Compliance
KeyCare Pass and POPIA
South Africa's Protection of Personal Information Act asks responsible parties to secure the personal information they process. Access to systems holding that information starts with passwords.
Prices and options by email
How to get started today
KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.
What POPIA asks for
The Protection of Personal Information Act 4 of 2013 (POPIA) sets conditions for lawful processing. Condition 7, security safeguards, requires a responsible party to secure the integrity and confidentiality of personal information with appropriate, reasonable technical and organisational measures (section 19), and to notify the Information Regulator and data subjects of security compromises (section 22).
Our cloud service runs in the European Union. If personal information must stay in South Africa, you can run KeyCare Pass on your own servers.
Where KeyCare Pass fits
Section 19 safeguards that a password manager can support.
| What is asked for | How KeyCare Pass can help | Plans |
|---|---|---|
| Prevent unlawful access (s19(1)) | Collections and groups limit who can reach the logins to systems holding personal information; two-step login protects every account. | Teams, Enterprise |
| Appropriate technical measures (s19(1)) | Vault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS. | All plans |
| Identify and manage risks (s19(2)) | Vault health reports find weak, reused and exposed passwords to fix. | All plans |
| Verify safeguards are effective (s19(2)) | Event logs and sign-in activity show who accessed what. | Teams, Enterprise |
| Investigate security compromises (s22) | Event logs with times and IP addresses help you work out what was reached and by whom. | Teams, Enterprise |
What stays with you
A password manager is one control among many. These remain your organization's work:
- Your information officer's duties and your POPIA compliance framework
- Agreements with operators that process personal information for you
- Deciding whether cross-border processing is allowed for your data
- Notifying the Information Regulator and data subjects of a compromise
Frequently asked questions
Does GovPAM see the personal information in our vault?
No. Vault contents are encrypted on your members' devices and GovPAM cannot read them. GovPAM does hold account data such as email addresses, as the privacy policy explains.
Can our data stay in South Africa?
Our cloud service is hosted in the European Union. To keep everything in South Africa, host KeyCare Pass yourself.
Need details for your auditor?
Ask us about KeyCare Pass's design, hosting and data handling.