Details on our ISO 9001, ISO 27001, and POPIA certifications for document handling.
At Paperop, we operate under the strictest international and local regulatory frameworks. Our document storage vaults, scanning bureaus, and cloud architecture are audited regularly to maintain industry-leading compliance certifications.
Our entire infrastructure is certified under ISO/IEC 27001. This guarantees that all physical and digital records managed by Paperop are protected by a comprehensive Information Security Management System (ISMS), safeguarding confidentiality, integrity, and availability.
We maintain ISO 9001 certification across our document digitization and archiving workflows. This ensures that every document scanned via our OCR engines meets strict quality control standards, minimizing errors and maintaining the evidential weight of the records.
Our physical storage facilities meet and exceed the stringent environmental and security specifications required by the National Archives and Records Service of South Africa for the storage of public records.
We are fully compliant with the Protection of Personal Information Act (POPIA). For our multinational clients, our data processing agreements and secure cloud hosting infrastructure also align with the principles of the General Data Protection Regulation (GDPR).
Need copies of our ISO certificates for your vendor procurement process?
The Protection of Personal Information Act (POPIA, Act 4 of 2013) is South Africa's primary data protection law. It came into full effect on 1 July 2021, with a one-year grace period that ended on 30 June 2022. All businesses operating in South Africa — regardless of size — must comply.
POPIA establishes eight conditions for lawful processing of personal information. Of these, document management professionals most frequently deal with: Information Quality (data must be accurate and up to date), Storage Limitation (data may not be kept longer than necessary), and Security Safeguards (personal information must be protected from loss, damage, or unauthorised access).
Personal information may only be retained for as long as required to fulfil the purpose for which it was collected, or as required by law. Once this period has elapsed, the information must be destroyed, deleted, or de-identified. Paperop's automated retention schedules enforce this automatically — and issue a Certificate of Destruction as proof.
Responsible Parties must take appropriate, reasonable, technical, and organisational measures to prevent loss, damage, or unauthorised access to personal information. This means physical access controls on document vaults, encryption of digital files, and background-screened staff — all standard features of Paperop's service.
When you outsource document management to Paperop, we become your POPIA Operator. The law requires a formal written agreement establishing that we process personal information only on your instructions. Paperop provides a comprehensive Data Processing Agreement (DPA) to all clients to satisfy this requirement.
In the event of a suspected or confirmed personal information breach, POPIA requires notification to the Information Regulator and affected data subjects as soon as reasonably possible. Paperop's incident response procedure is documented and tested, and we will notify you immediately if any security event affects your documents in our care.
Non-compliance with POPIA carries significant consequences. The Information Regulator can issue an enforcement notice, seek an interdict, and refer matters to court. Criminal penalties can include:
Speak with a Paperop records management specialist to understand where your document handling practices currently stand relative to POPIA's requirements — and what it would take to close any gaps.