform partner
Security whitepaper available at onedash.co.za/security
Contact our team for enterprise compliance documentation or book a demo.