POPIA Readiness

Most organisations completed a POPIA project, produced a policy, appointed an Information Officer and then changed nothing in the systems. We look at where personal information actually lives, who can reach it, how long it is kept and whether the paperwork matches what the technology permits. Compliance that exists only on paper fails the first time it is tested.

1

Map

Where personal information lives

2

Assess

Lawful basis and consent

3

Test

Access, retention, security

4

Review

Operators and third parties

5

Report

Gaps and remediation plan

How We Assess

01

Personal Information Mapping

You cannot protect what you have not located. We build an inventory of the personal information you hold, where it is stored, how it entered the organisation and where it flows afterwards, including the spreadsheets and mailboxes that never appear on an official system list.

02

Lawful Processing Assessment

Every processing activity needs a lawful basis, and consent is only one of them. We assess each activity against the conditions in the Act and flag where you are relying on consent that was never properly obtained.

03

Access and Security Controls

This is where a paper exercise usually falls apart. We test who can actually reach personal information in the systems, against who should be able to, and whether access is reviewed by anyone.

04

Retention and Disposal

POPIA requires that records are not kept longer than necessary, which conflicts with the common instinct to keep everything. We check whether a retention schedule exists, whether the systems can enforce it, and whether anything is ever actually deleted.

05

Operators and Third Parties

Every supplier that processes personal information on your behalf is an operator, and you remain accountable for them. We review the contracts against what those suppliers can technically reach.

What You Receive

Indicative Timeline

A readiness review normally runs three to six weeks. The variable is how many systems hold personal information and how much of it sits outside official systems, which is usually more than expected.

What We Assess Against

POPIA is the statute, but readiness is assessed against the controls that make compliance demonstrable rather than merely asserted.

POPIA Conditions

The eight conditions for lawful processing, assessed activity by activity rather than organisation wide.

Information Regulator Guidance

Published guidance notes and the registration requirements for Information Officers and Deputies.

King IV

Principle 12 and the board responsibility for information governance that POPIA compliance ultimately reports into.

ISO/IEC 27701

Privacy information management, useful where a structured and certifiable privacy baseline is wanted.

Access Controls

The technical controls that determine whether policy is actually enforceable inside the systems.

PAIA

The access to information manual requirement that sits alongside POPIA and is frequently overlooked.

Frequently Asked Questions

Because most POPIA projects produced documents rather than changes to systems. The common finding is a well drafted policy alongside a finance system where twenty people can read salary data and nobody reviews access. This review tests the second part.

No. We assess operational and technical readiness and report the gaps. Where an issue turns on interpretation of the Act, we flag it for your legal advisors rather than opining on it ourselves.

Yes. Employee information is personal information, and payroll files usually contain special personal information as well. Organisations with no customer data at all still process a substantial amount as an employer.

An operator processes personal information on your behalf without owning it, such as a payroll bureau or a cloud provider. You remain accountable for what they do, which is why the contract and their actual access both need checking.

Yes, though remediation is quoted separately from the assessment. Where the fix is technical, it can be delivered through our ICT services. Where it is procedural, we help draft what is missing.

POPIA readiness overlaps heavily with access management and retention controls in an ITGC review. If both are needed we scope them together so evidence is gathered once.

Related Services

This sits inside our ICT Audit practice. Related work: IT General Controls Reviews, which tests the access controls POPIA depends on, and Cyber Security Assessments for the security safeguards the Act requires.

Discuss a POPIA readiness review