The Protection of Personal Information Act (POPIA) has been fully enforceable in South Africa since July 2021 — and the Information Regulator has demonstrated a clear willingness to investigate and impose penalties on non-compliant organisations. Yet thousands of South African businesses continue to store sensitive personal information in generic cloud drives — Google Drive, Microsoft OneDrive, SharePoint — under the assumption that "cloud" automatically means "compliant."
It does not. And a formal POPIA audit will expose exactly why.
This article covers the five most critical compliance gaps in generic cloud storage and explains what POPIA-compliant document storage actually requires.
Gap 1: Cross-Border Data Transfer — POPIA's Most Dangerous Trap
POPIA's Section 72 prohibits transferring personal information outside South Africa unless specific conditions are met — including the recipient country providing an adequate level of data protection, or the data subject consenting in an informed manner. This is one of POPIA's most commonly violated provisions.
The problem with Google Drive: your data is stored in Google's global infrastructure. Google's data centres for South African business accounts are currently in Europe and the United States. The same applies to Microsoft's consumer and small business OneDrive and SharePoint tiers — your data may be stored in Ireland, the Netherlands, or the United States, all outside South Africa. When your company uploads a client's ID document, proof of address, or financial statement to a standard Google Drive or OneDrive account, you may be committing a Section 72 violation.
Gap 2: Inadequate User-Level Access Auditing
POPIA Condition 7 requires organisations to have appropriate technical and organisational measures to prevent loss, damage, or unauthorised destruction of personal information — and to prevent unauthorised access. A POPIA audit will ask two specific questions about your document storage system:
- Who accessed document X, on what date, from which device?
- When was the document last modified, and by whom?
Standard Google Drive and OneDrive business plans provide basic file-level activity logs, but these logs are not immutable — an administrator can delete or alter them. They also do not provide the granular, per-user access logs that POPIA auditors and the Information Regulator look for.
Gap 3: No Automated Retention & Destruction Enforcement
POPIA Condition 3 (Purpose Specification) requires that personal information not be retained beyond the period necessary for the purpose for which it was collected. In other words, you must have a mechanism to delete or destroy personal information when its retention period expires.
Google Drive and OneDrive do not enforce retention policies automatically. Files sit indefinitely unless someone manually deletes them. In practice, this means most businesses using generic cloud platforms are retaining personal information far beyond their legal obligation — a direct POPIA violation that exposes them to complaints and regulatory action.
Gap 4: No POPI Data Inventory or Personal Information Mapping
POPIA requires organisations to know exactly what personal information they hold, where it is stored, who can access it, and for what purpose. This is known as a POPI Data Inventory or Records of Processing Activity (RoPA). A POPIA audit will request this inventory.
Generic cloud storage makes this virtually impossible. Files are scattered across shared drives, personal drives, and email attachments without systematic classification. Identifying every document containing a South African ID number, bank account, or health record is a manual, months-long exercise.
Gap 5: Lack of External Sharing Controls
Google Drive and OneDrive famously allow users to share files with "Anyone with a link" — meaning sensitive personal information can be inadvertently shared with the public or with external parties outside the organisation's control. POPIA requires reasonable technical measures to prevent exactly this kind of unauthorised disclosure.
The Practical Step Forward
The good news is that migrating from generic cloud storage to a POPIA-compliant system does not require months of IT work or expensive consultants. Paperop can extract your existing digital documents from OneDrive, SharePoint, or Google Drive, classify them, and load them into a POPIA-compliant vault — in days, not months.
For physical paper documents still sitting in filing cabinets or offsite warehouses, our AI document scanning service converts them into searchable digital records — complete with ECT Act legal certification that makes them admissible in South African courts as original evidence.
Summary: The 5 POPIA Gaps in Generic Cloud Storage
| Gap | POPIA Condition | Generic Cloud Risk | Paperop Solution |
|---|---|---|---|
| Cross-border data transfer | Section 72 | Data stored overseas | SA Tier-III data centres only |
| Access auditing | Condition 7 | Mutable, incomplete logs | WORM immutable audit trails |
| Retention enforcement | Condition 3 | No automated deletion | Automated retention schedules |
| POPI Data Inventory | Accountability Condition | Manual and incomplete | AI-generated personal info inventory |
| External sharing controls | Condition 7 | "Anyone with link" risk | External sharing disabled by default |
Ready to close your POPIA compliance gaps?
Book a free POPIA Document Audit assessment with Paperop — we'll identify exactly which documents need to be migrated, classified, and protected.