POPIA compliance done properly. Not just on paper.
Most organisations have a POPIA policy. Far fewer have implemented what it requires. Celagenix® has been ahead of POPIA since 2018, before it came into force. We know the difference between compliance on paper and compliance that holds up under scrutiny.
- Ahead of POPIA since 2018Before it came into force
- 100+ documents & templatesDeveloped from real engagements
- Training delivered at scaleInformation Officer, Deputy IO and staff
- Connected to the ecosystemThe full Celagenix® governance infrastructure
POPIA Compliance Status Assessment
Complete our structured assessment and receive a personalised POPIA compliance status report, reviewed by our data-privacy specialists. Understand where your organisation stands before committing to anything further.
Responses are treated with strict confidentiality. Assessment data is not shared with third parties. No automated processing, reviewed by a Celagenix® data-privacy specialist.
POPIA has been in force since 2021. The regulator is watching.
The grace period is long over and the Information Regulator is using its enforcement powers. For boards, POPIA compliance is not an IT matter, it is a governance obligation. King V Principle 10 places responsibility for data and information governance at board level, which means the board must satisfy itself that a compliant processing framework exists, not just a policy in a filing system.
The 8 conditions for lawful processing.
Every organisation that processes personal information must comply with all eight conditions, not just some. Custodian: the Information Regulator of South Africa, in force 1 July 2021.
POPIA compliance is a journey, not a checkbox.
Most organisations start with the assessment and discover the gap between where they are and where they need to be. We assemble the right elements from across the ecosystem to close that gap sustainably, not superficially.
POPIA Compliance Status Assessment, free
The starting point for every engagement. Complete the structured online assessment, our specialists review your responses and produce a personalised status report. You understand where you stand, what the gaps are, and what they mean in practice. No obligation to proceed.
Delivered free via celagenix.comFull gap assessment via BoardEvaluator™
A comprehensive, platform-driven gap assessment across all eight conditions. Cross-departmental in scope, it identifies not just the policy gaps but the operational and cultural gaps that policy documents alone cannot address.
Delivered via BoardEvaluator™ platformPrivacy framework, policy & PAIA manual
We build or rebuild the privacy governance infrastructure: a tailored POPIA privacy policy, a PAIA manual, a record of processing activities, data-subject request procedures, operator agreements and a breach-response procedure.
Delivered via senior advisoryInformation Officer implementation & training
POPIA requires every organisation to designate an Information Officer, and an untrained one cannot do the role effectively. We train Information Officers and deputies, deliver staff awareness at scale (up to 6,000+ employees), and train managers on their obligations.
Delivered via Academy platform, advisory facilitationAnnual review & compliance monitoring
POPIA compliance is not once-off. Processing activities change, systems are introduced, staff turn over. An annual BoardEvaluator™ review keeps the posture current and gives the board the evidence it needs to discharge its Principle 10 obligation.
Delivered via BoardEvaluator™, advisory supportMore than a policy. A working compliance system.
The difference between compliance on paper and compliance that works is implementation depth. We deliver across all four layers: documentation, assessment, training and ongoing governance. Together they form a system that holds up under regulatory scrutiny.
Policy & documents
Privacy policy, PAIA manual, record of processing activities, data-subject procedures, operator agreements and breach notification.
Assessment & audit
Free status assessment, full gap assessment via BoardEvaluator™, eight-condition audit and board-level compliance reporting.
Training & awareness
Information Officer and Deputy IO training, staff awareness at any scale, and manager-level obligations training.
Ongoing governance
Annual review via BoardEvaluator™, policy maintenance and regulatory-development monitoring.
The AI and POPIA intersection: AI tools process personal information. Every organisation using AI has a POPIA exposure it may not have assessed. We address the data-governance layer of AI adoption as part of both the POPIA engagement and the AI Governance programme.
POPIA is one expression of the same governance practice.
Data privacy sits inside King V Principle 10, alongside AI governance, cybersecurity and information management. At Celagenix® it is not a standalone service, it connects to the evaluation platform, the Academy and the broader governance advisory.
Personalised report, free, no obligation
› BoardEvaluator™, POPIA Compliance Assessmentboardevaluator.com, full gap assessment, eight conditions
↗ Celagenix® Academy, POPIA trainingcelagenix.academy, IO, Deputy IO and staff awareness, any scale
↗ AI Governance, POPIA intersectionAI tools process personal information, connected
›What organisations ask us about POPIA.
We already have a privacy policy. Are we compliant?
Having a policy is one of eight conditions, and arguably one of the easier ones. The harder conditions are accountability, processing limitation, security safeguards and data-subject participation. Most organisations with a policy do not yet have a functioning record of processing activities, an operationally capable Information Officer, documented data-subject procedures, or the required security safeguards. The free assessment tells you honestly where you stand across all eight.
What is an Information Officer and do we need to register one?
Yes. POPIA requires every private body to designate an Information Officer. The CEO is automatically the Information Officer unless someone else is designated, and they must be registered with the Information Regulator. Deputy Information Officers can assist, particularly in larger organisations. Celagenix® provides training for both roles.
What is a PAIA manual and do we need one?
The Promotion of Access to Information Act requires private bodies with more than 50 employees to compile a PAIA manual describing the organisation, the records it holds, and how to request access. Smaller organisations are currently exempt from the manual but still bound by POPIA's access rights. We draft both the PAIA manual and the POPIA policy as part of the same engagement where required.
We have thousands of employees. Can training be delivered at that scale?
Yes. The Academy is designed for this. Staff awareness training is delivered as self-directed digital modules, accessible to any number of employees on any device. Organisations with 6,000+ employees have completed POPIA awareness training through Celagenix®. White-label content options are available for delivery under your own brand.
How does POPIA connect to our AI adoption?
Closely. Most AI tools process personal information, triggering POPIA obligations around lawful processing, purpose limitation, minimisation and security. An organisation that has deployed AI across HR, marketing or operations without a POPIA lens is accumulating exposure it may not be aware of. We address this intersection as part of both the POPIA engagement and the AI Governance programme.
What can the Information Regulator actually do to us?
The Regulator has significant enforcement powers: enforcement notices requiring corrective action, investigations, and in serious cases administrative fines of up to R10 million or referral for criminal prosecution carrying up to 10 years' imprisonment for responsible parties. It has been increasingly active since 2021. The reputational consequence of a public enforcement action is often more damaging than the fine itself.
Find out where you actually stand, before the Regulator does.
The free POPIA Compliance Status Assessment is the right starting point. Understand your gaps clearly, with no obligation to proceed further.