POPIA compliance pack
A customer has asked you to sign an operator agreement. A tender wants your PAIA manual. Somebody wants proof you have an Information Officer. This is the pack that answers all of it, prepared for your business rather than downloaded off the internet.
Independent paperwork service. ProperSA is an independent private company, not the Information Regulator. Registering your Information Officer is free if you do it yourself. Our R1 890 pays for the eleven documents prepared around how your business actually works, and for submitting that registration for you.
Who actually needs this
Be honest with yourself about which of these you are. It changes whether you should buy anything at all.
- A customer or a tender has asked for it. This is the reason nearly everyone buys. A corporate will not release payment or keep you on the panel without a signed operator agreement and a privacy policy, and tender evaluators ask for the PAIA manual by name.
- You hold sensitive information. Medical practices, schools and creches, recruitment and payroll, debt collection, security companies, anyone running direct marketing. The consequences of getting it wrong are real and the questions get asked sooner.
- You have had a breach or a complaint. Someone has demanded their data, or asked you to delete it, or something has leaked. You need a procedure and a record, quickly.
- Nobody has asked you anything. Then you are not urgent, and the POPIA Starter Pack at R890 is probably all you need for now.
What is included
Eleven documents, each customised from your answers about how your business actually handles personal information, plus one registration.
- Privacy policy for your website and your customers, in plain English
- PAIA manual, the document every private body is expected to hold and the one tenders ask for by name
- Operator agreement for suppliers who process personal information for you, and the version to sign when a customer sends you theirs
- Record of processing activities, what you hold, why you hold it, who you share it with and where it goes. This is the backbone document an audit starts from
- Data subject request procedure and forms, for when someone demands a copy of their information or asks you to delete it
- Retention and deletion schedule, how long you keep each type of record and what happens at the end. The one almost nobody has
- Employee privacy notice, because your staff files are personal information too and most small employers never think of it
- Supplier and operator register, the list of everyone who touches your data on your behalf
- Consent and direct marketing wording for your forms, your mailers and your website
- Data breach response procedure with the Regulator notification steps and timelines
- Staff awareness material, a short briefing you can actually put in front of your people
- Your Information Officer registered with the Information Regulator, prepared and submitted for you
What POPIA enforcement actually looks like
We would rather you bought this for the right reason, so here is the honest picture rather than the scare story.
Fines under POPIA have gone almost entirely to large organisations and public bodies, and only after they ignored an enforcement notice first. The Department of Justice and the Department of Basic Education were each fined R5 million. Blouberg Municipality was fined R500 000. Infringement notices of R100 000 went to Lancet Laboratories and FT Rams Consulting. In August 2026 the Regulator issued fresh enforcement notices against public and private bodies, including the SABS after a ransomware attack.
No small South African business has been fined simply for not holding a PAIA manual. The realistic risk for a business your size is not a fine. It is losing a contract, failing a tender, or having a corporate customer hold your payment until you produce the paperwork.
That is the reason to buy this, and it is a good enough reason on its own.
How ordering works
- Order online with the button below and pay securely by card or instant EFT (PayFast), or wait for the EFT invoice.
- Complete the questionnaire in your client portal. It asks what information you collect, who you share it with, where it is stored and who handles it. No calls, no meetings, everything in writing.
- We prepare all eleven documents around your answers and submit your Information Officer registration to the Regulator.
- Everything lands in your portal downloads within 3 business days, with a short note on what to do with each document.
Not sure whether you need this one or the R890 Starter? Ask us first and you get a written answer within one business day. Tell us what your customer actually asked for and we will tell you which one covers it.
What we will need from you
- What personal information you collect, from customers, staff and suppliers
- Where it is stored, which systems, which cloud services, and whether anything sits outside South Africa
- Who you share it with, including your accountant, your payroll provider and anyone doing marketing for you
- Who handles it internally, and who the head of the business is, since that person is your Information Officer by law
- Your company or close corporation registration number, or identity number if you trade in your own name
- Anything a customer has already sent you to sign, so we work with their wording rather than against it
Frequently asked questions
What does a client usually ask for when they say POPIA compliance?
Almost always a signed operator agreement, a privacy policy, and proof that you have an Information Officer registered with the Information Regulator. Larger customers push compliance down their supply chain, and the supplier who cannot produce those three things is the one who gets held up on payment or dropped from the panel.
Has anyone actually been fined under POPIA?
Yes, but almost entirely large organisations and public bodies, and only after they ignored an enforcement notice first. The Department of Justice and the Department of Basic Education were fined R5 million each, Blouberg Municipality R500 000, and R100 000 infringement notices went to Lancet Laboratories and FT Rams Consulting. No small South African business has been fined simply for not holding a PAIA manual. The realistic risk for a small business is losing a contract, not a fine.
Do I need to register an Information Officer?
Yes. The head of the business is the Information Officer by law from day one, and registration with the Regulator is expected. The Regulator charges nothing to register. Preparing and submitting that registration is included here, and we also sell it on its own as Information Officer registration at R390.
What is the difference between this and the POPIA Starter Pack?
The Starter Pack at R890 gives you the five core documents. This pack adds the record of processing activities, the data subject request procedure and forms, a retention and deletion schedule, an employee privacy notice, a supplier and operator register and staff awareness material, and it includes registering your Information Officer. It is the version that answers a customer audit rather than just putting a policy on your website.
Is a PAIA manual still required?
Yes. Every private body is expected to hold a PAIA manual and make it available on request. It is one of the first documents a tender evaluator or a corporate procurement team asks to see, which is why it is included.
Do you give legal advice?
No. ProperSA is not a law firm. These are documents and guidance prepared from your answers about how your business actually handles personal information. If your situation needs legal advice, for example an active Regulator investigation or a serious breach, you need an attorney and we will tell you so.
This page summarises obligations under the Protection of Personal Information Act 4 of 2013 and the Promotion of Access to Information Act 2 of 2000. Enforcement figures quoted are drawn from the Information Regulator’s published media statements and enforcement notices and were correct when written. This is general information and a document preparation service, not legal advice, and it does not cover every obligation that may apply to your business.