POPIA has been fully enforceable since July 2021, yet many South African businesses still aren't sure where they stand. Answer 12 plain-language questions and get an instant readiness score with tailored guidance you can print or save. Free, no sign-up, nothing stored.
Work through the 12 questions on the left. Your score and tailored guidance update live as you answer.
This checklist offers general, plain-language guidance to help you gauge your POPIA readiness. It is not legal advice and does not cover every requirement of the Protection of Personal Information Act or your organisation's specific circumstances. For advice tailored to your business, consult a qualified attorney or a POPIA specialist, and refer to the Information Regulator of South Africa for official guidance. AVAV accepts no liability for actions taken based on this tool.
The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It sets conditions for how organisations may collect, use, store and share personal information, and it became fully enforceable on 1 July 2021.
Almost every South African business, non-profit and public body that processes personal information about employees, customers or suppliers must comply with POPIA, regardless of size.
Yes. Every responsible party must have an information officer, by default the head of the organisation, and register them with the Information Regulator before processing personal information. Deputy information officers can also be designated.
The Information Regulator can issue enforcement notices, and serious breaches can lead to administrative fines of up to R10 million or, in some cases, criminal liability including imprisonment. Reputational damage and civil claims are real risks too.
No. This checklist provides general guidance to help you understand your POPIA readiness. It is not legal advice. For advice on your specific circumstances, consult a qualified attorney or a POPIA specialist.
PeopleCore keeps employee data in POPIA-aware systems with role-based access, audit trails and SA-based processing. Let's talk about your compliance.