POPIA · built in South Africa

POPIA data retention that can actually prove deletion.

POPIA asks you to do two things that fight each other: keep records secure for as long as the law requires, and delete a person's data when they ask. AT-1 does both in one sealed archive — compressed, searchable, tamper-evident, and erasable one data subject at a time, with a signed certificate proving the deletion to the Information Regulator.

What POPIA actually asks of your records

The four obligations that a retention and deletion strategy has to satisfy — and where most archives fall short.

Section 14 — retention limits

You may keep records only as long as there is a lawful basis, then you must delete or de-identify them. But other laws (FICA, tax, sector rules) force you to retain some records for years — so you need to keep and forget in the same store.

The right to deletion

A data subject can ask you to delete or destroy their personal information. You have to honour it across live systems, backups and archives — and be able to show that you did.

Condition 7 — security safeguards

You must secure the integrity and confidentiality of personal information and be able to demonstrate it. Tamper-evidence and access control are not optional extras.

Accountability to the Regulator

The Information Regulator can ask you to demonstrate compliance. "We deleted it" is weaker than a signed, timestamped certificate proving the record is cryptographically irrecoverable.

How AT-1 answers each one

  • Retain, compressed. One bundle 3–5× smaller than raw — years of records without the storage bill, and without going opaque.
  • Search in place. Query a retained dataset without restoring it — answer a subject-access request or an audit query in milliseconds.
  • Prove integrity (Condition 7). A SHA-256 manifest means a single changed byte fails verification — the record is provably the original.
  • Delete on request. Erase one data subject in milliseconds by destroying their key — their retained pseudonymous rows stay queryable, the bytes never move.
The proof-of-deletion certificate

When you erase a data subject, AT-1 emits a signed certificate: the subject's ID, a timestamp, a proof that their specific key was destroyed, and the archive's hash before and after (identical — the retained records were untouched). This is the difference between telling the Regulator “we deleted it” and handing them admissible evidence that the record is permanently irrecoverable. A free proof on a sample of your own data takes 24–48 hours — send 100k to 1M rows (identifiers masked on your side if you prefer) and we return a one-page report with your numbers: storage, query-in-place latency, erasure time with a signed certificate, and an integrity check.

Built for POPIA-regulated organisations

  • Banks & fintech — retain transaction history for FICA, erase a customer on request, prove integrity for audit.
  • Insurers & medical schemes — keep claims data queryable, forget a member cleanly when POPIA requires it.
  • Retail & telco — years of customer and loyalty data, retained small and provably deletable.
  • Any Information Officer closing the gap between retention obligations and the right to deletion.

Honest scope: AT-1 is a technical control, not a compliance programme. It does not replace an appointed Information Officer, your PAIA manual, operator agreements, policies or staff training — it makes two of the hardest technical obligations (secure retention and provable deletion) demonstrable. Cryptographic erasure is an established, regulator-recognised method; our contribution is the unified, queryable, productised archive, not a new cryptographic claim.

POPIA questions, answered

How does AT-1 help with POPIA data retention?
AT-1 stores your records as a single compressed, searchable archive that is tamper-evident and per-subject erasable. You keep records for as long as retention law requires, query them in place without restoring, and when a POPIA deletion request or retention limit applies you erase that one subject in milliseconds — with a signed certificate as proof.
Can I prove to the Information Regulator that a person's data was deleted?
Yes. Every erasure emits a signed proof-of-deletion certificate — subject ID, timestamp, a key-destruction proof, and the archive hash before and after (identical). It is admissible evidence that the specific record is permanently irrecoverable, not just that a deletion was requested.
How do I delete one person under POPIA while still keeping records I'm legally required to retain?
Each data subject's identifying PII is encrypted under its own key. Erasing them destroys that key, so their name/email/ID number become permanently unrecoverable — while the pseudonymous rows you must keep for FICA, tax or audit stay intact and queryable. You forget the person without breaking your retention obligations.
Does AT-1 make my organisation POPIA compliant on its own?
No — and be wary of any tool that claims it does. POPIA compliance still needs an appointed Information Officer, policies, operator agreements and staff training. AT-1 is the technical control for two of the hardest parts: securely retaining records (Condition 7) and provably deleting a data subject on request.
Is cryptographic erasure enough to satisfy the POPIA right to deletion?
Crypto-shredding — destroying the key so the data is permanently irrecoverable — is an established, regulator-recognised erasure method, and the only one compatible with a tamper-evident archive (physically deleting bytes would break the integrity proof you also need under Condition 7).

Bring a sample of your data — we'll prove POPIA-grade retention and deletion on it.

Start a free proof