POPIA (the Protection of Personal Information Act 4 of 2013) governs how organisations collect, use, store and share personal information in South Africa. It is enforced by the Information Regulator, which can impose administrative fines of up to R10 million, and already has. Encircle's assessment is built on the current law, including the amended Regulations that took effect on 17 April 2025 (stronger direct-marketing consent, multi-channel data-subject requests, and breach notification via the Regulator's eServices portal).
This framework contributes to the following governance domains in your Encircle score:
Encircle maps POPIA's eight conditions for lawful processing to your governance wheel and asks for the documents a compliant organisation must hold, from your Information Officer registration and ROPA to your breach procedure and direct-marketing consent records. Every gap becomes an assigned remediation task with guidance grounded in the current Act and the 2025 Regulations.
Encircle tells you when you are POPIA ready, your evidence demonstrates lawful processing across all eight conditions, with the registers, policies and procedures the Information Regulator expects. This is compliance readiness, not legal advice; you remain accountable as the responsible party.
Live demo
The same organisation seen through the POPIA lens. Red is where the exposure is. Switch lens to see how the picture changes under another framework.
Select a framework
POPIA: direct-marketing consent records predate the amended Regulation 6 (17 April 2025); opt-out no longer counts as consent, and the privacy risk assessment is undocumented. Technology drops 17 points, with Compliance, Risk and Ethics behind it.