
Sue Adams represents Fulcrum as a Roots and Wings Mentor 2026
5 May 2026
Personal branding for young insurance professionals: lessons from the creator economy
18 August 2026
The Protection of Personal Information Act (POPIA) is South Africa’s data privacy legislation, designed to ensure that personal information is processed lawfully, responsibly, and securely. It protects individuals’ right to privacy by setting clear obligations for organisations and giving individuals greater control over how their personal information is handled.
Trust beyond compliance
For the insurance and broader financial services industry, POPIA is far more than a regulatory requirement. Every day, insurers are entrusted with highly sensitive personal information, including identity details, financial records, medical histories, and claims data. Clients share this information with the expectation that it will remain confidential and secure, making the protection of that trust fundamental to every client relationship.
When personal information is compromised, the consequences extend far beyond compliance. A data breach can quickly undermine client confidence, damage an organisation’s reputation, and weaken relationships that may have taken years to build.
When trust is breached
South Africa has experienced several high-profile data breaches in recent years, involving organisations such as Dis-Chem, TransUnion, and Lancet Laboratories. These incidents exposed the personal information of millions of individuals and attracted significant public, media, and regulatory attention. While the causes varied, they all reinforced the same message: a data breach is not merely a technology failure; it is a breach of trust.
This is particularly significant in the insurance industry, where clients are required to share deeply personal information throughout the customer journey. From underwriting policies to processing claims, insurers often have access to information relating to an individual’s health, finances, family circumstances, and assets. If clients lose confidence in how this information is protected, they may become reluctant to disclose important details, potentially affecting underwriting decisions, advice, and claims outcomes.
The impact on client relationships can be immediate and long-lasting. Customers whose information has been compromised often feel exposed and vulnerable. Even where no financial loss occurs, a perceived failure to protect personal information can result in complaints, reputational damage, reduced customer loyalty, and ultimately, loss of business.
In an industry where trust is a key competitive advantage, rebuilding confidence after a breach is often more difficult than restoring affected systems.
Beyond the tick-box
For this reason, POPIA compliance should never be seen as a tick-box exercise focused solely on avoiding penalties. It should form part of a broader commitment to good governance, ethical business practices, and customer care. Effective compliance requires embedding privacy, accountability, and information security throughout the information lifecycle – from collection and processing to secure disposal.
This philosophy, for example, underpins our approach to information governance. As a Compliance Manager and Information Officer, my responsibility extends beyond legislative compliance. My focus is on fostering a culture where protecting personal information is part of the organisation’s DNA. This includes implementing robust governance frameworks, promoting employee awareness, proactively managing information security risks, and embedding privacy considerations into everyday business decisions.
The Information Officer’s role goes beyond policies and procedures. It involves ensuring personal information is handled with the care, respect, and security it deserves while aligning regulatory obligations with client expectations. Through ongoing oversight, proactive risk management, and a culture of accountability, we strengthen both our compliance framework and the confidence our clients place in us.
Ultimately, personal information is more than data – it is trust. While organisations can recover from the technical impact of a data breach, rebuilding client confidence is often far more challenging. In the insurance industry, where long-term relationships depend on confidence, transparency, and discretion, protecting personal information is not just a legal obligation; it is a business imperative.
By embedding privacy and information security into our operations, organisations not only comply with POPIA but also strengthen the trust that underpins every successful client relationship.
Kerusha Pillay
Compliance Manager
Fulcrum




