1️⃣ Governance & Registration
Information Officer appointed (usually business owner or director)
Information Officer registered with the Information Regulator of South Africa
POPIA Compliance Policy and Privacy Notice published (website/app)
Internal data protection policy in place (for employees/contractors)
2️⃣ Data Inventory
List of all types of personal information collected (e.g. names, IDs, banking details, contact info)
Record of where data is stored (servers, cloud, files)
List of all third parties who receive data (e.g. Yoco payment gateway, hosting providers)
3️⃣ Legal Basis & Consent
Users are informed why their information is collected
Consent is obtained where required (e.g. account registration, marketing emails)
Privacy notice available before or at the time of data collection
4️⃣ Security Measures
SSL certificate active on the website
Access to personal information limited to authorised staff only
Regular backups performed and stored securely
Anti-virus and firewall protections in place
Yoco payment processing complies with PCI-DSS standards
5️⃣ Data Subject Rights
Procedure in place for users to request access to their data
Procedure in place to correct or delete user information upon request
System for handling objections or withdrawal of consent
Record of any access or deletion requests handled
6️⃣ Retention & Disposal
Retention schedule defined (how long data is kept)
Secure deletion or anonymisation of outdated records
7️⃣ Training & Awareness
All staff/contractors briefed on POPIA and confidentiality
Regular reminders or short training sessions on data handling
8️⃣ Incident Management
Procedure in place for data breach detection and response
Record of any security incidents or breaches and actions taken
Information Regulator notified of any serious data breaches
9️⃣ Documentation
POPIA Compliance Policy (latest version)
Privacy Notice (public)
Proof of Information Officer registration
Record of data subject requests
Third-party data processing agreements (Yoco, hosting, etc.)