The POPIA Compliance Checklist for SA law firms
47 action items across 10 POPIA sections, with a 10-point action plan you can implement in 90 days. Enter your email and we'll send the PDF immediately.
We respect your privacy. Your email is used only to send the PDF and one follow-up. No spam, no third-party sharing. Read our Privacy Policy.
What's inside
A practical, printable PDF written for SA attorneys. Not theory — actual action items you can tick off, with owners and deadlines.
- Section-by-section POPIA breakdown (Sections 6, 7, 11, 17, 19, 22, 23, 30, 32, 57, 72)
- 47 action items, each with a checkbox for tracking
- A 10-point action plan with owner and deadline for each item
- 7 vendor evaluation questions for assessing legal software
- Honest disclosure of what software can and cannot do for POPIA
- 12-minute read, printable, shareable with your team
Why this matters now
POPIA has been in full force since July 2021. The Information Regulator is now actively enforcing — with administrative fines up to R10 million. Law firms are squarely in the regulator's sights as custodians of some of the most sensitive personal information in the economy. If you have not done a POPIA audit in the last 12 months, you are at risk.
A glimpse of the action plan:
- 1Designate and register an Information Officer with the Information Regulator. (30 days)
- 2Conduct a personal information impact assessment. (60 days)
- 3Update your retainer agreement to disclose data processing and AI usage. (45 days)
- 4Implement technical safeguards: 2FA, role-based access, audit logging. (60 days)
- ...and 6 more in the PDF