Handle access and deletion requests
People can ask what you hold and ask you to correct or delete it. Have a simple process and a reasonable timeframe to respond.
Breach response steps
If personal information is compromised, contain it, assess it, and notify the Information Regulator and affected people as required. A written plan keeps you calm.
The Information Officer
Every organisation has one (the owner by default). They're responsible for compliance and can be registered with the Regulator. Brief them and keep this course handy.
Key takeaway
POPIA compliance is ongoing practice: map your data, be transparent, get consent, secure it, and be ready to respond.