Skip to content
  • Services
    • Compliance Services
    • Managed Services
    • Training & Learning
  • Free Maturity Assessment
  • Blog
  • Contact Us
  • Services
    • Compliance Services
    • Managed Services
    • Training & Learning
  • Free Maturity Assessment
  • Blog
  • Contact Us
POPIA Gap Analysis Services
POPIA Implementation Services
POPIA Audit Services
POPIA Gap Analysis Services

POPIA gap analysis

Compliance Services

Take your first step towards compliance with a comprehensive POPIA assessment that easily outlines your next steps.

Get a full picture of your POPIA compliance

Your POPIA gap analysis will start with a series of interviews with key departments in your organisation that handle personal information, such as HR, IT, Sales and Marketing.

These interviews allow our team to assess your current processes and policies against POPIA requirements.

POPIA document review included

Unlike many other providers, we will include a full review of up to 20 documents as part of your POPIA gap analysis. This could include any existing POPIA documentation including policies, procedures, logs and registers.

Get a comprehensive POPIA report

Once your POPIA gap analysis is complete you will receive a detailed, actionable report that contains:

  • A snapshot of your current state of compliance against POPIA compliance
  • Comments and suggestions on how to improve existing POPIA documentation
  • An action plan identifying what needs to be done to address areas of non-compliance

Benefits of a POPIA gap analysis

Here are just some of the ways that your business will benefit from completing a POPIA gap analysis:

  • Get an accurate picture of where your organisation currently is in terms of POPIA compliance
  • Grow your understanding of POPIA with the help of our friendly and experienced personal information protection consultants
  • Highlight issues with your current processes and learn how to address them Identify a clear path forward for establishing a compliance framework

Why choose Privacy Partners?

With our vast experience in personal information privacy and protection, our clients trust us to provide expert, actionable advice to help solve even the most complex personal information protection challenges.

Our consultancy team is made up of privacy practitioners and personal information privacy experts. We support businesses of all sizes, implement and maintain their compliance standards, providing guidance on all aspects of personal information protection and how to address the risks of handling personal information.

Get a quote today

Contact us

    We are committed to protecting and respecting your privacy, and we’ll only use your personal information to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick the box.

    For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our privacy notice.

    Frequently asked questions

    What is a POPIA gap analysis?

    A POPIA assessment is the first step companies need to take on their journey to compliance. The purpose of the gap analysis is to assess an organisations’ level of compliance to POPIA requirements, identify areas of non-compliance and provide an action plan to address these. Companies that conduct a POPIA readiness assessment will have a clear plan of what they need to do and how to do it, thus making the journey to compliance easy to understand and straightforward.

    Our POPIA assessment involves:

    • Interviewing key staff who handle personal information e.g. IT, HR, Sales, Marketing, Customer Services, Senior Management, existing privacy staff
    • A review of your POPIA related documentation e.g. policies, procedures, logs, registers etc.

     

    Preparation of a comprehensive report that outlines:

    • Our findings of the current state of compliance against POPIA requirements
    • A document review with comments and suggestions on improvements
    • An action plan identifying what needs to be done to address areas of non-compliance
    What is a POPIA gap analysis?

    A POPIA assessment is the first step companies need to take on their journey to compliance. The purpose of the gap analysis is to assess an organisations’ level of compliance to POPIA requirements, identify areas of non-compliance and provide an action plan to address these. Companies that conduct a POPIA readiness assessment will have a clear plan of what they need to do and how to do it, thus making the journey to compliance easy to understand and straightforward.

    Our POPIA assessment involves:

    • Interviewing key staff who handle personal information e.g. IT, HR, Sales, Marketing, Customer Services, Senior Management, existing privacy staff
    • A review of your POPIA related documentation e.g. policies, procedures, logs, registers etc.

     

    Preparation of a comprehensive report that outlines:

    • Our findings of the current state of compliance against POPIA requirements
    • A document review with comments and suggestions on improvements
    • An action plan identifying what needs to be done to address areas of non-compliance
    Who will need to be involved in a gap analysis?

    Typically we need to speak to people that head up departments such as IT, HR, Marketing, Finance, Sales, compliance, legal and also anyone who currently has responsibility for privacy. It can also be good to speak to frontline staff that know the day-to-day job really well as they can often offer insights that managers can’t.

    Who will need to be involved in a gap analysis?

    Typically we need to speak to people that head up departments such as IT, HR, Marketing, Finance, Sales, compliance, legal and also anyone who currently has responsibility for privacy. It can also be good to speak to frontline staff that know the day-to-day job really well as they can often offer insights that managers can’t.

    How quickly will I get my POPIA gap analysis report?

    Once we have finished interviewing all your team, we will write up the report, which usually takes 1 day and then the report goes through our rigorous QA process to ensure it meets our quality standards. Typically this means you will have your report within 5 working days of the last interview.

    How quickly will I get my POPIA gap analysis report?

    Once we have finished interviewing all your team, we will write up the report, which usually takes 1 day and then the report goes through our rigorous QA process to ensure it meets our quality standards. Typically this means you will have your report within 5 working days of the last interview.

    What’s the difference between a POPIA gap analysis and a POPIA audit?

    The gap analysis is designed for organisations that may have done some bits and pieces around POPIA but don’t have an established compliance framework/programme in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

    What’s the difference between a POPIA gap analysis and a POPIA audit?

    The gap analysis is designed for organisations that may have done some bits and pieces around POPIA but don’t have an established compliance framework/programme in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

    What areas does the POPIA gap analysis cover?

    As part of your POPIA gap analysis, our team will cover the following main areas of compliance:

    • Governance
    • Risk management
    • POPIA resourcing
    • Roles & responsibilities
    • Scope of compliance
    • Personal information processes
    • Data subject rights
    What areas does the POPIA gap analysis cover?

    As part of your POPIA gap analysis, our team will cover the following main areas of compliance:

    • Governance
    • Risk management
    • POPIA resourcing
    • Roles & responsibilities
    • Scope of compliance
    • Personal information processes
    • Data subject rights
    How much time do we need to set aside for the POPIA assessment?

    Typically interviews with individuals take in the region of 1-2 hours and we will work around your schedule to find a time that is convenient. We’re happy to book different slots of different days to make it work for you. Occasionally after meetings there may be one or two follow up questions, but we can usually address these via email.

    How much time do we need to set aside for the POPIA assessment?

    Typically interviews with individuals take in the region of 1-2 hours and we will work around your schedule to find a time that is convenient. We’re happy to book different slots of different days to make it work for you. Occasionally after meetings there may be one or two follow up questions, but we can usually address these via email.

    What if I have questions or I don’t understand something?

    If there are questions about the report, we can address these as part of the catch-up meeting which we normally have a few days after you have the report. If, however your question is urgent, please feel free to contact the consultant who conducted the gap analysis and they will be happy to answer any queries.

    What if I have questions or I don’t understand something?

    If there are questions about the report, we can address these as part of the catch-up meeting which we normally have a few days after you have the report. If, however your question is urgent, please feel free to contact the consultant who conducted the gap analysis and they will be happy to answer any queries.

    POPIA Implementation Services

    Expert POPIA implementation services

    Compliance Services

    Our experienced consultants will help you implement POPIA & maintain compliance.

    Achieve and maintain POPIA compliance

    When you choose our POPIA implementation service, we’ll help your business achieve and maintain compliance against POPIA. Here are just some of the areas that we can assist you with:

    • Full, tailored privacy notices and POPIA-related policies and procedures
    • Data mapping
    • Risk framework / risk assessments with training
    • Privacy Impact Assessments (PIA) where required
    • Legitimate Interest Assessments (LIA) where required
    • POPIA training for employees
    • Record of Processing (section 51 of PAIA)
    • Data breach procedures
    • Data subject rights
    • Security recommendations based on best practice

    Benefits of implementing POPIA

    Achieving and maintaining POPIA compliance can bring several benefits to your business, including:

    • Increased marketing return on investment (ROI)
    • Reduced business risk
    • A better understanding of the personal information being collected
    • Improved personal information management
    • Better alignment with evolving technology
    • Enhanced cyber security

    Why choose Privacy Partners?

    Our consultancy team is made up of privacy practitioners and personal information privacy experts. We support businesses of all sizes, implement and maintain their compliance standards, providing guidance on all aspects of personal information protection.

    We understand that every organisation has different priorities and requirements, which can make an implementation process daunting. With Privacy Partners, there’s no need to worry. Our consultants work with you to ensure that your POPIA implementation plan is comprehensive yet actionable, with minimal disruption to your business.

    Get a quote today

    Contact us

      We are committed to protecting and respecting your privacy, and we’ll only use your personal information to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick the box.

      For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our privacy notice.

      Frequently asked questions

      What is a POPIA implementation project?

      Conducting a POPIA implementation project is a critical step in the journey to satisfy the requirements of POPIA. The purpose of an implementation project is to develop the necessary policies, procedures, processes, and documentation to achieve and maintain POPIA compliance.

      In addition, a POPIA implementation project will also train staff to ensure they understand how the regulation affects their role and how they can maintain compliance in the future.

      What is a POPIA implementation project?

      Conducting a POPIA implementation project is a critical step in the journey to satisfy the requirements of POPIA. The purpose of an implementation project is to develop the necessary policies, procedures, processes, and documentation to achieve and maintain POPIA compliance.

      In addition, a POPIA implementation project will also train staff to ensure they understand how the regulation affects their role and how they can maintain compliance in the future.

      Who will need to be involved?

      We will need to involve many different people in the business from senior management down to the people on the front line. We will work with you to identify people with key responsibilities in each department so that we can involve them where required.

      Who will need to be involved?

      We will need to involve many different people in the business from senior management down to the people on the front line. We will work with you to identify people with key responsibilities in each department so that we can involve them where required.

      What’s the difference between a POPIA gap analysis and a POPIA audit?

      The gap analysis is designed for organisations that may have done some bits and pieces around POPIA but don’t have an established compliance framework/programme in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

      What’s the difference between a POPIA gap analysis and a POPIA audit?

      The gap analysis is designed for organisations that may have done some bits and pieces around POPIA but don’t have an established compliance framework/programme in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

      What happens once the POPIA implementation is complete?

      Once complete, we will conduct a project wrap up meeting to run through everything we have completed. After this, we will discuss next steps which may include your own team taking over the day-to-day running of the privacy information management system, or you might decide to onboard us as your managed privacy service provider to help keep things up to date and compliant. We can also provide annual auditing for you if you decide to run your privacy management system yourself but want to make sure everything is still running correctly.

      What happens once the POPIA implementation is complete?

      Once complete, we will conduct a project wrap up meeting to run through everything we have completed. After this, we will discuss next steps which may include your own team taking over the day-to-day running of the privacy information management system, or you might decide to onboard us as your managed privacy service provider to help keep things up to date and compliant. We can also provide annual auditing for you if you decide to run your privacy management system yourself but want to make sure everything is still running correctly.

      How long does a POPIA implementation project take?

      This largely depends on the amount of work required and the resources you have available. A typical project usually takes between 9-15 days which are spread over a 2-3 month period.

      How long does a POPIA implementation project take?

      This largely depends on the amount of work required and the resources you have available. A typical project usually takes between 9-15 days which are spread over a 2-3 month period.

      Can we do parts of the POPIA implementation ourselves?

      Yes, we can work with you to identify which areas of the implementation you would like us to support you with and which areas you are happy to do yourselves. Alternatively, if resource or in-house knowledge is limited, we can support you with all of it.

      Can we do parts of the POPIA implementation ourselves?

      Yes, we can work with you to identify which areas of the implementation you would like us to support you with and which areas you are happy to do yourselves. Alternatively, if resource or in-house knowledge is limited, we can support you with all of it.

      POPIA Audit Services

      POPIA audit service

      Compliance Services

      Review and monitor your POPIA compliance with a comprehensive POPIA audit from seasoned consultants.

      Get a clear view of your POPIA compliance

      A POPIA audit helps you understand your level of compliance, identify risks and demonstrate how personal information protection is a priority for the business.
      The assessment of your policies and processes will determine if personal information is being handled appropriately across the business to ensure you are meeting your regulatory obligations.

      Our consultants work with you to ensure your individual requirements are met as well as to guide you through the process and provide advice for any follow-up activities that may be required.

      What are the benefits of a POPIA audit?

      • Get an independent, evidence-based assessment of your current level of compliance from experienced POPIA consultants
      • Provide customers, investors, regulatory authorities and others with reassurance that your organisation is managing its compliance and can demonstrate this
      • Identify areas that need improvement so that you can address these quickly
      • Our experienced consultants can identify opportunities for improvement and advice on further security and compliance measures
      • Have a follow up call with your consultant after the audit to answer any questions you may have

      What is included in our POPIA audit service ?

      Step 1: Introductory call

      An opportunity for both parties to meet, for the consultant to understand more about your business and address the following:

      • Understand the scope of compliance i.e. what processing is the organisation carrying out and what is its role as a responsible party/operator
      • Roles and responsibilities for the audit
      • Current business objectives in relation to the audit e.g. is it being done for a customer, regulator etc.
      • Understanding any known areas of concern
      • Understand relationships with third-parties, subsidiaries, and parent or group members
      • Discuss the type of evidence we will be looking for when we conduct the audit
      • Agree a schedule for the audit interviews

      Step 2: POPIA audit

      The consultant will arrange a series of interviews with key staff who are responsible for handling personal information to audit the following areas:

      • Governance
      • Leadership
      • Roles & responsibilities
      • Training & awareness
      • Privacy by design
      • Privacy management
      • Risk management
      • Upholding data subjects’ rights
      • International data transfers
      • Agreements with operators
      • Supplier contracts

      Step 3: POPIA document review

      A review of a sample of POPIA related documents will be conducted, examples of document to be reviewed include:

      • Personal information protection policy
      • Privacy notices (internal & external)
      • Personal information breach policy, process & logs
      • Agreements with operators
      • Personal information processing agreements with customers / suppliers
      • Record of Processing (section 51 of PAIA)
      • Information security policy
      • Job descriptions & template employment contract

      Why choose Privacy Partners?

      Our consultancy team is made up of privacy practitioners and personal information privacy experts. We support businesses of all sizes, implement and maintain their compliance standards, providing guidance on all aspects of personal information protection.

      We understand that every organisation has different priorities and requirements, which can make an audit process daunting. Our consultants work with you to ensure that your POPIA audit is not only comprehensive with clear report findings, but also causes minimal disruption to your business..

      Get a quote today

      Contact us

        We are committed to protecting and respecting your privacy, and we’ll only use your personal information to provide the products and services you requested from us. From time to time, we would like to contact you about our products and services, as well as other content that may be of interest to you. If you consent to us contacting you for this purpose, please tick the box.

        For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our privacy notice.

        Frequently asked questions

        How long does it take to do a POPIA audit?

        Typically an audit is a 3-day project, but it does depend on the size and complexity of your organisation so please contact us to get an accurate quote.

        How long does it take to do a POPIA audit?

        Typically an audit is a 3-day project, but it does depend on the size and complexity of your organisation so please contact us to get an accurate quote.

        How quickly will I get my POPIA audit report?

        Once we have finished interviewing all of your team, we will write up the report, which usually takes one working day. The report then goes through our rigorous Quality Assurance process to ensure it meets our usual standards. Typically this means you will have your report within 5 working days of the last interview.

        How quickly will I get my POPIA audit report?

        Once we have finished interviewing all of your team, we will write up the report, which usually takes one working day. The report then goes through our rigorous Quality Assurance process to ensure it meets our usual standards. Typically this means you will have your report within 5 working days of the last interview.

        What’s the difference between a POPIA gap analysis and a POPIA audit?

        The gap analysis is designed for organisations that may have done some bits and pieces around the POPIA but don’t have an established compliance framework in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

        What’s the difference between a POPIA gap analysis and a POPIA audit?

        The gap analysis is designed for organisations that may have done some bits and pieces around the POPIA but don’t have an established compliance framework in place. It’s really for those organisations who are starting on their journey to compliance. An audit is for those organisations who have put in place a framework/personal information management system and who want to carry out regular checks to make sure it is still operating as envisaged.

        What does our POPIA audit involve?
        • Interviewing key staff who are involved in the day-to-day handling of personal information e.g. IT, HR, Sales, Marketing, Customer Services, Senior Management and any staff with specific personal information protection/privacy responsibilities
        • An evidence-based review where we will ask for and review evidence that establishes whether the privacy policies and procedures in place are working correctly
        • A document review of any POPIA related documentation to make sure they meet the requirements of POPIA
        • Preparation of a comprehensive audit report that outlines:
          • An executive summary identifying key results and findings
          • A summary table of non-conformities and opportunities for improvement
          • A document review with comments and suggestions on improvements
        What does our POPIA audit involve?
        • Interviewing key staff who are involved in the day-to-day handling of personal information e.g. IT, HR, Sales, Marketing, Customer Services, Senior Management and any staff with specific personal information protection/privacy responsibilities
        • An evidence-based review where we will ask for and review evidence that establishes whether the privacy policies and procedures in place are working correctly
        • A document review of any POPIA related documentation to make sure they meet the requirements of POPIA
        • Preparation of a comprehensive audit report that outlines:
          • An executive summary identifying key results and findings
          • A summary table of non-conformities and opportunities for improvement
          • A document review with comments and suggestions on improvements
        How much would an audit interfere with our day-to-day operations?

        We appreciate that audits can be very disruptive and so we try and be as flexible as possible in terms of booking in interviews to avoid impacting heavily on your day-to-day operations. We can spread interviews over a period of days, and we will always try and find slots that work for all. We will also advise you ahead of the audit what type of information we are likely to ask for so that you can make sure that information is at hand.

        How much would an audit interfere with our day-to-day operations?

        We appreciate that audits can be very disruptive and so we try and be as flexible as possible in terms of booking in interviews to avoid impacting heavily on your day-to-day operations. We can spread interviews over a period of days, and we will always try and find slots that work for all. We will also advise you ahead of the audit what type of information we are likely to ask for so that you can make sure that information is at hand.

        How will I receive my audit?

        Your report will be sent to you via a secure link in email. From here you can download the PDF report.

        How will I receive my audit?

        Your report will be sent to you via a secure link in email. From here you can download the PDF report.

        • PAIA manual
        • Privacy notice
        • PAIA manual
        • Privacy notice
        • Your privacy rights
        • Contact Us
        • Your privacy rights
        • Contact Us