Engagement

Compliance readiness assessment

A structured review of how your organisation collects, stores, and protects personal information against POPIA expectations and common audit questions.

From R18 500 per engagement — Final fee depends on number of systems, processing activities, and sites in scope.

Illustration for Compliance readiness assessment

Who it is for

Owners, compliance officers, and IT leads at SMEs preparing for customer due diligence, board reporting, or formal POPIA programmes.

Result you leave with

A clear readiness report with prioritised gaps, evidence checklists, and a practical 90-day action plan.

Format and timing

  • Format: On-site or remote workshops with written findings
  • Duration: Typically 2–4 weeks depending on scope
  • Location: Cape Town and remote across South Africa
  • Delivered by: Senior compliance advisors at Page Willowhub

Included

  • Kick-off scoping call and processing-activity inventory
  • Document and control review against agreed POPIA themes
  • Interviews with process owners for high-risk flows
  • Written readiness report with risk-ranked findings
  • 90-day remediation roadmap and follow-up debrief

Outside this engagement

  • Legal opinions or court representation
  • Penetration testing or technical vulnerability scanning
  • Ongoing outsourced DPO appointment unless separately retained

How the work unfolds

  1. Scope and processing map
  2. Evidence and interview week
  3. Gap analysis and drafting
  4. Readiness debrief with your team

How to prepare

Have access to current policies, vendor lists, and one contact who knows how personal information moves through the business.

Constraints

We work with organisations that can assign a single internal sponsor for the engagement.