POPIA as operating practice, not a binder.
Registration, notices, and controls that match how the business actually runs.
Last updated: September 2026
A POPIA file that nobody operates is not compliance. It is storage. The Information Regulator asks how you process information, who is accountable, and what you do when something goes wrong — not whether you bought a template.
Impact Elements registered an Information Officer (IO Reg. 2026-063729) and runs the same class of controls we implement for clients: access, retention, incident paths, and a way to answer a monitoring notice on a compressed timeline. We did that for ourselves first so the advice is not theoretical.
What we will and will not do
- Readiness assessment when you want gaps before the Regulator finds them.
- Monitoring-notice response when the clock is already running.
- Retainer support for a registered IO who still has a day job.
- We will not turn a network or software engagement into a compliance project by default.
Governance sits beside the wider practice — cyber, networks, applications — because the paperwork only holds if the estate does.