Consulting
Celagenix Ecosystem
BoardEvaluator™ Academy Agency About Insights
Free POPIA Assessment →
Data Privacy & POPIA · Celagenix®

POPIA compliance
done properly. Not just
on paper.

Most organisations have a POPIA policy. Far fewer have actually implemented what it requires. Celagenix has been ahead of POPIA since 2018 - before it came into force. We know the difference between compliance on paper and compliance that holds up under scrutiny.

Ahead of POPIA since 2018 - before it came into force
100+ documents, templates, and policies developed from real engagements
Information Officer, Deputy IO, and staff training delivered at scale
Connected to the full Celagenix governance ecosystem
Free · No obligation
POPIA Compliance Status Assessment
Complete our structured assessment and receive a personalised POPIA compliance status report - reviewed by our data privacy specialists. Understand where your organisation stands before committing to anything further.
1
Complete the structured assessment online
2
Our specialists review your responses
3
Receive a personalised compliance status report
4
Clear next steps - no obligation to proceed further
Start the free assessment
Responses are treated with strict confidentiality. Assessment data is not shared with third parties. No automated processing - reviewed by a Celagenix data privacy specialist.
Why it matters

POPIA has been in force since 2021. The regulator is watching.

The grace period is long over. The Information Regulator has enforcement powers - and is using them. For boards and executives, POPIA compliance is not an IT department matter. It is a governance obligation.

King V Principle 10 places responsibility for the governance of data and information at the board level. This means the board needs to satisfy itself that the organisation has a compliant personal information processing framework - not just a privacy policy that sits in a filing system.

Celagenix has worked in this space since 2018 - well before POPIA came into force on 1 July 2021. That early start has produced something genuinely valuable: not just familiarity with the legislation, but 100+ documents, templates, and policies developed from real implementation across diverse organisations and sectors. The Academy systematises that library. The BoardEvaluator™ platform makes the compliance assessment scalable. The advisory handles the situations the systems cannot resolve.

2018
Ahead of POPIA since
100+
Documents & templates
8
Conditions for lawful processing
6,000+
Staff trained across engagements
POPIA - Protection of Personal Information Act 4 of 2013
The 8 Conditions for Lawful Processing
Every organisation that processes personal information must comply with all eight conditions - not just some.
1Accountability - the responsible party is accountable for compliance
2Processing limitation - lawful, minimised, adequate purpose
3Purpose specification - collected for specific, explicit purpose
4Further processing limitation - compatible with original purpose
5Information quality - accurate, complete, and up to date
6Openness - transparent policies and notification to data subjects
7Security safeguards - appropriate technical and organisational measures
8Data subject participation - right of access, correction, and deletion
Custodian: Information Regulator of South Africa · inforegulator.org.za · In force: 1 July 2021
How an engagement works

POPIA compliance is a journey, not a checkbox.

Most organisations start with the assessment and discover the gap between where they are and where they need to be. The Celagenix response assembles the right elements from across the ecosystem to close that gap - sustainably, not just superficially.

1
Entry point - free
POPIA Compliance Status Assessment

The starting point for every POPIA engagement. Complete the structured online assessment - our data privacy specialists review your responses and produce a personalised compliance status report. You understand where you stand, what the gaps are, and what they mean in practice. No obligation to proceed further. Most organisations that complete the assessment choose to.

Compliance status report
Gap identification
Priority recommendations
Delivered via: Free · celagenix.com
2
Full assessment
POPIA Gap Assessment via BoardEvaluator™

For organisations that need a comprehensive, platform-driven gap assessment across all eight conditions, the BoardEvaluator™ POPIA Compliance Assessment provides a structured, evidence-based analysis of your current compliance posture. Cross-departmental in scope, it identifies not just the policy gaps but the operational and cultural gaps that policy documents alone cannot address.

Full gap analysis
Eight conditions assessment
Risk prioritisation
Board-ready report
Delivered via: BoardEvaluator™ platform
3
Policy & documentation
Privacy Framework, Policy Development & PAIA Manual

With the gap assessment complete, we build or rebuild the organisation's privacy governance infrastructure. This includes a POPIA privacy policy tailored to your processing activities, a PAIA manual meeting the Promotion of Access to Information Act requirements, record of processing activities, data subject request procedures, and the operator agreements that govern how third parties handle personal information on your behalf.

Privacy policy
PAIA manual
ROPA documentation
Operator agreements
Breach response procedure
Delivered via: Senior advisory
4
People & capability
Information Officer Implementation & Training

POPIA requires every organisation to designate an Information Officer - and in practice, an Information Officer who has not been trained cannot do the role effectively. Celagenix provides structured training for Information Officers and Deputy Information Officers, staff awareness training at scale (we have delivered this to organisations with 6,000+ employees), and manager-level training on their specific obligations around personal information processing.

IO training
Deputy IO training
Staff awareness
Manager training
Delivered via: Academy platform Advisory facilitation
5
Ongoing governance
Annual Review & Compliance Monitoring

POPIA compliance is not a once-off project. Processing activities change. New systems are introduced. Staff turn over. The regulatory environment evolves. An annual BoardEvaluator™ POPIA review keeps the compliance posture current - and gives the board the evidence it needs to discharge its King V Principle 10 obligation to satisfy itself that data governance is functioning effectively.

Annual review cycle
Board compliance report
Policy update management
Delivered via: BoardEvaluator™ Advisory support
What we deliver

More than a policy.
A working compliance system.

The difference between POPIA compliance on paper and POPIA compliance that works is implementation depth. Documents alone are not enough - the organisation has to understand, internalise, and operationalise what they require.

Celagenix delivers across all four layers of compliance: the documentation, the assessment, the training, and the ongoing governance. Individually any of these layers can be addressed as a standalone engagement. Together they form a compliance system that holds up under regulatory scrutiny.

📄 Documentation & Policy
Privacy policy aligned to POPIA's eight conditions
PAIA manual meeting Information Regulator requirements
Record of processing activities (ROPA)
Data subject request and complaints procedures
Operator and third-party agreements
Personal information breach notification procedure
📊 Assessment & Audit
Free POPIA Compliance Status Assessment
Full gap assessment via BoardEvaluator™
Eight-condition compliance audit
Board-level compliance reporting
🎓 Training & Awareness
Information Officer and Deputy IO training
Staff POPIA awareness (any scale)
Manager-level processing obligations training
Board governance briefing on Principle 10 obligations
🔄 Ongoing Governance
Annual compliance review via BoardEvaluator™
Policy maintenance and update management
Regulatory development monitoring
Built from real engagements
100+
Documents, templates, policies, and procedures developed from real POPIA implementation engagements since 2018. Not generic templates downloaded from the internet - frameworks built and tested across diverse organisations, industries, and compliance contexts in South Africa.

On the AI and POPIA intersection: AI tools process personal information. Every organisation that uses AI across its operations has a POPIA exposure it may not have assessed. Celagenix addresses this as an integrated part of both the POPIA engagement and the AI Governance programme - because the data governance layer of AI adoption is a POPIA matter, not just a technology matter.

The ecosystem

POPIA is one expression of the same governance practice.

Data privacy governance sits inside King V Principle 10 - alongside AI governance, cybersecurity, and information management. At Celagenix it is not a standalone service. It connects to the evaluation platform, the Academy, and the broader governance advisory practice.

An organisation that addresses POPIA through the Celagenix ecosystem gets more than compliance. It gets a data governance capability that contributes to the board's overall governance posture - and that connects directly to the annual BoardEvaluator™ evaluation cycle.

Common questions

What organisations ask us about POPIA.

We already have a privacy policy. Are we compliant?

Having a privacy policy is one of eight conditions for lawful processing under POPIA - and it is arguably one of the easier ones. The harder conditions are accountability, processing limitation, security safeguards, and data subject participation. Most organisations that have a policy do not yet have a functioning record of processing activities, an operationally capable Information Officer, documented data subject procedures, or the security safeguards that POPIA requires. The free assessment will tell you honestly where you stand across all eight conditions - not just on the policy question.

What is an Information Officer and do we need to register one?

Yes - POPIA requires every private body (company, close corporation, partnership, or sole proprietor) to designate an Information Officer. The CEO is automatically the Information Officer unless someone else is designated. Information Officers must be registered with the Information Regulator. They are responsible for ensuring POPIA compliance within the organisation, handling data subject requests and complaints, and liaising with the Information Regulator. Deputy Information Officers can be designated to assist - particularly useful in larger organisations or those with complex processing activities. Celagenix provides training for both roles.

What is a PAIA manual and do we need one?

The Promotion of Access to Information Act requires private bodies with more than 50 employees to compile a PAIA manual - a document that describes the organisation, the categories of records it holds, and how a person can request access to those records. Organisations with fewer than 50 employees are currently exempt from the manual requirement but are still bound by POPIA's data subject access rights. The PAIA manual and the POPIA privacy policy are related but separate obligations - Celagenix drafts both as part of the same engagement where both are required.

We have thousands of employees. Can training be delivered at that scale?

Yes. The Celagenix Academy is designed precisely for this. Staff awareness training is delivered as self-directed digital modules - accessible to any number of employees simultaneously, on any device, at their own pace. Organisations with 6,000+ employees have completed staff POPIA awareness training through Celagenix. The Academy's enterprise subscription model makes large-scale delivery commercially straightforward. For organisations that want the training under their own brand on their own LMS, white-label content options are available through the Academy methodology product.

How does POPIA connect to our AI adoption?

Closely and directly. Most AI tools process personal information - which means their adoption triggers POPIA obligations around lawful processing, purpose limitation, data minimisation, and security safeguards. An organisation that has deployed AI tools across HR, marketing, customer service, or operations without a POPIA lens on that deployment is accumulating compliance exposure it may not be aware of. Celagenix addresses the data governance layer of AI adoption as part of both the POPIA engagement and the AI Governance programme. For organisations facing both challenges simultaneously, an integrated engagement is typically more efficient and more effective than two separate exercises.

What can the Information Regulator actually do to us?

The Information Regulator has significant enforcement powers under POPIA. These include issuing enforcement notices requiring specific corrective action, conducting investigations, and - in serious cases - issuing administrative fines of up to R10 million or referring matters for criminal prosecution, which carries fines or imprisonment of up to 10 years for responsible parties. The Regulator has been increasingly active since the grace period ended in 2021 - investigating complaints, issuing enforcement notices, and making its intentions around enforcement clear. The reputational consequence of a public enforcement action is often more damaging than the fine itself, particularly for organisations that handle sensitive personal information.

Start with a free assessment

Find out where you actually stand - before the Regulator does.

The free POPIA Compliance Status Assessment is the right starting point. Understand your gaps clearly, with no obligation to proceed further.

📞 +27 12 755 5528 💬 WhatsApp +27 73 047 5262 ✉ advisory@celagenix.com