Most organisations have a POPIA policy. Far fewer have actually implemented what it requires. Celagenix has been ahead of POPIA since 2018 - before it came into force. We know the difference between compliance on paper and compliance that holds up under scrutiny.
The grace period is long over. The Information Regulator has enforcement powers - and is using them. For boards and executives, POPIA compliance is not an IT department matter. It is a governance obligation.
King V Principle 10 places responsibility for the governance of data and information at the board level. This means the board needs to satisfy itself that the organisation has a compliant personal information processing framework - not just a privacy policy that sits in a filing system.
Celagenix has worked in this space since 2018 - well before POPIA came into force on 1 July 2021. That early start has produced something genuinely valuable: not just familiarity with the legislation, but 100+ documents, templates, and policies developed from real implementation across diverse organisations and sectors. The Academy systematises that library. The BoardEvaluator™ platform makes the compliance assessment scalable. The advisory handles the situations the systems cannot resolve.
Most organisations start with the assessment and discover the gap between where they are and where they need to be. The Celagenix response assembles the right elements from across the ecosystem to close that gap - sustainably, not just superficially.
The starting point for every POPIA engagement. Complete the structured online assessment - our data privacy specialists review your responses and produce a personalised compliance status report. You understand where you stand, what the gaps are, and what they mean in practice. No obligation to proceed further. Most organisations that complete the assessment choose to.
For organisations that need a comprehensive, platform-driven gap assessment across all eight conditions, the BoardEvaluator™ POPIA Compliance Assessment provides a structured, evidence-based analysis of your current compliance posture. Cross-departmental in scope, it identifies not just the policy gaps but the operational and cultural gaps that policy documents alone cannot address.
With the gap assessment complete, we build or rebuild the organisation's privacy governance infrastructure. This includes a POPIA privacy policy tailored to your processing activities, a PAIA manual meeting the Promotion of Access to Information Act requirements, record of processing activities, data subject request procedures, and the operator agreements that govern how third parties handle personal information on your behalf.
POPIA requires every organisation to designate an Information Officer - and in practice, an Information Officer who has not been trained cannot do the role effectively. Celagenix provides structured training for Information Officers and Deputy Information Officers, staff awareness training at scale (we have delivered this to organisations with 6,000+ employees), and manager-level training on their specific obligations around personal information processing.
POPIA compliance is not a once-off project. Processing activities change. New systems are introduced. Staff turn over. The regulatory environment evolves. An annual BoardEvaluator™ POPIA review keeps the compliance posture current - and gives the board the evidence it needs to discharge its King V Principle 10 obligation to satisfy itself that data governance is functioning effectively.
The difference between POPIA compliance on paper and POPIA compliance that works is implementation depth. Documents alone are not enough - the organisation has to understand, internalise, and operationalise what they require.
Celagenix delivers across all four layers of compliance: the documentation, the assessment, the training, and the ongoing governance. Individually any of these layers can be addressed as a standalone engagement. Together they form a compliance system that holds up under regulatory scrutiny.
On the AI and POPIA intersection: AI tools process personal information. Every organisation that uses AI across its operations has a POPIA exposure it may not have assessed. Celagenix addresses this as an integrated part of both the POPIA engagement and the AI Governance programme - because the data governance layer of AI adoption is a POPIA matter, not just a technology matter.
Data privacy governance sits inside King V Principle 10 - alongside AI governance, cybersecurity, and information management. At Celagenix it is not a standalone service. It connects to the evaluation platform, the Academy, and the broader governance advisory practice.
An organisation that addresses POPIA through the Celagenix ecosystem gets more than compliance. It gets a data governance capability that contributes to the board's overall governance posture - and that connects directly to the annual BoardEvaluator™ evaluation cycle.
Having a privacy policy is one of eight conditions for lawful processing under POPIA - and it is arguably one of the easier ones. The harder conditions are accountability, processing limitation, security safeguards, and data subject participation. Most organisations that have a policy do not yet have a functioning record of processing activities, an operationally capable Information Officer, documented data subject procedures, or the security safeguards that POPIA requires. The free assessment will tell you honestly where you stand across all eight conditions - not just on the policy question.
Yes - POPIA requires every private body (company, close corporation, partnership, or sole proprietor) to designate an Information Officer. The CEO is automatically the Information Officer unless someone else is designated. Information Officers must be registered with the Information Regulator. They are responsible for ensuring POPIA compliance within the organisation, handling data subject requests and complaints, and liaising with the Information Regulator. Deputy Information Officers can be designated to assist - particularly useful in larger organisations or those with complex processing activities. Celagenix provides training for both roles.
The Promotion of Access to Information Act requires private bodies with more than 50 employees to compile a PAIA manual - a document that describes the organisation, the categories of records it holds, and how a person can request access to those records. Organisations with fewer than 50 employees are currently exempt from the manual requirement but are still bound by POPIA's data subject access rights. The PAIA manual and the POPIA privacy policy are related but separate obligations - Celagenix drafts both as part of the same engagement where both are required.
Yes. The Celagenix Academy is designed precisely for this. Staff awareness training is delivered as self-directed digital modules - accessible to any number of employees simultaneously, on any device, at their own pace. Organisations with 6,000+ employees have completed staff POPIA awareness training through Celagenix. The Academy's enterprise subscription model makes large-scale delivery commercially straightforward. For organisations that want the training under their own brand on their own LMS, white-label content options are available through the Academy methodology product.
Closely and directly. Most AI tools process personal information - which means their adoption triggers POPIA obligations around lawful processing, purpose limitation, data minimisation, and security safeguards. An organisation that has deployed AI tools across HR, marketing, customer service, or operations without a POPIA lens on that deployment is accumulating compliance exposure it may not be aware of. Celagenix addresses the data governance layer of AI adoption as part of both the POPIA engagement and the AI Governance programme. For organisations facing both challenges simultaneously, an integrated engagement is typically more efficient and more effective than two separate exercises.
The Information Regulator has significant enforcement powers under POPIA. These include issuing enforcement notices requiring specific corrective action, conducting investigations, and - in serious cases - issuing administrative fines of up to R10 million or referring matters for criminal prosecution, which carries fines or imprisonment of up to 10 years for responsible parties. The Regulator has been increasingly active since the grace period ended in 2021 - investigating complaints, issuing enforcement notices, and making its intentions around enforcement clear. The reputational consequence of a public enforcement action is often more damaging than the fine itself, particularly for organisations that handle sensitive personal information.
The free POPIA Compliance Status Assessment is the right starting point. Understand your gaps clearly, with no obligation to proceed further.