Skip to main content

Protection of Personal Information Act 4 of 2013 (POPIA)

Your growth shouldn’t come at the cost of privacy risk. The Protection of Personal Information Act (POPIA) is South Africa’s primary data protection law. It governs how personal information must be collected, stored, used, and shared — and it applies to any business processing personal data in South Africa, whether you’re handling customer sign-ups, employee records, or marketing lists.

If you’re a fast-growing business, POPIA matters more than you think.

What is POPIA, really?

POPIA gives effect to the constitutional right to privacy. It sets out how organisations must lawfully process personal information — including rules around transparency, consent, security, and accountability. It’s South Africa’s answer to global data protection trends like the EU’s GDPR, and while it shares many of the same principles, it’s been adapted to our local legal system and economic realities.

POPIA isn’t just about compliance. It’s about trust.

The law is built on eight core conditions for lawful processing. These include:

  • Collecting only what you need (data minimisation)
  • Being transparent about how data is used (purpose specification)
  • Keeping information accurate, secure, and confidential
  • Respecting individual rights like access, correction, and objection

It also introduces rules for special personal information, children’s data, cross-border transfers, and direct marketing, as well as mandatory breach notifications and enforcement by the Information Regulator—a statutory body with powers to investigate, fine, and take legal action.

Why it matters to scaleups

Startups often begin with good intentions, but as you grow, systems fragment, data gets duplicated, and privacy risk creeps in. You onboard more tools. You sign up more users. You raise a funding round. You start working cross-border. Suddenly, data protection is no longer a checkbox; instead, it’s a board-level conversation.

  1. Investors are asking for your compliance posture.
  2. Customers are asking how you protect their data.
  3. Regulators are asking about your breach preparedness.

That’s where we come in.

Products built for the scaleup journey

We’ve designed a full ecosystem of tools, templates, and transformation services all mapped to POPIA and made for real-world growth. Whether you’re pre-seed or Series C, we meet you where you are and help you scale trust, not just tech.

Product What it helps you do What you get Best for Price (ZAR)
POPIA explainer video Understand POPIA basics in 5 minutes Animated video Everyone Free
POPIA rights quick guide Know data subject rights under POPIA 2-page PDF guide Individuals, Employees Free
Self-assessment quiz: Are you POPIA-ready? Diagnose your POPIA gaps in 2 minutes Online quiz + action plan SMEs, Compliance leads Free
POPIA compliance checklist Check your organisation’s compliance status Editable checklist Business owners, HR Free
30 Days to Compliance Toolkit Build a compliance foundation fast Templates + guide Startups, SMEs R8499
POPIA Notice and Consent Pack Get ready-to-use notices and forms Editable templates Website owners, HR R11699
DIY POPIA Compliance Plan Create your own compliance plan Workbook + video guide SMEs, Non-profits R22,899
POPIA Officer-in-a-Box Get virtual compliance support Templates + advice updates SMEs, Growing teams R48,900/month
POPIA Risk Mapping Sprint Map your data flows and risks fast Live workshops + templates Compliance teams, IT leads R65,000
POPIA Gap Analysis Diagnostic Find and fix your compliance gaps Full diagnostic report Corporates, Legal teams R120,000
End-to-end POPIA Implementation Achieve full POPIA compliance 3-month project delivery Medium and large organisations From R360,000
Virtual DPO (vDPO) Service Outsource your Data Protection Officer role Ongoing advisory + reporting Businesses without in-house DPOs R624,000/year
Board Training: POPIA and Beyond Train leadership on privacy risks 1-day live training + materials Boards, Executives R84,000/session
The POPIA Trust Transformation™ Build a trust-centred, privacy-first organisation 6-month consulting programme Enterprises, Corporates From R900,000

Not sure where to start?

Take our free 2-minute quiz and get a custom POPIA roadmap for your scaleup.
No forms, no fluff—just clarity.