
POPIA & PAIA compliance, demystified.
We understand the importance of the Protection of Personal Information. From manuals to officer training — we make compliance practical and auditable.
South Africa’s data protection law — with real consequences.
POPIA (Protection of Personal Information Act, 2013) protects personal information processed by public and private bodies — companies, living people, trusts, closed corporations and sole proprietors.
It came into effect on 1 July 2020 with a 12-month grace period. From 1 July 2021, non-compliance comes with severe penalties.
Consequences of non-compliance
- Administrative penalties — fines up to R10 million and/or 10 years in prison per incident.
- Enforcement Notices stopping you from processing personal information.
- Civil actions — data subjects can sue for distress payouts and damages.
- General damages — loss of revenue, brand damage and reputational harm.
From PAIA manual to incident response.
POPIA Implementation
Information Officer appointments, data mapping, policies and PAIA-linked manuals.
PAIA Manuals
Compiled, submitted to the Human Rights Commission and published for your website.

Privacy & Data Policies
Customer-facing privacy notices and internal data-handling SOPs.
Officer Training
Online and in-person training for Information & Deputy Information Officers.

Audits & Reviews
Annual reviews to keep manuals, registers and consents current.
Incident Response
Breach response playbooks and assistance with Information Regulator engagement.
Need an Information Officer training session?
Live and online sessions — plus a take-away playbook for your Deputy Officers.

Ready to engineer a lasting legacy?
Tell us about your business. We’ll come back within one working day with a tailored proposal.