POPIA Readiness
Most organisations completed a POPIA project, produced a policy, appointed an Information Officer and then changed nothing in the systems. We look at where personal information actually lives, who can reach it, how long it is kept and whether the paperwork matches what the technology permits. Compliance that exists only on paper fails the first time it is tested.
1
Map
Where personal information lives
2
Assess
Lawful basis and consent
3
Test
Access, retention, security
4
Review
Operators and third parties
5
Report
Gaps and remediation plan
How We Assess
01
Personal Information Mapping
You cannot protect what you have not located. We build an inventory of the personal information you hold, where it is stored, how it entered the organisation and where it flows afterwards, including the spreadsheets and mailboxes that never appear on an official system list.
- Inventory of personal information by system and process
- Data flow mapping, including flows to third parties
- Special personal information and childrens data identified
- Shadow repositories such as shared drives and mailboxes
02
Lawful Processing Assessment
Every processing activity needs a lawful basis, and consent is only one of them. We assess each activity against the conditions in the Act and flag where you are relying on consent that was never properly obtained.
- Lawful basis established per processing activity
- Consent capture, records and withdrawal mechanisms
- Purpose limitation and further processing review
- Direct marketing and section 69 requirements
03
Access and Security Controls
This is where a paper exercise usually falls apart. We test who can actually reach personal information in the systems, against who should be able to, and whether access is reviewed by anyone.
- Access rights over systems holding personal information
- Privileged and administrative access review
- Encryption in transit and at rest
- Logging of access to sensitive records
04
Retention and Disposal
POPIA requires that records are not kept longer than necessary, which conflicts with the common instinct to keep everything. We check whether a retention schedule exists, whether the systems can enforce it, and whether anything is ever actually deleted.
- Retention schedule against statutory requirements
- Whether systems can enforce retention technically
- Secure disposal and de identification practices
- Backup and archive retention alignment
05
Operators and Third Parties
Every supplier that processes personal information on your behalf is an operator, and you remain accountable for them. We review the contracts against what those suppliers can technically reach.
- Operator register and contract review
- Section 21 operator agreement clauses
- Cross border transfer assessment
- Supplier access rights tested against contract terms
What You Receive
- Personal information inventory and data flow map
- Gap assessment against the conditions for lawful processing
- Access rights testing results by system
- Retention schedule review and recommendations
- Prioritised remediation plan with owners
- Summary for the Information Officer and the board
Indicative Timeline
A readiness review normally runs three to six weeks. The variable is how many systems hold personal information and how much of it sits outside official systems, which is usually more than expected.
- Scoping and stakeholder interviews: one week
- Mapping and system testing: two to three weeks
- Contract and operator review: one week
- Reporting and management comment: one week
What We Assess Against
POPIA is the statute, but readiness is assessed against the controls that make compliance demonstrable rather than merely asserted.
POPIA Conditions
The eight conditions for lawful processing, assessed activity by activity rather than organisation wide.
Information Regulator Guidance
Published guidance notes and the registration requirements for Information Officers and Deputies.
King IV
Principle 12 and the board responsibility for information governance that POPIA compliance ultimately reports into.
ISO/IEC 27701
Privacy information management, useful where a structured and certifiable privacy baseline is wanted.
Access Controls
The technical controls that determine whether policy is actually enforceable inside the systems.
PAIA
The access to information manual requirement that sits alongside POPIA and is frequently overlooked.
Frequently Asked Questions
We already did a POPIA project. Why do this?
Because most POPIA projects produced documents rather than changes to systems. The common finding is a well drafted policy alongside a finance system where twenty people can read salary data and nobody reviews access. This review tests the second part.
Is this a legal opinion?
No. We assess operational and technical readiness and report the gaps. Where an issue turns on interpretation of the Act, we flag it for your legal advisors rather than opining on it ourselves.
Does POPIA apply to us if we only hold employee data?
Yes. Employee information is personal information, and payroll files usually contain special personal information as well. Organisations with no customer data at all still process a substantial amount as an employer.
What is an operator and why does it matter?
An operator processes personal information on your behalf without owning it, such as a payroll bureau or a cloud provider. You remain accountable for what they do, which is why the contract and their actual access both need checking.
Will you help us fix what you find?
Yes, though remediation is quoted separately from the assessment. Where the fix is technical, it can be delivered through our ICT services. Where it is procedural, we help draft what is missing.
How does this relate to an ICT audit?
POPIA readiness overlaps heavily with access management and retention controls in an ITGC review. If both are needed we scope them together so evidence is gathered once.
Related Services
This sits inside our ICT Audit practice. Related work: IT General Controls Reviews, which tests the access controls POPIA depends on, and Cyber Security Assessments for the security safeguards the Act requires.
