SA Practitioner Guide

SA Practitioner Guide

Open in ChatGPT
Ask ChatGPT about this page
Open in Claude
Ask Claude about this page

POPIA and PAIA Controls

POPIA and PAIA controls

Use the core privacy records to document governance; they do not replace organisational policies or Information Regulator processes.

The records do not automatically decide lawful basis, notify the Information Regulator or data subjects, execute
retention deletion, or produce a legally approved PAIA manual. Those decisions remain with the Information Officer
and the organisation's advisers.

  • Register the Information Officer and retain independent review evidence.
  • Maintain processing activities, lawful purpose, retention, operators and cross-border safeguards.
  • Verify identity before responding to a data-subject request.
  • Restrict payroll, tax IDs, bank details, disability, injury and medical information by role, company and purpose.
  • Record incident containment, notification assessment, regulator/data-subject communication and remediation evidence.
  • Maintain and approve the PAIA manual and publication evidence.

Do not place real personal, medical, banking or tax information in test fixtures, source control, logs or screenshots.

Last updated 1 week ago
Was this helpful?
Thanks!