Commtac Consult

POPIA compliance checklist: all 54 requirements

This is the full checklist our consultants use to assess South African organisations against the Protection of Personal Information Act, 4 of 2013. Every line item cites the POPIA section it comes from and the evidence an assessor will ask you to produce. Work through it top to bottom and you will know exactly where you stand.

Download the checklist (PDF)Free · 54 requirements · printable scoring column · no sign-up required

What is POPIA?

POPIA is South Africa's data protection law. It governs how a responsible party (the organisation deciding why and how data is processed) may collect, use, store, share and delete personal information about data subjects — which, unusually, includes both living people and existing juristic persons such as companies. It has been fully enforceable since 1 July 2021, and the Information Regulator can impose administrative fines of up to R10 million.

Compliance is structured around 8 conditions for lawful processing (sections 8 to 25). Every processing activity must meet all eight. On top of those sit rules for special personal information, children's data, direct marketing, automated decisions, cross-border transfers and the registration of an Information Officer — which is why a realistic checklist runs to 54 items rather than eight.

How to use this checklist

  1. Score each item Compliant, Partially compliant, Not compliant or Not applicable.
  2. Attach the evidence named in the item. If you cannot produce it, the item is not compliant, whatever the practice on the ground.
  3. Score the result: compliant items count 1, partial items count 0.5, and not-applicable items are excluded from the denominator.
  4. Fix the lowest-scoring conditions first — Processing Limitation and Security Safeguards carry the most regulatory risk.
  5. Re-assess at least annually and after any material change to your systems or vendors.

Our platform runs exactly this checklist with scoring, evidence uploads and gap reporting built in — assessments are free.

Contents

Application — does POPIA apply to you?

Sections 3 to 7. Before you do anything else, confirm POPIA applies and record which statutory exclusions you rely on.

  • A1Confirm POPIA applies: the responsible party is domiciled in South Africa, or processing of personal information takes place in South Africa.

    POPIA s.3 · Evidence to keep: Applicability assessment or legal opinion confirming POPIA applies.

  • A2Identify whether any statutory exclusions apply (purely personal or household activity; de-identified information; cabinet or legislative function; judicial functions; journalistic, literary or artistic expression).

    POPIA s.6 & s.7 · Evidence to keep: Documented exclusion assessment with motivation.

Condition 1 — Accountability

Section 8. Someone must own POPIA compliance, and the ownership must be documented.

  • C1.1The responsible party has taken accountable steps to ensure all 8 conditions are met when the purpose and means of processing are determined, and throughout processing.

    POPIA s.8 · Evidence to keep: POPIA compliance framework signed off by an accountable executive.

  • C1.2A POPIA governance structure is in place (Information Officer, deputies, privacy committee) with documented roles and responsibilities.

    POPIA s.8 · Evidence to keep: Governance terms of reference; organogram; appointment letters.

Condition 2 — Processing Limitation

Sections 9 to 12. This is where most assessments lose points: organisations process data they cannot justify, on a lawful basis they never wrote down.

  • C2.1Personal information is processed lawfully and in a manner that does not unreasonably infringe the data subject's privacy.

    POPIA s.9 · Evidence to keep: Lawful basis register; privacy notice; legitimate interest assessments.

  • C2.2Minimality: the personal information processed is adequate, relevant and not excessive given the purpose.

    POPIA s.10 · Evidence to keep: Data minimisation review per processing activity; form audit.

  • C2.3A lawful justification exists for every processing activity: consent, contract, legal obligation, protection of a legitimate interest, public law duty, or legitimate interests of the responsible party or a third party.

    POPIA s.11(1) · Evidence to keep: Processing activity register with the lawful basis recorded per activity.

  • C2.4Where consent is the lawful basis, consent is voluntary, specific and informed, you can demonstrate the data subject consented, and there is a mechanism to withdraw consent at any time.

    POPIA s.11(2) · Evidence to keep: Consent records; consent capture screens; withdrawal procedure.

  • C2.5Data subjects can object to processing on reasonable grounds (and always for direct marketing) using the prescribed or an equivalent form, and processing stops on a valid objection.

    POPIA s.11(3) · Evidence to keep: Objection procedure and form; objection register.

  • C2.6Personal information is collected directly from the data subject unless a listed exception applies and is documented.

    POPIA s.12 · Evidence to keep: Collection source register; documented exceptions.

Condition 3 — Purpose Specification

Sections 13 to 14. Every purpose must be specific and every record must have an end date.

  • C3.1Each processing activity has a specific, explicitly defined and lawful purpose, and the data subject is made aware of it at the point of collection.

    POPIA s.13 · Evidence to keep: Processing register; privacy notices linked to each collection point.

  • C3.2A retention schedule defines maximum retention periods per category of personal information, and records are not kept longer than necessary.

    POPIA s.14(1)–(3) · Evidence to keep: Retention and disposal schedule; records management policy.

  • C3.3At the end of the retention period records are destroyed, deleted or de-identified so they cannot be reconstructed in intelligible form.

    POPIA s.14(4)–(5) · Evidence to keep: Destruction or de-identification procedure; destruction certificates.

  • C3.4Where processing is restricted (accuracy disputed, no longer needed but required for legal claims), restrictions are applied and the data subject is notified before they are lifted.

    POPIA s.14(6)–(7) · Evidence to keep: Restriction-of-processing procedure; restriction register.

Condition 4 — Further Processing Limitation

Section 15. New uses of existing data need a compatibility test, not a new privacy policy line.

  • C4.1Any further processing is assessed for compatibility with the original purpose against the section 15(2) factors: relationship, nature of the information, consequences, manner of collection and contractual rights.

    POPIA s.15 · Evidence to keep: Compatibility assessment template; completed assessments for new uses.

Condition 5 — Information Quality

Section 16. Accuracy is a legal obligation, not a data-hygiene nice-to-have.

  • C5.1Reasonably practical steps are taken to ensure personal information is complete, accurate, not misleading and updated where necessary, taking the purpose into account.

    POPIA s.16 · Evidence to keep: Data quality procedures; periodic data refresh or verification process.

Condition 6 — Openness

Sections 17 to 18, read with PAIA. If your privacy notice is missing one of the section 18 matters, this condition fails.

  • C6.1A PAIA manual is maintained and made available, addressing the documentation requirements for processing personal information.

    POPIA s.17 (with PAIA s.14/51) · Evidence to keep: Current PAIA manual published on the website and available at premises.

  • C6.2Data subjects are notified, before or as soon as reasonably practicable after collection, of every required matter: the information collected, its source, the name and address of the responsible party, the purpose, whether supply is voluntary or mandatory, consequences of not providing it, applicable laws, any intention to transfer abroad, recipients, and rights to access, correct and complain.

    POPIA s.18(1) · Evidence to keep: Privacy notices; collection-point notifications; just-in-time notices.

  • C6.3Where exemptions from notification are relied on, the basis is documented.

    POPIA s.18(4) · Evidence to keep: Documented exemption assessment per section 18(4).

Condition 7 — Security Safeguards

Sections 19 to 22. This condition carries the breach-notification duty and the operator contract requirement that catches most organisations out.

  • C7.1Appropriate, reasonable technical and organisational measures protect personal information against loss, damage, unauthorised destruction, unlawful access or processing.

    POPIA s.19(1) · Evidence to keep: Information security policy; ISO 27001 or equivalent ISMS.

  • C7.2A documented risk assessment identifies all reasonably foreseeable internal and external risks, with safeguards established, regularly verified and updated.

    POPIA s.19(2) · Evidence to keep: Personal information risk register; periodic risk assessment reports.

  • C7.3Generally accepted information security practices and procedures, both industry-specific and general, are adopted.

    POPIA s.19(3) · Evidence to keep: Mapping of controls to ISO 27001, NIST, King IV or sector standards.

  • C7.4Operators and persons acting under the responsible party's authority process personal information only with knowledge or authorisation and treat it as confidential.

    POPIA s.20 · Evidence to keep: Confidentiality undertakings; access control matrix; authorised-user list.

  • C7.5A written contract with every operator requires them to establish and maintain section 19 security measures and to notify the responsible party of security compromises immediately.

    POPIA s.21 · Evidence to keep: Operator (DPA) contract register; signed agreements.

  • C7.6A documented incident response and breach notification procedure exists: notify the Information Regulator and affected data subjects as soon as reasonably possible, with communications meeting the section 22(5) content requirements.

    POPIA s.22 · Evidence to keep: Incident response plan; breach register; notification templates.

Condition 8 — Data Subject Participation

Sections 23 to 25. People must be able to see, correct and delete what you hold about them.

  • C8.1A process confirms whether personal information about a data subject is held and provides the record or a description within a reasonable time, in a reasonable manner and format, at the prescribed fee.

    POPIA s.23 · Evidence to keep: Subject access request procedure and log; response templates.

  • C8.2A process lets data subjects request correction, deletion or destruction of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained.

    POPIA s.24 · Evidence to keep: Correction and deletion request procedure; request register.

  • C8.3The manner of access aligns with the procedures, forms and fees prescribed under PAIA.

    POPIA s.25 · Evidence to keep: PAIA-aligned request forms; fee schedule.

Special personal information and children

Sections 26 to 35. Health, biometrics, race, religion, trade union membership, political persuasion, sex life, criminal behaviour and any information about children need a specific statutory authorisation.

  • SP1Identify whether any special personal information is processed: religion or philosophy, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometric information or criminal behaviour.

    POPIA s.26 · Evidence to keep: Special personal information inventory.

  • SP2For each category of special personal information, a lawful authorisation under sections 27 to 33 is documented (consent, established by law, public interest, necessary for a legal claim, or deliberately made public).

    POPIA s.27–33 · Evidence to keep: Authorisation matrix per category.

  • CH1Identify whether personal information of children is processed.

    POPIA s.34 · Evidence to keep: Children's personal information inventory; age-gating assessment.

  • CH2Where children's information is processed, an authorisation under section 35 is in place: consent of a competent person, necessity for law or a legal claim, public interest with safeguards, or information deliberately made public by the child with consent.

    POPIA s.35 · Evidence to keep: Parental or guardian consent records; authorisation rationale.

Information Officer, exemptions and prior authorisation

Sections 36 to 38 and 55 to 58. Registration is a hard requirement, and some processing may not start at all until the Regulator authorises it.

  • EX1Where a Regulator-granted or function-based exemption is relied on, the authorisation is documented and current.

    POPIA s.37 & 38 · Evidence to keep: Regulator authorisation letter; documented function-based assessment.

  • IO1An Information Officer has been designated and registered with the Information Regulator before performing their duties.

    POPIA s.55(1)(a) & Regs · Evidence to keep: Registration confirmation from the Regulator.

  • IO2Deputy Information Officers are designated in writing to assist the Information Officer, with documented delegations.

    POPIA s.56 · Evidence to keep: Deputy designation letters; registration where required.

  • IO3Information Officer duties are actively discharged: encourage compliance, deal with requests, cooperate with the Regulator, develop and implement a compliance framework, conduct impact assessments, maintain the PAIA manual, run internal awareness and training, handle complaints and maintain the section 17 documentation.

    POPIA s.55(1)(b)–(f) & Reg 4 · Evidence to keep: Compliance framework; training records; PAIA manual; impact assessment reports.

  • PA1Determine whether any processing is subject to prior authorisation by the Regulator.

    POPIA s.57 · Evidence to keep: Prior-authorisation assessment register.

  • PA2Where prior authorisation applies, the Regulator has been notified and processing has not commenced until authorised or the statutory waiting period elapsed without objection.

    POPIA s.58 · Evidence to keep: Notification letter; authorisation or acknowledgement received.

Direct marketing, directories and automated decisions

Sections 69 to 71. Electronic direct marketing to non-customers is opt-in only.

  • DM1Electronic direct marketing is only sent with prior opt-in consent, or to an existing customer for similar products and services where opt-out was offered at collection and in every subsequent communication.

    POPIA s.69(1)–(3) · Evidence to keep: Marketing consent register; unsubscribe records; suppression list.

  • DM2Every direct marketing communication includes the sender's details and a clear opt-out mechanism.

    POPIA s.69(4) · Evidence to keep: Sample communications showing identification and opt-out.

  • DR1If directories are published, data subjects are informed free of charge of the purpose before inclusion, and given a free opt-out and the ability to verify, correct or withdraw their data.

    POPIA s.70 · Evidence to keep: Directory inclusion notice and opt-out procedure.

  • AD1Decisions with legal or substantial effects are not based solely on automated processing unless an exception applies and safeguards such as human review and the ability to make representations are in place.

    POPIA s.71 · Evidence to keep: Automated decision inventory; human review procedures; impact assessment.

Cross-border transfers, enforcement and account numbers

Sections 72 to 109. Cloud hosting outside South Africa is a cross-border transfer and needs a section 72 basis.

  • TB1Cross-border transfers only occur where at least one section 72 condition is met: adequacy, consent, contract necessity, a contract in the data subject's interest, or benefit to the data subject.

    POPIA s.72 · Evidence to keep: Transfer impact assessments; cross-border data-flow map; transfer agreements such as standard contractual clauses.

  • EN1An internal complaints procedure exists for data subjects, referencing the right to complain to the Regulator.

    POPIA s.74 & s.5(f) · Evidence to keep: Complaints procedure; complaints register; published contact details.

  • EN2A documented approach exists for cooperating with the Regulator: responding to information notices, assessments and enforcement notices within prescribed time-frames.

    POPIA s.81 & s.89–95 · Evidence to keep: Regulator engagement procedure; sample responses.

  • OP1Account numbers (bank, credit, store, customer) are processed only where lawful and necessary, with controls preventing unlawful disclosure, procurement and use.

    POPIA s.105–106 · Evidence to keep: Account-number handling procedure; access controls; logging.

  • OP2Leadership is aware of the penalty regime, including administrative fines up to R10 million, and there is board-level oversight of POPIA compliance.

    POPIA s.107–109 · Evidence to keep: Board or Exco reporting cadence; minutes.

Cross-cutting operational controls

The programme layer. These seven controls are what turn a one-off remediation project into defensible, ongoing compliance.

  • OC1An overall written POPIA or data protection policy is approved, communicated and reviewed at defined intervals.

    POPIA Programme · Evidence to keep: Version-controlled data protection policy with approval evidence.

  • OC2A current Records of Processing Activities (RoPA) or personal information inventory and data-flow map is maintained.

    POPIA Programme · Evidence to keep: RoPA spreadsheet or system entries.

  • OC3A Personal Information Impact Assessment methodology is in place, and assessments are performed for new or high-risk processing.

    POPIA Programme · Evidence to keep: Methodology document; completed assessments.

  • OC4An awareness and training programme covers all employees and contractors handling personal information, refreshed at least annually.

    POPIA Programme · Evidence to keep: Training plan; attendance records; e-learning completion reports.

  • OC5A vendor and operator management programme covers due diligence at onboarding, signed data processing agreements and periodic assurance.

    POPIA Programme · Evidence to keep: Vendor risk assessments; DPA register; assurance reports.

  • OC6A data subject request register tracks access requests, corrections, deletions, objections and complaints, with response times measured against statutory limits.

    POPIA Programme · Evidence to keep: Request register or case-management reports.

  • OC7Periodic internal audit or compliance monitoring of POPIA controls, with findings tracked to closure.

    POPIA Programme · Evidence to keep: Internal audit reports; management action plans.

POPIA compliance FAQ

What is POPIA?

POPIA is South Africa's Protection of Personal Information Act, 4 of 2013. It sets out how organisations (called responsible parties) may collect, use, store, share and delete personal information about people and companies (data subjects). It applies where the responsible party is domiciled in South Africa, or where processing takes place in South Africa. Compliance has been enforceable since 1 July 2021.

What are the 8 conditions for lawful processing?

Accountability, Processing Limitation, Purpose Specification, Further Processing Limitation, Information Quality, Openness, Security Safeguards, and Data Subject Participation. Every processing activity must satisfy all eight, not just the ones that are convenient.

Who needs to comply with POPIA?

Any public or private body that determines the purpose and means of processing personal information in or from South Africa — including sole proprietors and small businesses. Operators (processors) acting on a responsible party's instructions carry security and confidentiality duties under sections 20 to 21.

Do I have to register an Information Officer?

Yes. The head of the organisation is the Information Officer by default, and the Information Officer must be registered with the Information Regulator before performing their duties. Deputy Information Officers must be designated in writing.

What are the penalties for non-compliance?

The Information Regulator can issue enforcement notices, and failure to comply can result in administrative fines of up to R10 million or criminal liability including imprisonment, depending on the offence.

How long does POPIA compliance take?

For most mid-sized organisations, a first pass through the 54 requirements takes two to six weeks of focused work, with the bulk of the effort going into the processing register (RoPA), the retention schedule, operator contracts and the Information Officer registration.

Score this checklist in one afternoon

Instead of a spreadsheet, run the same 54 requirements in our POPIA platform: live compliance scoring per condition, evidence files attached to each item, a POPIA expert assistant that explains any requirement in plain language, and an official compliance certificate once you pass 80%. The assessment itself is free.

This guide is general information about the Protection of Personal Information Act, 4 of 2013 and is not legal advice. Consult a qualified adviser for your specific circumstances.