CertusFree compliance check

South Africa · POPIA Compliance

Is your business the Information Regulator’s next audit target?

The Information Regulator is shifting to proactive audits for 2026–2027, with financial services, insurance, healthcare, retail, telecoms and the public sector named first. Registering an Information Officer is step one — most SMEs stop there, and that’s exactly where audits start.

5 minutes. No card required. You’ll get a maturity score and a breakdown of exactly what’s missing.

Named as priority sectors by the Information Regulator:Financial ServicesInsuranceHealthcareRetailTelecommunicationsPublic Sector

Registered isn’t the same as compliant.

POPIA runs on a ladder, not a trapdoor — complaint, enforcement notice, then administrative fine or criminal referral only if the notice is ignored. The real risk isn’t a single mistake; it’s not having data mapping, the 8 lawful processing conditions, or a documented policy in place when the Regulator asks.

R10m
Maximum administrative fine
Issued for failing to comply with an enforcement notice — not for the original gap itself.
10 yrs
Maximum imprisonment
Reserved for ignoring enforcement notices or obstructing the Regulator, not ordinary mistakes.
2026–27
Proactive audit rollout
The Information Regulator is moving from complaint-driven to self-initiated inspections.

One workspace, from registration to audit-ready.

Information Officer wizard

A 5-minute diagnosis tells you whether you need to register, then walks you through the eServices portal steps.

Data mapping workspace

Document what personal information you hold, where it flows, and why — in plain questions, not legal language.

8 lawful processing conditions

A live checklist against POPIA Chapter 3, so you always know exactly which conditions are met and which aren't.

Policy generation

Privacy Policy and PAIA Manual drafted from your own data map, ready for legal review instead of a blank page.

Consent management

An embeddable widget for your site or app that actually logs consent, instead of a static checkbox no one can prove.

Breach response workflow

When something goes wrong, know your notification deadlines and have the right form ready — not a scramble.

Free 5-minute compliance maturity check

Answer a few questions about your sector, data mapping, documentation and consent process. Get a maturity score out of 100 and a category-by-category breakdown of what to fix first.

Start my free check

Start free. Upgrade when the gaps need fixing.

Basic
FreeAlways free
  • Information Officer registration wizard
  • 8 lawful conditions checklist (view only)
  • Registration renewal reminders
Start free
Plus
R599–999per month
  • Everything in Basic
  • Data mapping workspace (edit)
  • Privacy Policy & PAIA Manual generation
  • Consent management widget
  • DSAR & breach response workflows
Start free trial
Pro
R5,000–15,000scoped project, on top of Plus
  • Sector-specific template packages
  • Audit-response report support
  • Multi-site onboarding
Talk to us

Indicative pricing, to be confirmed during the pilot phase.

Grounded in the actual law.

POPIA gives effect to section 14 of the Constitution (the right to privacy). The substantive law is the Protection of Personal Information Act, 2013 (Act 4 of 2013), enforced by the Information Regulator alongside PAIA (the Promotion of Access to Information Act).

Certus turns the Act’s requirements — Chapter 3’s eight lawful processing conditions, the Information Officer registration duty under section 55, and the rest — into a workspace you can act on directly, without reading the Act itself.

Find out where you actually stand.

Get your free compliance score