Prove you're POPIA-ready. Then win the deal.

Your client's procurement team wants to know how you handle personal information. Kompli scores your business against POPIA's eight conditions, tells you exactly what to fix, and gives you something credible to send back.

6 minutes · no signup · no card

POPIA Readiness Report
Northbound Digital (Pty) Ltd · 12 Aug 2026
86
READY
Assessed against all eight conditions
Security safeguards
Processing limitation
Openness
Operator agreements
Data subject participation
kompli.co.za/r/nbd-8f21
§ 01 / why this lands on your desk

It usually starts with an email from someone in procurement.

Not from the Information Regulator. From your client's vendor onboarding team, two weeks before contract signature, asking how you handle personal information and whether you can prove it.

Most South African tech companies answer this the same way: a privacy policy downloaded three years ago, a scramble through Slack, and a delay that costs them momentum in a deal they'd already won.

Compliance stopped being paperwork the moment it started gating revenue.

VENDOR DATA PROTECTION QUESTIONNAIRE · P.2/4
Do you have a designated Information Officer registered with the Information Regulator?
Provide your PAIA manual and current privacy policy.
List all third parties processing personal information on your behalf, and confirm operator agreements are in place.
Is any personal information processed outside South Africa? State the lawful basis.
Describe your breach notification procedure and response timelines.
Every question here maps to something Kompli assesses.
§ 02 / what gets assessed

POPIA has eight conditions. You're measured against every one.

Most compliance tools stop at a privacy policy, which covers one condition and part of another. Kompli scores each condition separately, so you can see which part of your business is actually exposed rather than getting one number with no explanation.

ACC Accountability Someone is formally responsible, registered, and can produce evidence on request.
PL Processing limitation You collect only what you need, with a lawful basis, and can show where it came from.
PS Purpose specification Every field has a stated reason, and a retention period that actually ends.
FP Further processing Data collected for one purpose isn't quietly reused for another.
IQ Information quality What you hold is accurate and current enough for what you're using it for.
OP Openness People are told what you're collecting at the point you collect it — and a PAIA manual exists.
SS Security safeguards Access control, MFA, encryption, offboarding, vendor agreements, breach response.
DSP Data subject participation Someone can ask what you hold, and you can answer and correct it within the deadline.

Plus s69 direct marketing and s72 cross-border transfers, where they apply to you.

§ 03 / how it works

Assess, then fix, then prove.

In that order, because each step produces the input for the next. The assessment is live today; generation and registers are in build.

01

Answer honestly

Around fifty plain questions about how your business actually handles personal information. No legal jargon, and "not sure" is always a valid answer — it's a finding, not a failure.

YOU GET
Readiness score, 0–100
Score for each condition
Critical findings, called out
02

Work the plan

Every gap becomes a task, ordered by what actually matters. Some take an afternoon — turning on MFA, moving the team to a password manager. Some are documents you don't have yet.

YOU GET
Prioritised remediation plan
Generated policy & PAIA manual
Operator agreement templates
03

Keep the evidence

Compliance isn't a state, it's a maintained record. Registers stay current as you add tools, staff and clients — and the report you hand to procurement is generated from them, not written by hand.

YOU GET
Processing & vendor registers
Consent & breach logs
Shareable readiness report
§ 04 / the assessment

Find out where you actually stand.

Your score is free. So are your three highest-priority fixes.

Before you start

Answer as things really are, not as you'd like them to be — a wrong answer only produces a wrong plan. Nobody sees this but you.

30 QUESTIONS ~6 MINUTES 8 CONDITIONS NO SIGNUP
§ 05 / pricing

Priced in rands. Month to month.

The assessment is free and always will be. Paid plans open as each part ships — and founding members keep their price permanently.

Open now · limited

Founding member

R750 /month
First ten customers, price locked for good
  • Everything in Business, permanently
  • Full remediation plan and per-condition breakdown
  • Direct line to me — you shape what gets built next
  • Generated documents, as they ship
  • Registers and readiness report, as they ship
Talk to me

You're buying early access and influence, not a finished product. If it isn't useful, walk away.

From launch

Starter

R499 /month
Freelancers and micro-agencies
  • Full remediation plan
  • Per-condition breakdown
  • Privacy policy and PAIA manual
  • Retention schedule
  • Annual re-assessment
Start with the assessment
From launch

Business

R1,499 /month
Agencies, SaaS and fintech, 5–50 people
  • Everything in Starter
  • Processing, vendor, consent and breach registers
  • Operator agreements and incident response plan
  • Shareable readiness report
  • Regulation-change alerts
Start with the assessment
STATUS

The assessment, scoring and remediation plan work today. Document generation, registers and the readiness report are in build, and every generated document goes through an attorney before anyone relies on it. Greyed items above aren't available yet — I'd rather tell you that now than after you've paid.