Data & Risk

Enterprise-grade protection for your cross-border team.

POPIA and GDPR-aligned contracts, IP assignment, and security controls - so hiring in South Africa strengthens your compliance posture instead of exposing it.

Controls we operate

Security and compliance, baked into every hire.

Privacy-law (POPIA) compliant contracts

Every employment agreement includes lawful-basis clauses, processor terms, and subject-rights procedures aligned with POPIA and GDPR.

IP assignment & confidentiality

Present-and-future IP assigned to your entity, plus enforceable NDAs, non-solicits, and post-employment restraints where applicable.

Device & access controls

Managed laptops with disk encryption, MDM, and SSO enforcement. Access to your systems is provisioned and revoked with the employment lifecycle.

Audit trails

Onboarding, access grants, terminations, and payroll changes are logged. When your security team asks, we can show the evidence.

Incident response

Documented response plan for data incidents affecting SA employees - with US client notification SLAs and Information Regulator escalation paths.

DPAs & sub-processors

Signed data processing agreements, a maintained sub-processor list, and vendor due diligence for anything that touches your data.

Standards we align to

We meet the bar your security and legal teams expect from a US vendor.

  • POPIA (Protection of Personal Information Act, SA)
  • GDPR-aligned processing for EU data flows
  • SOC 2-aligned internal controls
  • ISO 27001-aligned security practices
  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Least-privilege access with quarterly reviews

Risks we remove

The four cross-border risks that actually bite.

Misclassification

Hiring contractors long-term across borders exposes you to reclassification, back taxes, and penalties. EOR employment eliminates the risk.

IP ownership

Without SA-law-compliant assignment clauses, work product may not belong to your US entity. Every EMPLOI contract closes that gap.

Data residency & POPIA

SA has its own privacy regime with real teeth. We handle lawful basis, DPAs, and subject requests so you don't have to become an expert.

Termination disputes

SA labor law protects employees strongly. We structure probation, warnings, and terminations so exits don't become cases at the CCMA, South Africa's employment tribunal.

Due diligence

What US security and legal teams ask us.

Background checks

We run criminal record, identity, qualification, and reference checks where the role requires it. Every check is run with the candidate's written consent under POPIA, and only lawful, role-relevant findings are shared.

Device logistics

EMPLOI procures, images, and ships the laptop to the employee against your security baseline. The device is owned by our South African operating entity and assigned to the worker for the duration of employment, then wiped and retrieved at offboarding.

Who you contract with

You sign a services agreement with EMPLOI Inc. (US). We employ the worker through our South African entity, Veridian Global (Pty) Ltd, so you get one USD invoice without setting up your own local company.

Talk to us

Want our DPA, controls summary, or a security review?

We'll share our data processing agreement, sub-processor list, and controls documentation on request. Your security team is welcome to put them under the microscope.

Already paying South African contractors? Long-term contractors who work like employees are a misclassification claim waiting to happen: back pay, penalties, and an ugly CCMA (Commission for Conciliation, Mediation and Arbitration) case. Converting them to compliant EOR employment takes about two weeks.

See how conversion works