Is your business POPIA compliant?
A short, plain-English questionnaire checks your business against all 8 of POPIA's conditions for lawful processing, plus special personal information. You get a scored report immediately - a PAIA manual, privacy policy, and Information Officer registration pack can then be generated from your answers, reviewed by our team before you rely on them.
What you get
- A scored gap-analysis report, ranked by finding severity - not a black box, every question and score is visible.
- A PAIA manual, privacy policy, and Information Officer registration pack, populated from your answers. Anything we couldn't establish is marked to complete, never invented.
- A separate breach-response tool for when something goes wrong: tells you whether POPIA s22 requires you to notify the Information Regulator and affected people, and drafts those notifications.
This is not legal advice. Every score and document is reviewed by our team before it's meant to be relied on - see Disclaimer.
Frequently asked questions
What is POPIA and does it apply to my business?
POPIA (the Protection of Personal Information Act 4 of 2013) is South Africa's data protection law. It applies to virtually any business that processes personal information in South Africa, whether or not you're online-only - staff records, a customer database, or even a paper filing system all count.
What are POPIA's 8 conditions for lawful processing?
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Our questionnaire scores your business against each one individually so you can see exactly where the gaps are.
Do I need to register an Information Officer?
Yes - POPIA requires most organisations that process personal information to register an Information Officer with the Information Regulator (by default this is the CEO/head of the organisation, unless someone else is formally appointed). We generate the registration pack from your questionnaire answers.
What happens if my business has a data breach?
Section 22 of POPIA requires notifying the Information Regulator, and in most cases the affected individuals, "as soon as reasonably possible" after you become aware of a breach. Our breach-response tool assesses whether your incident triggers that duty and drafts the notifications for you to review.
How long does the compliance check take?
The questionnaire itself takes most businesses 15-30 minutes. You get your scored report immediately; the generated PAIA manual, privacy policy, and Information Officer pack are then reviewed by our team before you rely on them.
What if I'm not sure whether something I hold counts as "personal information"?
POPIA's definition is broad - basically anything that identifies or relates to a living person (and in some cases a deceased or juristic person): names, ID numbers, contact details, financial information, even an IP address in some contexts. Flag anything you're unsure about during the questionnaire and our team will help you classify it.
What is "special personal information" and does it apply to me?
Special personal information (POPIA s26-33) covers particularly sensitive categories - religious/philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric data, and criminal behaviour. It generally can't be processed unless a specific exception applies, and our questionnaire includes a dedicated gate for it.
What does the scored gap-analysis report actually look like?
It's not a black box - every question maps to one of POPIA's 8 conditions, and any gap is ranked by severity (critical, high, or medium) so you can see and contest each finding individually, rather than trusting an opaque overall score.
Do I need a PAIA manual as well as a POPIA-compliant privacy policy?
Usually both - a PAIA (Promotion of Access to Information Act) manual explains how someone can request records from you, while your privacy policy explains what you collect and why. We generate both from the same questionnaire answers.
Is this a once-off check, or does compliance need ongoing attention?
POPIA compliance isn't a once-off certificate - it needs ongoing attention as your business, systems, and data practices change. We'd recommend re-running the questionnaire whenever something material changes (a new system, a new type of data collected, a new third party you share data with).
Can a small business or sole proprietor use this, or is it only for larger companies?
It's built for any size - POPIA doesn't exempt small businesses from compliance, though what 'proportionate' security safeguards and documentation look like does scale with your size and risk. The questionnaire adapts based on your answers rather than assuming a large-company structure.
