Compliance software · South Africa

POPIA and GRC compliance software for South African businesses

POPIA gives every South African business a clear privacy duty — an Information Officer, eight conditions for lawful processing and a duty to report security compromises — and the Information Regulator now enforces it. AI Pazz Govnex turns POPIA, PAIA and King IV governance into owned controls and evidence.

In short

Every South African organisation that processes personal information must follow the Protection of Personal Information Act (POPIA): meet its eight conditions for lawful processing, register an Information Officer with the Information Regulator, and report security compromises to the Regulator and affected people as soon as reasonably possible. It must also keep a PAIA manual. Govnex keeps POPIA as your own control set with owners and evidence.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in South Africa

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

POPIA

Protection of Personal Information Act 4 of 2013 (POPIA)

Track it with your own controls
Regulator
Information Regulator
Who it applies to
Every public and private body that processes personal information in South Africa — of people and of juristic persons — enforced since 1 July 2021.
If you fall short
Administrative fines of up to ZAR 10 million, and imprisonment of up to 10 years for the most serious offences.
What it asks of you
  • The eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation
  • Register the Information Officer (and deputies) with the Information Regulator
  • Notify the Regulator and affected people of a security compromise as soon as reasonably possible
  • Prior authorisation for certain processing, opt-in for electronic direct marketing, and conditions on cross-border transfers

Source: inforegulator.org.za

PAIA

Promotion of Access to Information Act 2 of 2000 (PAIA)

Track it with your own controls
Regulator
Information Regulator
Who it applies to
Public and private bodies.
If you fall short
Offences and fines under PAIA.
What it asks of you
  • A PAIA manual describing the records you hold and how to request them
  • Answer access requests within the statutory time limits

Source: inforegulator.org.za

King IV

King IV Report on Corporate Governance

Track it with your own controls
Regulator
Institute of Directors in South Africa (voluntary code; JSE-listed companies apply it)
Who it applies to
Listed companies — and any organisation that wants good governance on an 'apply and explain' basis.
If you fall short
None in itself; required by the JSE Listings Requirements for listed companies.
What it asks of you
  • The governing body governs risk, and technology and information, in a way that supports objectives
  • Compliance with laws and adopted codes, and assurance over the organisation's reports

Source: iodsa.co.za

Joint Standard 2 of 2024

Joint Standard 2 of 2024 — Cybersecurity and Cyber Resilience

Track it with your own controls
Regulator
Financial Sector Conduct Authority and the Prudential Authority
Who it applies to
Banks, insurers, market infrastructure and other financial institutions.
If you fall short
Supervisory action by the FSCA and Prudential Authority.
What it asks of you
  • A cybersecurity strategy and governance approved by the governing body
  • Cyber risk management, testing, incident reporting and third-party security

Source: fsca.co.za

Standards South Africa buyers ask for

How AI Pazz Govnex helps in South Africa

What you needHow Govnex does itModule
POPIA's eight conditionsAdd POPIA as your own control set, assign owners — your Information Officer first — and collect evidence.
Security compromise notificationEach compromise an issue with its notification, owner and corrective actions.
Personal information inventoryA register of personal information, purposes, owners and cross-border transfers — the basis of your PAIA manual.
King IV risk and IT governanceRisk registers with treatments and board-ready reports across the organization.
Policies and awarenessPOPIA and security policies with tracked acknowledgement.

Your first 90 days

  1. 1Register your Information Officer and deputies with the Information Regulator.
  2. 2Add POPIA's conditions as controls and assign owners.
  3. 3Map the personal information you hold and update your PAIA manual.
  4. 4Put a security compromise notification process in place.
  5. 5Report your POPIA position to the board, King IV style.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in South Africa: questions and answers

Who must comply with POPIA?
Every public and private body that processes personal information in South Africa, whatever its size. POPIA also protects the information of juristic persons such as companies.
Do we need to register an Information Officer?
Yes. The head of a private body is its Information Officer by default, and must be registered — with any deputies — with the Information Regulator.
What happens after a security compromise?
Notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering it, using the Regulator's prescribed form.
What are the POPIA penalties?
Administrative fines of up to ZAR 10 million, and imprisonment of up to 10 years for the most serious offences, plus civil claims from affected people.
Is POPIA in the Govnex Library?
Not yet as a ready-made set — add its conditions as your own controls. ISO 27001, NIST CSF and ISO 22301 are ready-made.
What else does Govnex include?
Policies, risk registers, issues, internal audits, regulatory change, a data register and ESG & EHS in one workspace.