Compliance & Cyber Intelligence for Insurance
Menu
Log in ↗
PROVANTIS / RULE LIBRARY
← BACK TO LIBRARY
← Conduct rule engine

Category 03

POPIA Privacy Governance

Protection of Personal Information Act 4 of 2013 — data protection compliance framework, Information Officer obligations, and data subject rights.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Popia
  • Insurance Broker: POPIA duties follow the entity's role as responsible party or operator and the personal information it processes. Do not state that consent is always the lawful basis, or that a public scan proves POPIA compliance.
  • Uma Binder Holder: POPIA duties follow whether the UMA is a responsible party or operator for the processing in question. The insurer relationship does not by itself settle POPIA role allocation; check the processing purpose, means and operator agreement.
  • Insurer: POPIA duties follow the insurer's responsible-party or operator role for each processing activity. Allocate duties for outsourced processing explicitly; the insurer cannot treat outsourcing as eliminating its own responsible-party obligations.

Key legislation

  • POPIA 4 of 2013
  • PAIA 2 of 2000
  • ECTA 25 of 2002

Readiness guidance

Check IO registration on the Information Regulator's portal. Examine the RoPA for completeness against known data flows. Test data subject request timelines. Verify all material operators have signed data processing agreements. Confirm breach log is maintained and notifiable breaches were reported.

Rules in this category

14 rules

POP-01

Information Officer registered with the Information Regulator

Critical
Trigger
IO not registered or registration lapsed
Section
POPIA s.55(2)
Evidence
['Information Regulator registration confirmation', 'IO appointment letter']
Remediation
Register IO on the Information Regulator's online portal immediately.

POP-02

POPIA Compliance Framework — board-approved and implemented

Critical
Trigger
No documented compliance framework or not approved at governance level
Section
POPIA s.8 (Accountability condition)
Evidence
['Board-approved POPIA Framework', 'Board resolution', 'Implementation roadmap']
Remediation
Develop and board-approve a POPIA Compliance Framework covering all eight conditions.

POP-03

Lawful basis — documented basis for all processing activities

Critical
Trigger
Personal information processed without a documented lawful basis
Section
POPIA s.11 (Processing Limitation)
Evidence
['Records of Processing Activities (RoPA) with lawful basis column', 'Processing register']
Remediation
Map all processing activities. Assign and document a lawful basis for each.

POP-04

Records of Processing Activities (RoPA) — complete and current

High
Trigger
RoPA absent, incomplete, or not updated within 12 months
Section
POPIA s.8 / s.14
Evidence
['RoPA document', 'Last review date', 'Data flow diagrams']
Remediation
Conduct data flow mapping exercise. Build and maintain RoPA. Review annually.

POP-05

Privacy Notices — accessible on all digital channels; meets POPIA s.18 requirements

High
Trigger
Privacy Notice absent from website/app or missing prescribed s.18 content
Section
POPIA s.18 (Openness condition)
Evidence
['Privacy Notice (all versions)', 'Website link screenshot', 's.18 compliance checklist']
Remediation
Update Privacy Notice to include all s.18 mandatory elements. Link from all data collection touchpoints.

POP-06

Consent management — records of consent maintained where consent is lawful basis

High
Trigger
Consent records absent or obtained in non-compliant manner
Section
POPIA s.11(1)(a) / s.69
Evidence
['Consent management system', 'Sample consent records', 'Consent withdrawal mechanism']
Remediation
Implement consent management platform. Ensure consent is specific, informed, and freely given.

POP-07

Data subject rights — procedures to handle requests within 30 days

High
Trigger
No formal procedure or requests not actioned within 30-day timeframe
Section
POPIA s.23–s.25 (Data subject participation condition)
Evidence
['Rights request procedure', 'Request log', 'Response time data']
Remediation
Implement a data subject rights request procedure. Log and track all requests.

POP-08

Operator agreements — written contracts with all data processors

High
Trigger
Processors handling personal information without a written data processing agreement
Section
POPIA s.20–s.21
Evidence
['Operator register', 'Signed DPAs', 'Operator DPA checklist']
Remediation
Map all operators. Execute DPA with each operator. Include mandatory POPIA s.21 clauses.

POP-09

Security safeguards — technical and organisational measures documented and implemented

High
Trigger
No information security policy or controls assessment not conducted
Section
POPIA s.19 (Security Safeguards condition)
Evidence
['Information Security Policy', 'Controls assessment report', 'Penetration test results']
Remediation
Conduct information security risk assessment. Implement and document controls.

POP-10

Breach notification — procedure to notify Regulator and data subjects within reasonable timeframe

Critical
Trigger
No breach notification procedure or breach not reported as required
Section
POPIA s.22
Evidence
['Breach notification procedure', 'Breach register', 'Regulator notification records']
Remediation
Develop breach notification procedure. Conduct breach drills. Report any outstanding breaches.

POP-11

Cross-border transfers — adequacy or binding agreement in place for all third-country transfers

High
Trigger
Personal information transferred to a third country without compliant safeguards
Section
POPIA s.72
Evidence
['Cross-border transfer register', 'Transfer agreements', 'Adequacy assessments']
Remediation
Map all cross-border data flows. Execute binding agreements or confirm adequacy.

POP-12

Retention and disposal — personal information retained only as long as necessary

Medium
Trigger
No retention schedule or personal information retained beyond prescribed period
Section
POPIA s.14 (Purpose Specification)
Evidence
['Retention schedule', 'Disposal records', 'Automated purge controls']
Remediation
Develop retention schedule aligned to legal obligations. Implement secure disposal process.

POP-13

Staff training — POPIA awareness training for all staff processing personal information

Medium
Trigger
No training programme or training not completed within last 12 months
Section
POPIA s.8 (Accountability condition)
Evidence
['Training material', 'Completion records per staff member', 'Assessment scores']
Remediation
Implement annual POPIA training. Track and record completion by staff member.

POP-14

PAIA Manual — published and available on organisation's website

Medium
Trigger
PAIA Manual absent, outdated, or not publicly accessible
Section
PAIA s.51
Evidence
['PAIA Manual', 'Website URL', 'Last update date']
Remediation
Compile PAIA Manual per s.51 requirements. Publish on website. Update on material changes.