Skip to content
Gatsheni Advisory logo
  • Home
  • Areas of Expertise
  • Services
    • AI Positioning and Organizational Strategy
    • Compliance Courses
    • Compliance Risk Management Plans
    • Developing a Compliance Universe
    • Digital Assets Strategy
    • ESG Compliance
    • Free Provisional POPIA Maturity Assessments
    • Legal
    • POPI Compliance & Personal Information Impact Assessment
    • POPI Compliance Training
    • School of Compliance Management
    • Transaction Advisory
  • Thought Leadership
  • Some of our Success & Clients
Get in touch

Step 1 of 3

33%
Name(Required)
Does your organization have a Compliance Risk Management Plan (CRMP) which deals with POPIA, specifically?(Required)
Drop files here or
Max. file size: 32 MB.
    Based on question 1; above, has your organization done any compliance monitoring in respect of POPIA, specifically?(Required)
    Drop files here or
    Max. file size: 32 MB.
      Has your organization conducted an independent personal information impact assessment?(Required)
      (see Regulation 4(1)(a) of POPIA)). Even if you believe the initial effort to have been lacking in some respects, it is still important that you respond.)
      Drop files here or
      Max. file size: 32 MB.
        Does your organization have a written compliance framework in terms of Regulation 4(1)(a) of POPIA?(Required)
        Drop files here or
        Max. file size: 32 MB.
          Does your organization have a written compliance policy?(Required)
          Drop files here or
          Max. file size: 32 MB.
            Does your organization have a Retention Schedule or Policy?(Required)
            Alternatively, to the best of your knowledge, is there a rule within your organization which governs how long both physical and electronic documents must be kept for?
            Drop files here or
            Max. file size: 32 MB.
              Does your organization have a policy or Standard Operating Procedures (SOP) which deal with “Quality of Information”? (see section 16 of POPIA).(Required)
              Drop files here or
              Max. file size: 32 MB.
                Has your organization’s IT function conducted an assessment to internal risks to personal information and an assessment of external risks to personal information?(Required)
                Drop files here or
                Max. file size: 32 MB.
                  Does your organization have a data breach response plan?(Required)
                  Drop files here or
                  Max. file size: 32 MB.
                    Does your organization have a PAIA Manual in terms of the Promotion of Access to Information Act, 2000?(Required)
                    Drop files here or
                    Max. file size: 32 MB.
                      Were your organization’s Information Officer and Deputy Information Officer (if applicable, registered with the Information Regulator)?(Required)
                      Drop files here or
                      Max. file size: 32 MB.
                        In respect of question 3., above, does your organization’s PIIA have risk assessment section which was considered and completed within the context of the 8 conditions for the lawful processing of personal information?(Required)
                        Personal Information Risk Assessment in respect of the 8 conditions for the lawful processing of personal information.
                        Drop files here or
                        Max. file size: 32 MB.
                          When was the last occasion where your organization conducted training and awareness on POPIA?(Required)
                          Drop files here or
                          Max. file size: 32 MB.

                            Free Provisional POPIA Maturity Assessment – Disclaimer & Consent

                            By submitting this form and selecting the confirmation checkbox, you acknowledge and agree to the following:


                            1. Nature of the Assessment

                            The Free Provisional POPIA Maturity Assessment is provided for informational and preliminary evaluation purposes only. The outcome is a high-level assessment of your organisation’s POPIA maturity level based solely on the information and documentation voluntarily provided by you.


                            2. Accuracy of Information

                            You confirm that the information and documents submitted through this platform are accurate, lawful, and provided with appropriate authority. The quality, reliability, and usefulness of the assessment are entirely dependent on the completeness and accuracy of the information you provide.


                            3. No Professional or Legal Opinion

                            The provisional assessment does not constitute legal advice, compliance certification, audit opinion, or regulatory approval. It is not a substitute for a comprehensive compliance review, legal consultation, or formal audit. Where a more detailed analysis is required (e.g., for EXCO, Audit and Risk Committees, or Board reporting), such services will be provided separately on a quoted and agreed engagement basis.


                            4. Processing of Personal Information

                            Any personal or organisational information submitted through this form will be processed in accordance with the Protection of Personal Information Act, 2013 (POPIA) and applicable data protection principles. Information will only be used for the purpose of conducting the provisional assessment and related communication regarding the assessment.


                            5. Safeguarding of Information

                            Appropriate technical and organisational security measures, consistent with section 19 of POPIA, will be implemented to protect information submitted through this platform against loss, damage, unauthorised access, or unlawful processing.


                            6. Document Submissions

                            You may upload documents to support your responses. Where documents contain sensitive or confidential information, you may submit redacted extracts or relevant sections only to limit processing.


                            7. Retention and Disposal of Information

                            Submitted responses and documents will be retained only for the period reasonably necessary to complete the assessment and communicate the results. Once the assessment process is concluded, information will be securely disposed of using responsible and legally compliant electronic means, unless further engagement is requested or legally required.


                            8. Limitation of Liability

                            To the fullest extent permitted by law, the provider of this assessment accepts no liability for decisions, actions, or omissions taken by any organisation based solely on the provisional assessment or summary provided.

                            Consent(Required)

                            Quick links

                            • Home
                            • Areas of Expertise
                            • Compliance Courses
                            • Some of our Successes & Clients
                            • Thought Leadership
                            • School of Compliance Management

                            Contact us

                            • Cell phone: 074 854 3354

                            DBN Branch

                            • Musgrave Business Centre (Second Floor), 102 Stephen Dlamini Road Durban

                            JHB Branch

                            • Eagle Canyon Office Park

                            Policies

                            • PAIA Manual
                            • POPIA Policy
                            • POPIA Maturity Assessments Disclaimer
                            © 2026 All rights Reserved. Design by Woww.