Coverage of POPIA conditions for lawful processing, Information Officer obligations under §55, operator agreement requirements under §21, and security compromise notification requirements under §22.
Protection of Personal Information Act (South Africa)
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, data subject participation.
Manual maintenance, prior authorisation requests, compliance assessments, and complaints handling supported.
Vendor DPA equivalents tracked as operator agreements with mandatory security and confidentiality obligations.
Information Regulator and data subject notification workflow supported through incident management.
Sections 14 and 51 PAIA-aligned manual generated from current configuration.
§22 notification artifact with Information Regulator submission package.
What Verisq does — and doesn’t. Verisq orchestrates the evidence: it maps controls, collects and retains supporting artifacts, tracks gaps, and assembles the packages auditors and regulators ask for. Verisq is not a certification body and does not issue, guarantee or substitute for an independent audit opinion. Compliance with any framework is determined by your organization and its assessors — our role is to make that determination fast, evidenced and defensible.
Verisq generates the artifacts your auditors and regulators expect — on demand, with current data, with framework mappings embedded.