POPIA data retention that can actually prove deletion.
POPIA asks you to do two things that fight each other: keep records secure for as long as the law requires, and delete a person's data when they ask. AT-1 does both in one sealed archive — compressed, searchable, tamper-evident, and erasable one data subject at a time, with a signed certificate proving the deletion to the Information Regulator.
What POPIA actually asks of your records
The four obligations that a retention and deletion strategy has to satisfy — and where most archives fall short.
Section 14 — retention limits
You may keep records only as long as there is a lawful basis, then you must delete or de-identify them. But other laws (FICA, tax, sector rules) force you to retain some records for years — so you need to keep and forget in the same store.
The right to deletion
A data subject can ask you to delete or destroy their personal information. You have to honour it across live systems, backups and archives — and be able to show that you did.
Condition 7 — security safeguards
You must secure the integrity and confidentiality of personal information and be able to demonstrate it. Tamper-evidence and access control are not optional extras.
Accountability to the Regulator
The Information Regulator can ask you to demonstrate compliance. "We deleted it" is weaker than a signed, timestamped certificate proving the record is cryptographically irrecoverable.
How AT-1 answers each one
- Retain, compressed. One bundle 3–5× smaller than raw — years of records without the storage bill, and without going opaque.
- Search in place. Query a retained dataset without restoring it — answer a subject-access request or an audit query in milliseconds.
- Prove integrity (Condition 7). A SHA-256 manifest means a single changed byte fails verification — the record is provably the original.
- Delete on request. Erase one data subject in milliseconds by destroying their key — their retained pseudonymous rows stay queryable, the bytes never move.
When you erase a data subject, AT-1 emits a signed certificate: the subject's ID, a timestamp, a proof that their specific key was destroyed, and the archive's hash before and after (identical — the retained records were untouched). This is the difference between telling the Regulator “we deleted it” and handing them admissible evidence that the record is permanently irrecoverable. A free proof on a sample of your own data takes 24–48 hours — send 100k to 1M rows (identifiers masked on your side if you prefer) and we return a one-page report with your numbers: storage, query-in-place latency, erasure time with a signed certificate, and an integrity check.
Built for POPIA-regulated organisations
- Banks & fintech — retain transaction history for FICA, erase a customer on request, prove integrity for audit.
- Insurers & medical schemes — keep claims data queryable, forget a member cleanly when POPIA requires it.
- Retail & telco — years of customer and loyalty data, retained small and provably deletable.
- Any Information Officer closing the gap between retention obligations and the right to deletion.
Honest scope: AT-1 is a technical control, not a compliance programme. It does not replace an appointed Information Officer, your PAIA manual, operator agreements, policies or staff training — it makes two of the hardest technical obligations (secure retention and provable deletion) demonstrable. Cryptographic erasure is an established, regulator-recognised method; our contribution is the unified, queryable, productised archive, not a new cryptographic claim.
POPIA questions, answered
- How does AT-1 help with POPIA data retention?
- AT-1 stores your records as a single compressed, searchable archive that is tamper-evident and per-subject erasable. You keep records for as long as retention law requires, query them in place without restoring, and when a POPIA deletion request or retention limit applies you erase that one subject in milliseconds — with a signed certificate as proof.
- Can I prove to the Information Regulator that a person's data was deleted?
- Yes. Every erasure emits a signed proof-of-deletion certificate — subject ID, timestamp, a key-destruction proof, and the archive hash before and after (identical). It is admissible evidence that the specific record is permanently irrecoverable, not just that a deletion was requested.
- How do I delete one person under POPIA while still keeping records I'm legally required to retain?
- Each data subject's identifying PII is encrypted under its own key. Erasing them destroys that key, so their name/email/ID number become permanently unrecoverable — while the pseudonymous rows you must keep for FICA, tax or audit stay intact and queryable. You forget the person without breaking your retention obligations.
- Does AT-1 make my organisation POPIA compliant on its own?
- No — and be wary of any tool that claims it does. POPIA compliance still needs an appointed Information Officer, policies, operator agreements and staff training. AT-1 is the technical control for two of the hardest parts: securely retaining records (Condition 7) and provably deleting a data subject on request.
- Is cryptographic erasure enough to satisfy the POPIA right to deletion?
- Crypto-shredding — destroying the key so the data is permanently irrecoverable — is an established, regulator-recognised erasure method, and the only one compatible with a tamper-evident archive (physically deleting bytes would break the integrity proof you also need under Condition 7).
Bring a sample of your data — we'll prove POPIA-grade retention and deletion on it.
Start a free proof