security
Compliance Handbook: POPIA & GDPR
Essential reading for processing user data via QR codes in South Africa and the EU.
## Privacy First Architecture
QR Code Pro is the only platform in South Africa with 2026-ready POPIA compliance built into the transit layer.
### How We Protect Data
- **Zero-PII Storage**: We track scan metadata (device, location) without storing personally identifiable information unless explicitly configured.
- **Data Residency**: All South African traffic is routed through local nodes to ensure compliance with data sovereignty laws.
- **Encryption**: AES-256 encryption for all database entries and TLS 1.3 for data in transit.
### Your Responsibilities
If you use QR codes to collect data via forms:
1. Ensure your destination site has a visible Privacy Policy.
2. Disclose any tracking cookies.
3. Obtain consent before storing contact details.
See our [Legal Hub](/solutions/legal) for more templates.
Was this helpful?
Last updated January 2026