🔒

POPIA Compliance Workbook

Stop worrying about POPIA fines. This workbook makes compliance achievable for any SMB — no legal degree required.

R249 once-off

Instant download • Editable DOCX • PDF included • 40+ pages

What's Included

  • Information Officer appointment letter
  • PAIA manual template
  • POPIA compliance checklist (8 conditions)
  • Data subject access request form
  • Data breach response procedure
  • Consent and processing register
  • Data retention and destruction policy
  • Third-party processing agreement template
  • Employee awareness training guide
  • Regulator notification form templates

Formats

  • Microsoft Word (.docx) — fully editable
  • PDF — print-ready

Overview

The Protection of Personal Information Act (POPIA) applies to every South African business that processes personal data — and that's pretty much everyone. But most SMBs don't have a legal department or a dedicated compliance officer. This workbook bridges that gap.

Who it's for: Small business owners, office managers, IT consultants helping clients achieve compliance, and anyone who needs a practical (not theoretical) approach to POPIA.

What You'll Get

Done-for-You Templates

PAIA manual, Information Officer appointment, data subject request forms, consent register — all editable and ready to use.

8-Condition Compliance Checklist

Walk through each POPIA condition with practical action items. Tick off what you've done, identify gaps, and build an action plan.

Data Breach Response Plan

Step-by-step procedure for detecting, containing, assessing, and reporting a data breach to the Information Regulator within the required 72-hour window.

IT-Specific Guidance

Technical controls mapped to POPIA requirements: encryption standards, access controls, backup encryption, email security, and breach detection.

Employee Training Guide

Ready-to-use presentation and talking points for training staff on POPIA basics — what constitutes personal information, how to handle data subject requests, and what to do if they suspect a breach.

Third-Party Processing

Agreement template for vendors and service providers who process personal data on your behalf, plus a due diligence checklist for evaluating their POPIA compliance.

Why This Workbook?

Most POPIA resources are written by lawyers, for lawyers. This workbook is written for the person who actually has to implement compliance — the business owner, IT manager, or office administrator. Plain English, actionable steps, and templates you can fill in today.

I've helped numerous SMB clients in South Africa navigate POPIA compliance as part of their broader IT setup. This workbook consolidates what actually works in practice, not what looks good on paper.