Free Tool · AVAV Tools

POPIA Compliance Checklist

POPIA has been fully enforceable since July 2021, yet many South African businesses still aren't sure where they stand. Answer 12 plain-language questions and get an instant readiness score with tailored guidance you can print or save. Free, no sign-up, nothing stored.

Lawful ProcessingConsentSecurity SafeguardsOperator ContractsBreach ResponseInformation OfficerData Subject RightsLawful ProcessingConsentSecurity SafeguardsOperator ContractsBreach ResponseInformation OfficerData Subject Rights
The Checklist

Twelve questions.
One honest score.

01

Lawful processing & purpose

We know exactly what personal information we hold, why we collect it, and only use it for the purpose it was collected for.
We only collect the minimum personal information we actually need, and we don't keep it longer than necessary.
02

Consent & data subject rights

We have a clear, accessible privacy notice explaining how we handle personal information.
We obtain proper consent where required, and people can withdraw it or object to direct marketing.
We have a process for people to access, correct or delete the personal information we hold about them.
03

Security safeguards

Personal information is protected with appropriate security, e.g. access controls, encryption and secure storage.
Staff who handle personal information have been trained on their POPIA responsibilities.
04

Operators & third parties

We have written contracts with our operators (suppliers, payroll, cloud, marketing) requiring them to protect personal information.
We know where our data is stored and hosted, and any cross-border transfers meet POPIA's conditions.
05

Breach response

We have a documented plan to detect, contain and report a data breach to the Information Regulator and affected people.
06

Information officer

We have designated an information officer and registered them with the Information Regulator.
We have a PAIA manual and a written record of our processing activities.
Your POPIA Readiness
0 / 12
Answer the questions

Work through the 12 questions on the left. Your score and tailored guidance update live as you answer.

0 of 12 answered · Nothing is sent or stored, everything stays in your browser.

General guidance, not legal advice

This checklist offers general, plain-language guidance to help you gauge your POPIA readiness. It is not legal advice and does not cover every requirement of the Protection of Personal Information Act or your organisation's specific circumstances. For advice tailored to your business, consult a qualified attorney or a POPIA specialist, and refer to the Information Regulator of South Africa for official guidance. AVAV accepts no liability for actions taken based on this tool.

FAQ

POPIA
questions.

What is POPIA?

The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It sets conditions for how organisations may collect, use, store and share personal information, and it became fully enforceable on 1 July 2021.

Who must comply with POPIA?

Almost every South African business, non-profit and public body that processes personal information about employees, customers or suppliers must comply with POPIA, regardless of size.

Do I need to register an information officer?

Yes. Every responsible party must have an information officer, by default the head of the organisation, and register them with the Information Regulator before processing personal information. Deputy information officers can also be designated.

What are the penalties for non-compliance?

The Information Regulator can issue enforcement notices, and serious breaches can lead to administrative fines of up to R10 million or, in some cases, criminal liability including imprisonment. Reputational damage and civil claims are real risks too.

Is this checklist legal advice?

No. This checklist provides general guidance to help you understand your POPIA readiness. It is not legal advice. For advice on your specific circumstances, consult a qualified attorney or a POPIA specialist.

Build POPIA in
from day one.

PeopleCore keeps employee data in POPIA-aware systems with role-based access, audit trails and SA-based processing. Let's talk about your compliance.

Explore PeopleCoreBook a Demo