POPIA
What is POPIA?
Protection of Personal Information Act. It comprises 8 controls organised across 8 domains, and applies in South Africa.
How POPIA maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains POPIA groups its controls into
Where POPIA overlaps with the standards you already hold
What POPIA means in your sector
What POPIA means for your job
Questions people ask about POPIA
What is POPIA?
How many controls does POPIA have?
Where does POPIA apply?
What frameworks does POPIA map to?
How do I get started with POPIA compliance?
Query POPIA programmatically
POPIA, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
POPIA API reference and MCP config →What POPIA requires, control by control
Each page carries the requirement text for one POPIA control and what an assessor expects to see as evidence.
- POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
- POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
- POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
- POPIASA-6 Transborder Information Flows, Direct Marketing
- POPIASA-7 Information Officer, Records of Processing, Notification, Training
- POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement
How ready are you for POPIA?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.