---
title: "POPIA and PAIA Controls"
space: "SA Practitioner Guide"
url: "https://wiki.cohenix.cloud/sa-guide/reference-operations/popia-paia-controls"
updated: "2026-08-17"
---

# POPIA and PAIA controls

Use the core privacy records to document governance; they do not replace organisational policies or Information Regulator processes.

The records do not automatically decide lawful basis, notify the Information Regulator or data subjects, execute
retention deletion, or produce a legally approved PAIA manual. Those decisions remain with the Information Officer
and the organisation's advisers.

- Register the Information Officer and retain independent review evidence.
- Maintain processing activities, lawful purpose, retention, operators and cross-border safeguards.
- Verify identity before responding to a data-subject request.
- Restrict payroll, tax IDs, bank details, disability, injury and medical information by role, company and purpose.
- Record incident containment, notification assessment, regulator/data-subject communication and remediation evidence.
- Maintain and approve the PAIA manual and publication evidence.

Do not place real personal, medical, banking or tax information in test fixtures, source control, logs or screenshots.
