3,219 security breach notifications reached the Information Regulator in 2025/26. This is happening five years into full POPIA enforcement, in organisations that have Information Officers, privacy policies, and compliance documentation in place.
“Policies alone do not prevent data breaches. Accountability, ownership, monitoring and continual improvement do.”Muhammad Ali, Managing Director, World Wide Industrial & Engineering Systems
Microsoft 365 contains the tools to meet every one of POPIA’s conditions. The question is whether anyone has configured them. This article is about that question.
What this article covers:
- Why POPIA compliance and POPIA protection are not the same thing
- What POPIA actually requires from your Microsoft 365 environment, condition by condition
- Why deploying Copilot without data governance is a POPIA risk, not just a security one
- What Microsoft’s in-country data processing announcement means for South African organisations
- The POPIA obligations many South African Microsoft environments are currently failing
POPIA and your Microsoft environment
POPIA’s conditions for lawful processing are well known. What is less well understood is how each condition translates into a specific technical control inside Microsoft 365.
| POPIA Condition | What it requires | M365 controls | Status in many tenants |
|---|---|---|---|
| Accountability |
|
|
Audit logging often enabled but not actively monitored or retained for required periods |
| Processing Limitation |
|
Microsoft Entra ID: Conditional Access policies, role-based access control, Privileged Identity Management | Conditional Access is often partially configured. PIM is rarely deployed for non-admin roles. |
| Purpose Specification | Data collected only for a specific, defined purpose and not retained longer than necessary | Microsoft Purview: retention labels and policies, data lifecycle management, auto-deletion rules | Retention policies rarely aligned to POPIA data categories. Many organisations have no auto-deletion in place. |
| Security Safeguards | “Appropriate and reasonable” technical and organisational measures to protect personal information | Microsoft Defender for Office 365, MFA via Entra ID, Sensitivity labels via Purview, Secure Score as ongoing measurement | MFA adoption is improving, but sensitivity labelling and Defender are largely unconfigured in mid-market tenants |
| Data Subject Participation | Ability to fulfil data subject access, correction, and deletion requests within a reasonable timeframe | Microsoft Purview Subject Rights Requests: automated workflow for data subject request fulfilment | Most organisations handle data subject requests manually with no defined SLA |
| Breach Notification | Notify the Information Regulator and affected data subjects as soon as reasonably possible after a breach |
|
Deployed in a minority of mid-market tenants. Most organisations cannot detect a breach, let alone notify quickly. |
The question nobody asked when they deployed Copilot
Every condition in that table becomes harder to satisfy the moment you add an AI tool that can access, surface, and act on personal information at scale.
When a user prompts Copilot with a question about a colleague, a customer, or a contract, that prompt contains personal information as POPIA defines it. Copilot’s responses draw on emails, documents, Teams messages, and calendar entries that may contain personal information about data subjects who have not consented to their data being processed by an AI tool.
As more and more South African organisations deploy Copilot, POPIA impact assessments need to become as normal as security patching.
And those assessments need to go deeper than Section 72 (POPIA’s cross-border transfer restriction). Until recently, this was the primary POPIA concern about cloud-based AI tools. But even that is changing.
Microsoft’s in-country processing announcement shifts the focus
In November 2025, Microsoft announced in-country data processing for Microsoft 365 Copilot interactions in 15 countries, including South Africa, with rollout expected in 2026. This means Copilot prompts and responses will be processed in Microsoft’s South African data centres rather than offshore.
Obviously, this materially improves the Section 72 position for organisations in regulated industries. But it addresses only one POPIA concern, and not the most operationally important one:
Data residency governs where processing happens.
Data governance governs what Copilot can access and surface.
These are different problems. An organisation with in-country processing but no sensitivity labels applied to its SharePoint sites is still in a position where Copilot can surface an employee’s salary information to a manager who should not see it, or a customer’s ID number to a user who has no need-to-know basis for that access. POPIA’s processing limitation and security safeguards conditions are violated regardless of where the processing occurred.
Microsoft provides the tools for POPIA-compliant Copilot governance
Microsoft Purview’s Data Security Posture Management for AI (DSPM for AI) is the tool that handles this problem, provided you configure it correctly.
It provides a centralised view of how Copilot and other AI tools are interacting with your data. With Purview, you can see which sensitivity labels are being referenced in Copilot interactions, and identify whether users are prompting with sensitive information.
The four controls that make a Copilot deployment POPIA-defensible:
- Sensitivity labels applied to personal information in SharePoint, OneDrive, Exchange, and Teams. These ensure Copilot respects POPIA’s processing limitation condition by design, not by configuration luck.
- DLP policies configured for AI interactions, preventing sensitive personal information from being surfaced in Copilot responses to users without a need-to-know basis.
- Purview Audit enabled and retained. This creates the audit trail POPIA’s accountability condition requires, including a log of every Copilot interaction that references labelled content.
- DSPM for AI data risk assessments running weekly. These can spot oversharing risks and SharePoint sites where personal information is accessible to users who should not have it.
The three POPIA obligations most Microsoft environments are failing
1. Breach notification readiness
POPIA requires notification to the Information Regulator and affected data subjects “as soon as reasonably possible” after a breach.
“As soon as reasonably possible” has no fixed clock, unlike GDPR’s 72-hour rule. But the Regulator’s enforcement posture is sharpening: 3,219 notifications in 2025/26, with the Regulator now running proactive compliance assessments rather than only responding to complaints.
2. Data subject rights operationalisation
The 2025 amended POPIA Regulations simplified the processes for data subjects to object to data processing, request corrections, and request deletion. This made the obligation clearer and the expectation higher.
Most South African organisations have a privacy policy that references these rights. Very few have an operational process to actually fulfil a data subject request: to locate all personal information held about a specific individual across SharePoint, OneDrive, Exchange, Teams, and any connected systems, within a timeframe that is reasonable.
Microsoft Purview Subject Rights Requests automates the search, review, and response workflow for data subject requests across the M365 environment. But it is underused, especially in South African mid-market tenants.
3. SharePoint oversharing: the silent POPIA violation
POPIA’s processing limitation condition requires that access to personal information be restricted to those with a need-to-know basis. In practice, most Microsoft 365 tenants have SharePoint sites and OneDrive folders where personal information is accessible to a far wider set of users than the condition permits.
This is an old problem, but it’s one that Copilot has made newly urgent, because Copilot will surface that information in responses to any user who asks a question that touches it. DSPM for AI’s weekly data risk assessments specifically identify oversharing risks of this type and produce a prioritised remediation list. It is one of the highest-value, lowest-effort starting points for improving both POPIA posture and Copilot governance simultaneously.
“Appropriate and reasonable” leaves very little room for error
POPIA’s security safeguards condition uses the phrase “appropriate and reasonable.” The Information Regulator has now shown, through enforcement, what this means in practice.
The first administrative fine under POPIA (R5 million against the Department of Justice in 2023) followed a ransomware attack in 2021. The root cause was not a sophisticated attack that no defence could have stopped. The department had allowed its security software licences to lapse. The Regulator issued an enforcement notice, the department failed to comply within the specified deadline, and the fine followed.
“Appropriate and reasonable” means, at minimum: licences maintained, MFA enforced, endpoint protection active, and a documented process for detecting and responding to incidents.
Which partners in South Africa can help lock down Microsoft 365 to prevent data leaks?
The honest answer is: not many, and the field matters more than the name.
Locking down Microsoft 365 against data leaks in a POPIA-compliant way is not a generic IT support task. It requires deep familiarity with Microsoft Purview’s sensitivity labelling and DLP architecture, the ability to configure Conditional Access policies without breaking operational workflows, and enough understanding of POPIA’s eight conditions to know which controls address which obligations. A partner who is strong on deployment but unfamiliar with the regulatory context will give you a more secure environment that is still not POPIA-defensible.
There are a handful of Microsoft partners in South Africa with the right combination of Microsoft 365 technical depth and compliance awareness. The questions worth asking before you engage any of them:
- Can they show you your current Microsoft Secure Score and tell you specifically which gaps represent POPIA exposure?
- Have they deployed Purview sensitivity labels and DLP policies in environments similar to yours, and can they give you a reference?
- Do they understand the difference between data residency and data governance?
- Can they explain what Microsoft’s in-country processing announcement does and does not solve for your POPIA position?
- Can they scope a POPIA-focused security review with defined deliverables, rather than an open-ended engagement?
Braintree has done this before
Braintree is one of the partners who can answer yes to all of these questions. As a Microsoft Solutions Partner with specific depth in Microsoft 365 security and compliance, we work with mid-market South African organisations to close the gap between POPIA documentation and POPIA-effective controls.
Crucially for your CFO, Braintree can do that using the Microsoft tools already included in your licensing rather than adding new ones. Our POPIA-focused security review starts with your current configuration, and gives you a prioritised remediation plan in plain language.
The Regulator is not waiting. Book a POPIA-focused security review with Braintree and put this to bed.
Specialists in Business Applications, Modern Workplace and Azure. Let’s grow.