We don't do POPIA — here's who does
POPIA tooling in South Africa is already well served. There are tools that scan your systems and track consent from around R750 a month, and they do it better than a questionnaire could. What almost nobody covers is whether the AI your team uses every day is actually governed. That's our job.
If POPIA is what you need
Look for a dedicated POPIA tool. The local ones handle data mapping, consent records and subject requests, and several start under R1 000 a month. A law firm or privacy consultant is the right call for the legal questions. We'd rather point you there than sell you a thinner version of it.
Where AI and POPIA meet
The two aren't separate problems. The minute someone pastes a customer list, a CV or a support thread into an AI tool, it's a privacy question as well as an AI one. Our ISO/IEC 42001 assessment covers exactly that: what data may be used with AI, where it's stored, whether the supplier trains on it, who signed it off, and whether a person checks decisions that affect people. That work counts towards POPIA too, even though we don't assess POPIA itself.
What we do cover
ISO/IEC 42001 readiness
Check whether your business uses and builds AI tools in a responsible, well-managed way.
Take a lookISO/IEC 27001 readiness
See how close you are to the international standard for keeping business information safe.
Take a look