PAIA & POPIA Compliance

Legal Data Protection

Audit, implementation, and ongoing support for South African data protection laws.

PAIA (access to information) and POPIA (personal data protection) are South African laws. Penalties for non-compliance: fines up to R10+ million. Most SMEs aren't compliant. Most don't know it. We audit your compliance, implement missing policies and procedures, and keep you protected.

How We Execute Compliance

Audit Phase (Weeks 1-2)

  • Current state assessment: What data do you collect? How do you store it? Who has access?
  • PAIA compliance check: Do you have a PAIA Manual? Can people request access?
  • POPIA compliance check: Do you have privacy policies? Consent mechanisms? Data deletion processes?
  • Gap identification: What's missing? What's broken?

Planning Phase (Week 3)

  • Compliance roadmap: Which gaps are critical? Which are moderate?
  • Timeline and scope: How to fix it without disrupting operations
  • Cost-benefit: Some fixes are easy; some require system changes

Implementation Phase (Weeks 4-8)

  • Policies: Draft and finalize privacy policy, PAIA manual, data retention policy
  • Consent mechanisms: Add opt-in/opt-out to forms, email, website
  • Data handling procedures: How to respond to access/deletion requests
  • Staff training: Your team knows the rules
  • Systems updates: Technical implementation (if needed)

Execution principles

Legal Compliance Isn't Optional

It's the law. Fines are real. Reputational damage is real. We treat this as mandatory, not nice-to-have.

It's Not Just a Privacy Policy

Policies are one piece. Actual processes matter — how to handle data requests, how to delete data, how to manage consent.

Different Rules for Different Data

Personal data has strict rules. Aggregate/anonymized data has looser rules. We help you classify your data correctly.

Ongoing Monitoring

Laws change. Your systems change. We help you stay updated. Optional ongoing support (limited) available post-implementation.

Proof

No case studies.Yet.

We don't have published case studies. Rather than invent one, we're telling you that directly — you'd be among the first clients we document.

Every business has different data handling, different systems, different gaps. We'll show your compliance roadmap and implementation results.

PAIA & POPIA Compliance Pricing

Project-Based Fee (Audit, Planning, Implementation). Fixed scope, fixed price. Paid 50% upfront, 50% at completion.

Compliance Audit Only

R25,000

Best for: You want to know your current state before deciding on implementation

  • Audit of current data handling
  • PAIA compliance assessment
  • POPIA compliance assessment
  • Gap report with recommendations
  • 2-3 weeks

Audit + Implementation (Medium/Complex)

R60,000

Best for: Multiple data sources, complex systems, multiple staff, regulatory complexity

  • Everything in Small Implementation, plus:
  • Data retention policy and deletion procedures
  • Advanced consent mechanisms (granular preferences)
  • Request handling procedures (documented)
  • Systems audit and recommendations
  • Enhanced staff training (multiple sessions)
  • Optional: 3 months limited post-launch support (email only)
  • 6-8 weeks

What's Included / What's Not

Included:

  • ✓ Compliance audit
  • ✓ Gap identification
  • ✓ Privacy policy
  • ✓ PAIA manual
  • ✓ Consent mechanisms
  • ✓ Data handling procedures
  • ✓ Staff training

Not Included:

  • ✗ Legal advice (we're not lawyers; we follow established compliance frameworks)
  • ✗ System overhaul (if your tech stack is fundamentally insecure, we identify it but don't rebuild)
  • ✗ Ongoing legal counsel (refer to your lawyer for legal questions)
  • ✗ Compliance insurance

Contract Terms

One-time project. Payment: 50% upfront, 50% at completion. Timeline: 2-8 weeks depending on scope. Ongoing support optional (limited): R2,000–R4,000/month (quarterly reviews, updates to policies as laws change).

Compliance: Common Questions

What's the difference between PAIA and POPIA?

PAIA (Promotion of Access to Information Act) lets anyone request info you hold about them. POPIA (Protection of Personal Information Act) requires you to protect personal data, get consent, and allow deletion. Both are laws. Both have penalties. You need compliance with both.

How much does non-compliance cost if we get caught?

POPIA fines: up to R10 million. PAIA violations: penalties vary but can be substantial. Plus reputational damage, loss of customer trust, and potential lawsuits. Not worth the risk.

Do we need a Data Protection Officer?

Not required for SMEs (only for large organizations processing sensitive data at scale). You need to designate someone responsible for compliance — often a manager or operations person. We’ll help you set this up.

What if someone requests access to their data?

You must comply within 20 business days (PAIA) or 30 days (POPIA) — find their data, compile it, deliver it. If you can’t, that’s a violation. We help you set up procedures to handle these requests efficiently.

Can we delete customer data after 5 years?

Depends on why you collected it and legal requirements. Some data must be kept (tax records: 5 years). Some should be deleted (marketing lists: after opt-out). We’ll help you classify your data and set retention schedules.

Next step · no retainer lock-in

Let's talk PAIA & POPIA Compliance.

Tell us the goal and the budget. We'll tell you honestly whether we can execute it, how long it takes, and what it costs.