Skip to content

Preparing your organisation for a POPIA audit

28 July 2026 · 6 min read · Data, Digital and Cyber Security

The Protection of Personal Information Act asks a deceptively simple question: can you account for the personal information your organisation holds, and can you justify each use of it. Most organisations discover during preparation that they cannot, and that is the real value of getting ready.

Start with a data inventory

Before policies, before training, list what you actually hold. Which systems store personal information, whose information it is, why you collected it, who can see it, and how long you keep it. This inventory is tedious to build and impossible to fake, which is precisely why regulators ask for it.

Appoint and empower an Information Officer

Every responsible party has an Information Officer by default, usually the person in charge. What matters is whether that role has been made real, with the time and authority to answer requests, log incidents, and say no to a use of data that cannot be justified.

Test your breach response before you need it

A breach is not the moment to invent a process. Decide in advance who is told, within what time, and who decides whether the Regulator and affected people must be notified. Walk through one realistic scenario as a group. The gaps you find in a calm room are far cheaper than the ones you find in a real incident.

Make training specific

Awareness training that stays general changes nothing. Tie it to the actual systems and forms your people use, so a clerk knows what to do when a customer asks to see their record, and a manager knows why a spreadsheet of ID numbers should not sit on a shared drive.

BMC Training runs practical programmes in Data, Digital and Cyber Security. See the courses in this area.

Courses in Data, Digital and Cyber Security

Data, Digital and Cyber Security

Cyber Security Fundamentals for Business Teams

Most breaches begin with an ordinary employee making a reasonable decision on incomplete information. Cyber security is translated into...

Next session
31 Aug to 2 Sep 2026
Venue
Harare
3 day programme
FromUS$900
Data, Digital and Cyber SecurityNew

Artificial Intelligence for Business Managers

Artificial intelligence has moved from novelty to something managers are expected to have an opinion on. Non technical leaders get a...

Next session
31 Aug to 2 Sep 2026
Venue
Mauritius
3 day programme
FromUS$900
Data, Digital and Cyber Security

Data Analytics and Dashboard Reporting for Decision Makers

Organisations collect far more data than they use well. Delegates clean and structure operational data, build dashboards that answer a...

Next session
31 Aug to 4 Sep 2026
Venue
Durban
5 day programme
FromUS$900