POPIA is not optional for enterprise comms

The Protection of Personal Information Act (POPIA) applies to every organisation that processes personal information of South African data subjects — including customer phone numbers, email addresses, and conversation history in your support inbox.

Five non-negotiables when evaluating platforms

1. Data residency

Customer data should be processed and stored in South African data centres. OneDash hosts primary infrastructure in Johannesburg with Cape Town disaster recovery.

2. Encryption

Data in transit (TLS 1.2+) and at rest (AES-256) protects conversation content and contact records.

3. Access controls

Role-based access control (RBAC) with module-level permissions ensures only authorised staff see sensitive customer data. Full audit trails log every action.

4. Data Processing Agreement

Enterprise clients should receive a formal DPA outlining processor obligations, sub-processors, and breach notification procedures.

5. Consent and opt-out

WhatsApp and SMS channels require explicit consent for marketing messages. Your platform should support opt-out tracking and template compliance.

OneDash's compliance posture

  • POPIA and GDPR aligned data processing

  • Multi-tenant isolation with strict account boundaries

  • Meta-certified WhatsApp Business Platform partner

  • Security whitepaper available at onedash.co.za/security

Contact our team for enterprise compliance documentation or book a demo.