Engagement
Compliance readiness assessment
A structured review of how your organisation collects, stores, and protects personal information against POPIA expectations and common audit questions.
Who it is for
Owners, compliance officers, and IT leads at SMEs preparing for customer due diligence, board reporting, or formal POPIA programmes.
Result you leave with
A clear readiness report with prioritised gaps, evidence checklists, and a practical 90-day action plan.
Format and timing
- Format: On-site or remote workshops with written findings
- Duration: Typically 2–4 weeks depending on scope
- Location: Cape Town and remote across South Africa
- Delivered by: Senior compliance advisors at Page Willowhub
Included
- Kick-off scoping call and processing-activity inventory
- Document and control review against agreed POPIA themes
- Interviews with process owners for high-risk flows
- Written readiness report with risk-ranked findings
- 90-day remediation roadmap and follow-up debrief
Outside this engagement
- Legal opinions or court representation
- Penetration testing or technical vulnerability scanning
- Ongoing outsourced DPO appointment unless separately retained
How the work unfolds
- Scope and processing map
- Evidence and interview week
- Gap analysis and drafting
- Readiness debrief with your team
How to prepare
Have access to current policies, vendor lists, and one contact who knows how personal information moves through the business.
Constraints
We work with organisations that can assign a single internal sponsor for the engagement.