Free POPIA compliance checklist

Is your business actually POPIA compliant? Find out in 2 minutes.

Most small businesses assume they're compliant because they have a privacy policy on their website — but POPIA has 8 legal conditions, and most SMBs are only meeting one or two. Run our free checklist below and get a plain-English score, a gap analysis, and an estimate to close every gap.

The real POPIA compliance checklist — 20 questions, 2 minutes

Answer honestly across all 8 legal conditions POPIA requires. You’ll get an instant score, a plain-English breakdown of your gaps, and an estimate to close them — no obligation.

0 of 20 answered0%

Accountability

Has your business appointed an Information Officer (or deputy) and registered them with the Information Regulator?

Do you have a written data protection / POPIA compliance policy that staff can access?

Processing Limitation

Do you only collect personal information that's actually necessary for a specific purpose (no "just in case" data collection)?

Do you have a documented lawful basis (consent, contract, legal obligation, or legitimate interest) for each type of personal information you collect?

Where you rely on consent, can people withdraw it easily at any time?

Purpose Specification

Do you tell people, at the point of collection, exactly why you're collecting their personal information (e.g. a notice on web forms)?

Do you avoid using personal information for a new purpose without telling the person first?

Further Processing Limitation

If you share personal information with third parties (payment processors, marketing tools, accountants), do you have written agreements requiring them to protect it?

Do you avoid selling or renting customer/employee personal information to unrelated third parties?

Information Quality

Do you have a process for customers or employees to correct inaccurate personal information you hold about them?

Do you periodically review and delete personal information you no longer need (data retention)?

Openness

Does your website have a published Privacy Policy / PAIA manual describing what data you collect and why?

Do new employees sign a data protection / confidentiality agreement covering personal information they will handle?

Can a customer or employee easily find out what personal information you hold about them if they ask?

Security Safeguards

Is personal information (customer databases, HR records, financial records) stored with access restricted to staff who actually need it?

Do you use encrypted connections (HTTPS) and secure, password-protected systems everywhere personal information is captured or stored?

Do you have a written data breach response plan (who to notify, within what timeframe), in line with POPIA's mandatory reporting requirement?

Are staff who handle personal information given any POPIA / data protection awareness training?

Data Subject Participation

Do you have a documented process for someone to request access to, correction of, or deletion of their personal information?

Do you respond to such requests within a reasonable time (generally within 30 days)?

POPIA compliant · No spam · Full report emailed to you

What we check for you

20 practical questions mapped across all 8 conditions POPIA requires for lawful processing of personal information.

Are you accountable?

We check whether you have a registered Information Officer and a written compliance policy — the foundation the Regulator looks for first.

Are you exposed to a breach?

We check your security safeguards and whether you have a documented breach response plan, in line with POPIA’s mandatory reporting rules.

Can people exercise their rights?

We check whether customers and staff can access, correct, or request deletion of their personal information — a legal right under POPIA.

What would it cost to fix?

For every gap we find, you get a clear once-off and monthly estimate using our real pricing — no obligation, no jargon.

The 8 POPIA conditions we score

1Accountability
2Processing Limitation
3Purpose Specification
4Further Processing Limitation
5Information Quality
6Openness
7Security Safeguards
8Data Subject Participation

How it works

1

Answer 20 questions

Honest yes/no/unsure answers across all 8 legal conditions. Takes about 2 minutes.

2

We score it instantly

Our engine grades each condition and your business overall, out of 100.

3

Get your report + estimate

See your results on screen and in your inbox as a PDF, with a costed remediation plan.

POPIA compliant · We never share your details · This checklist is a self-assessment indicator, not formal legal advice.