POPIA compliance hub
POPIA compliance: check it, score it, fix it
The Protection of Personal Information Act applies to virtually every South African business that holds a customer's name, email, or ID number. Start with what the Information Regulator sees first — your website — then score the rest of your business.
Then score the rest of your business
POPIA Self-Assessment
46 questions across all 8 POPIA Conditions, modelled on the Information Regulator's framework. Emailed PDF with what to fix first.
PAIA Self-Assessment
POPIA's sister act: section 51 manual, annual report, and request handling — scored the same way.
The fix path, in order
- 1
Register your Information Officer — usually the owner or CEO, formally authorised in writing and registered with the Regulator. Have a specialist do it or follow our guide.
- 2
Publish a PAIA manual and a POPIA-grade privacy notice on your website — the two things anyone checking you looks for first.
- 3
Get consent in order — cookie/tracking consent on the website, opt-ins on your forms, operator agreements with providers that process data for you.
- 4
Keep it that way — ClearComply tracks 12+ compliance requirements across POPIA, PAIA, CIPC, SARS, UIF, COIDA and B-BBEE, alerts you before every deadline, and tells you the moment your status changes. R99/month, cancel anytime.
Rather have it done for you?
An accredited POPIA/PAIA specialist handles it at a fixed price — Information Officer and Deputy IO registration, or your PAIA manual and privacy policies. They contact you within 24 hours of booking.
Need something else — B-BBEE, SARS, UIF? Request assistance and we'll match you with a specialist.
Read up on POPIA and PAIA
All compliance guidesPOPIA for small businesses: the complete guide
The 8 Conditions, the seven practical steps, and the penalties — in plain English.
Read guide →Information Officer registration, step by step
The most-missed POPIA obligation — and the first thing the Regulator asks about.
Read guide →What SA business websites actually get wrong
We scanned thousands of South African business sites against the visible POPIA requirements. Here is what is missing, and how often.
Read guide →POPIA fines: the real South African cases
Who the Information Regulator has actually fined, for what, and how much.
Read guide →The PAIA annual report explained
Section 32 reporting — due even if you received zero requests.
Read guide →What non-compliance actually costs
Both R5 million POPIA fines to date, and every other penalty that stacks.
Read guide →Quick answers
How do I check if my business is POPIA compliant?
Start with the two free checks on this page: the website check scans your site for the visible POPIA requirements (privacy notice, PAIA manual, Information Officer details, consent), and the self-assessment scores your business across all 8 POPIA Conditions using the Information Regulator’s own framework.
Can someone just do my POPIA compliance for me?
Yes. ClearComply connects you with an accredited POPIA/PAIA specialist at a fixed price — Information Officer and Deputy Information Officer registration, or a PAIA manual with a POPIA-grade privacy notice written for what your business actually does. You pay once, they contact you within 24 hours, and they deliver the documents to you directly.
Who is my Information Officer?
By default it is the most senior person in the business — usually the owner, CEO or managing member. The role has to be formally authorised in writing and registered with the Information Regulator, and larger or multi-site businesses are expected to designate Deputy Information Officers alongside it.
Does my small business need a PAIA manual?
Yes — every private body must compile a PAIA section 51 manual and make it available, typically on your website. It describes what records you hold and how someone can request access to them.
What happens if my business ignores POPIA?
The Information Regulator can fine up to R10 million and has already issued R5 million fines. It is running proactive compliance assessments, and an ignored enforcement notice is a criminal offence. Most SME gaps — Information Officer registration, a PAIA manual, a POPIA-grade privacy notice — are cheap and quick to close.
The tools on this page are self-checks, not legal certifications of POPIA compliance. For formal advice, consult a qualified attorney or POPIA specialist. ClearComply does not file or submit documents on your behalf.