Consulting
Celagenix Ecosystem
BoardEvaluator™ Academy Agency About Insights
Start assessment →
Free · Data Privacy & POPIA · Celagenix®

POPIA Compliance
Status Assessment

Complete this structured assessment and receive a personalised POPIA compliance status report - reviewed personally by our data privacy specialists. Understand where you stand before committing to anything further.

Free - no payment, no obligation to proceed further
Reviewed personally by Celagenix data privacy specialists
Responses handled with strict confidentiality
Ahead of POPIA since 2018 - before it came into force
What to expect
Four steps to your compliance report
1
Complete the structured assessment below - covering your organisation's current position across all eight POPIA conditions for lawful processing
2
Submit your responses - the assessment takes approximately 10–15 minutes to complete
3
Our data privacy specialists review your responses and prepare a personalised compliance status report
4
Receive your report - with clear findings, identified gaps, and recommended next steps specific to your organisation
Responses are treated with strict confidentiality and are not shared with third parties. This is not an automated tool - a specialist reviews every submission personally.

The 8 conditions for lawful processing

1Accountability
2Processing limitation
3Purpose specification
4Further processing limitation
5Information quality
6Openness
7Security safeguards
8Data subject participation
POPIA Compliance Status Assessment · Free · Personalised report
Organisation Details Step 1 of 12
Organisation Details
Tell us about your organisation
This information appears on your compliance report and helps us contextualise findings correctly.
Please enter your organisation name.
Please select an entity type.
Please select a sector.
Please select a range.
Please select a date.
Please enter a name.
Please enter a position.
Please enter a valid email address.
Section 1 of 10
Information Officer & Governance
POPIA requires every responsible party to appoint an Information Officer. This section assesses your governance structure.
Please select an option.
Please select an option.
Please select an option.
Please select an option.
Please select an option.
Section 2 of 10
Personal Information Inventory
Understanding what personal information your organisation collects and processes is fundamental to POPIA compliance.
Please select an option.
Select all that apply.
Please select at least one category.
Special PI includes health data, biometrics, religious/political beliefs, race, trade union membership, criminal records, and sexual orientation.
Please select an option.
Please select an option.
Section 3 of 10
Privacy Policies & Procedures
A documented policy framework demonstrates your commitment to compliance and provides procedural guidance to staff.
Please select an option.
Select all that apply.
Please make at least one selection.
Please select an option.
Section 4 of 10
Security Safeguards
Rate your implementation level for each security measure: 1 = Basic/None, 2 = Initial, 3 = Defined, 4 = Managed, 5 = Optimised.
Measure12345
Access Control
Encryption
Firewalls
Anti-virus / Anti-malware
Backup Systems
Intrusion Detection
1 - Basic / None3 - Defined5 - Optimised
Please rate all technical measures.
Measure12345
Physical Security
Clean Desk Policy
Visitor Management
Document Management
Employee Training
Incident Response
1 - Basic / None3 - Defined5 - Optimised
Please rate all organisational measures.
Please select an option.
Section 5 of 10
Third-Party Management
POPIA holds responsible parties accountable for how operators (third parties) process personal information on their behalf.
Please select an option.
Please select an option.
Please select an option.
Section 6 of 10
Data Subject Rights
POPIA grants data subjects the right to access, correct, delete, or object to the processing of their personal information.
Access Requests
Correction Requests
Deletion Requests
Objection to Processing
Please answer all four request types.
Enter 0 if none received.
Please select an option.
Section 7 of 10
Direct Marketing
POPIA strictly regulates unsolicited direct marketing. Consent must be explicit and properly recorded.
Through which channels? (Select all that apply)
Please select an option.
Section 8 of 10
Training & Awareness
Human error is a leading cause of data breaches. An informed workforce is one of your most important compliance controls.
Please select an option.
Please select an option.
Please select an option.
Section 9 of 10
Incident Management
POPIA requires notification to the Information Regulator and affected data subjects in the event of a data breach.
Please select an option.
Please select an option.
Please select an option.
Section 10 of 10
Cross-border Transfers
Transferring personal information outside South Africa requires adequate protection. Cloud-hosted services may constitute a cross-border transfer.
Note: cloud services, email platforms, or software hosted on overseas servers may qualify as cross-border transfers.
Please select an option.
Select all that apply. If no transfers occur, select "Not applicable".
Please make at least one selection.
Declaration & Submission
Review and submit your assessment
Please confirm your details and submit your completed assessment.
I hereby declare that the information provided in this POPIA Compliance Assessment is true and accurate to the best of my knowledge. I understand that Celagenix® Corporate Consulting will use this information solely to produce a personalised compliance assessment report, and that this assessment does not constitute legal advice.
Please enter your name.
Please enter your position.
You must confirm the accuracy of your responses.

Assessment submitted

Your responses have been received. Our team will review and deliver your personalised compliance report to within 48 hours.

Check your junk folder if you don't hear from us. Questions? info@celagenix.com

🔒 Your responses are handled in accordance with our Privacy Policy and the POPIA requirements we help our clients meet.

Why this matters now

The Regulator is watching. The grace period is over.

POPIA came into full force on 1 July 2021. The Information Regulator has enforcement powers - and is using them. For boards and executives, this is a governance obligation, not an IT matter.

King V Principle 10 places responsibility for the governance of data and information at board level. The board must satisfy itself that the organisation has a compliant personal information processing framework - not just a privacy policy in a filing system.

Celagenix has been working in this space since 2018 - before POPIA came into force. The assessment reflects that depth: 100+ documents, templates, and policies developed from real implementation across diverse organisations and sectors over more than seven years.

POPIA advisory Full gap assessment
What non-compliance can cost
⚖️

Administrative fines up to R10 million

The Information Regulator can issue administrative fines for serious POPIA contraventions - per incident, not capped across the organisation.

🔒

Criminal prosecution

Certain offences under POPIA carry criminal liability - including fines or imprisonment of up to 10 years for responsible parties. Personal liability for directors and officers applies.

📢

Reputational damage

The Information Regulator publishes enforcement actions. A public enforcement notice is often more damaging than the fine - particularly for organisations handling sensitive personal information.

📋

Enforcement notices

The Regulator can issue notices requiring specific corrective action within defined timeframes. Non-compliance with an enforcement notice is itself a criminal offence.

Source: Protection of Personal Information Act 4 of 2013 · Information Regulator of South Africa · inforegulator.org.za
After the assessment

What happens next is up to you.

The assessment report stands on its own. There is no obligation to engage Celagenix further. But if the report identifies gaps - as it typically does - here is what the ecosystem can do for you.

📊
Full gap assessment via BoardEvaluator™

For a comprehensive, platform-driven assessment across all eight conditions - cross-departmental, evidence-based, and producing a board-ready report.

BoardEvaluator™
⚖️
Advisory - policy, documentation, IO implementation

Senior advisory for policy development, PAIA manual, Information Officer implementation, and the documentation infrastructure that real compliance requires.

POPIA advisory
🎓
Training - staff awareness, IO & Deputy IO

Structured training for Information Officers, Deputy Information Officers, and staff awareness at any scale - delivered through the Celagenix Academy.

Academy training