Skip to content

Evidence request lists

POPIA

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability and Lawful Processing

POPIASA-1
Accountability, Processing Limitation, Lawful Basis, Codes

Per South African Protection of Personal Information Act (POPIA) 2013 Sections 8-11 + Accountability + Lawfulness conditions: foundation for processing. Requirements include (a) implement Accountability (Section 8) - the responsible party must ensure conditions for lawful processing are complied with + (b) implement Processing Limitation Lawfulness (Section 9) processing must be lawful + done in a manner that does not infringe data subject privacy + (c) implement Minimality (Section 10) - processing must be adequate + relevant + not excessive + (d) implement Consent, Justification, Objection (Section 11) per lawful basis + (e) maintain Codes of Conduct Adherence where industry codes apply + (f) document applicability + lawful basis + (g) align with Information Regulator guidance.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-1
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Enforcement

POPIASA-8
Information Regulator Cooperation, Complaints, Enforcement

Per POPIA + Information Regulator: enforcement + cooperation. Requirements include (a) cooperate with Information Regulator including responding to inquiries + facilitating audits + complying with directives + (b) operate Complaints Handling and Resolution mechanism enabling complaints to responsible party + Information Regulator + (c) maintain Compliance Monitoring and Auditing including periodic review + internal audit + reporting to leadership + (d) maintain Enforcement and Penalties awareness including administrative fines + civil liability + criminal penalties + (e) maintain Regulatory Reporting and Cooperation + (f) integrate with broader compliance + governance.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-8
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Governance and Lifecycle

POPIASA-7
Information Officer, Records of Processing, Notification, Training

Per POPIA + Information Regulator guidance: governance + lifecycle. Requirements include (a) designate Information Officer where required - includes head of public + private body + delegated functions per POPIA + (b) maintain records of processing activities + (c) implement Notification to Data Subject (Section 18) - data subject must be notified of collection including identity of responsible party + purposes + recipients + retention + rights + (d) implement retention + disposal aligned to purpose + legal obligations + (e) deliver Training and Awareness across personnel + (f) maintain documented governance + accountability + (g) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-7
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

High-Risk Processing

POPIASA-4
Special Personal Information, Children, Information Quality, Documentation

Per POPIA Sections 16-17 + 26 + 34: heightened safeguards. Requirements include (a) implement Special Personal Information (Section 26) protections - religious + race/ethnicity + trade union + political + health + sexual life + biometric + criminal behaviour require prohibition or specific consent + lawful basis + (b) implement Children (Section 34) protections requiring competent person consent for children under 18 + (c) implement Information Quality (Section 16) - personal information must be complete + accurate + up to date + (d) maintain Documentation (Section 17) of processing operations + (e) maintain documented risk assessments + (f) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-4
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Individual Rights

POPIASA-3
Data Subject Rights (Access, Correction, Objection), Automated Decisions

Per POPIA Sections 23-25 + 71: data subject rights. Requirements include (a) implement Access to Personal Information (Section 23) - data subjects have right to be informed of processing + obtain copy of records + (b) implement Correction of Personal Information (Section 24) - data subjects can request correction or deletion + (c) implement Automated Decision Making (Section 71) protections - data subjects cannot be subject to a decision based solely on automated processing that has significant effects + (d) implement Right to Object (Section 11 + 69) including for direct marketing + (e) maintain mechanism for receiving + verifying + responding to requests within statutory timelines + (f) maintain records of requests + responses.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-3
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Purpose and Collection

POPIASA-2
Purpose Specification, Collection Limitation, Further Processing Limitation

Per POPIA Sections 12-15: purpose + collection + further processing. Requirements include (a) implement Collection Directly from Data Subject (Section 12) - personal information must be collected directly from the data subject + with limited exceptions + (b) implement Purpose Specification (Section 13) - information must be collected for a specific + explicitly defined + lawful purpose + (c) implement Further Processing Limitation (Section 15) - further processing must be in accordance with or compatible with the original purpose + (d) provide notice to data subjects per Section 18 + (e) maintain records of collection sources + purposes + further processing decisions + (f) maintain change management.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-2
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Security and Operator

POPIASA-5
Security Safeguards, Encryption, Access Control, Operator Obligations

Per POPIA Sections 19-22: security safeguards + operator obligations + breach. Requirements include (a) implement Security Safeguards (Section 19) - responsible party must secure personal information against loss + damage + unauthorised destruction + access + by taking appropriate technical + organisational measures + (b) maintain Operator Obligations (Section 20-21) - operators process personal information only with knowledge or authorisation of responsible party + maintain confidentiality + secure processing + (c) implement encryption + access control + activity logging where appropriate + (d) implement Security Compromise Notification (Section 22) - notify Information Regulator + affected data subjects of security compromise without undue delay + (e) integrate with broader information security programme + (f) maintain operator due diligence.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-5
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial

Transfer and Marketing

POPIASA-6
Transborder Information Flows, Direct Marketing

Per POPIA Sections 69 + 72: transfer + marketing. Requirements include (a) implement Transborder Flows (Section 72) restrictions - personal information may be transferred outside South Africa only where (i) third party subject to law or binding corporate rules providing equivalent protection + (ii) data subject consents + (iii) transfer necessary for contract performance + (iv) transfer for benefit of data subject + (b) maintain documentation of cross-border data flows + safeguards + (c) implement Direct Marketing (Section 69) restrictions - direct marketing by means of unsolicited electronic communications prohibited except where data subject has consented + is a customer of the responsible party + (d) implement opt-out mechanisms + (e) maintain inventory of transfers + (f) cooperate with Information Regulator on transfer matters.

Artefacts an auditor will ask for
  • POPIA evidence for POPIASA-6
Where this commonly fails
  • Information Officer + transborder safeguards + breach notification partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the POPIA framework page.