POPIA in 90 days: a practical playbook for SA SMEs
Published 10 April 2026 · Editorial update 6 September 2026 · 2 min read · Enternovate

A 90-day plan can organise a POPIA readiness project. It cannot certify compliance or pause existing legal duties. Scope and timing depend on the information you process, your risks and the controls already in place. This article is practical guidance, not legal advice.
Weeks 1 to 3: identify your responsible owners, Information Officer registration requirements, systems, operators and personal-information flows. Record why data is collected, who receives it, how it is protected and when it is deleted.
Weeks 4 to 8: review privacy notices, your applicable PAIA manual requirements, operator agreements and retention rules against actual practice. Gavaza provides assessments and document generators. Generated documents are drafts to review, not evidence that a control operates.
Weeks 9 to 12: exercise access-request handling and an incident scenario. Under POPIA section 22, notification is required as soon as reasonably possible after discovery of a qualifying security compromise, subject to the Act's provisions. Do not substitute a fixed GDPR-style deadline. Confirm the notification process with the Information Regulator and your legal adviser.
Keep an evidence register with an owner, review date and open actions. Test access controls and backups, train staff and revisit the assessment when systems or suppliers change. Readiness is an ongoing operational responsibility, not a completed template pack.