Data Protection (POPIA)
POPIA Act 4 of 2013 — personal information register, consents, data subject rights, breach management and cross-border transfers.
30%
POPIA Compliance Score
IO registered: No · PIR: 0 categories · DSARs overdue: 0 · Unnotified breaches: 0
PIR categories
0
0 gaps
PIR reviews overdue
0
Active consents
0
0 expired
Open DSARs
0
0 overdue
Open breaches
0
0 unnotified
Cross-border transfers
0
POPIA 8 conditions for lawful processing — coverage in SHIELDos
- Accountability — Privacy Officer register + ComplianceAction audit trail.
- Lawful basis & purpose limitation — PIR tags each category with its lawful basis & legal reference.
- Data minimisation & quality — PIR owner + review cycle; overdue reviews escalate.
- Openness — Privacy notice linked from the Officer tab; consent records are auditable.
- Security safeguards — existing RLS + role-based access; breaches logged and notified.
- Data subject participation — DSAR workflow with 30-day statutory deadline & escalation.
- Retention — retention period captured per PIR category.
- Cross-border transfer — transfer register with mechanism & justification (s57).