POPIA is a compliance framework from South Africa with 8 domains and 8 controls that map to 137 other frameworks. The largest domains are Accountability and Lawful Processing (1 controls), Enforcement (1 controls), Governance and Lifecycle (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Accountability and Lawful Processing
| Code | Title |
|---|---|
| POPIASA-1 | Accountability, Processing Limitation, Lawful Basis, Codes |
Enforcement
| Code | Title |
|---|---|
| POPIASA-8 | Information Regulator Cooperation, Complaints, Enforcement |
Governance and Lifecycle
| Code | Title |
|---|---|
| POPIASA-7 | Information Officer, Records of Processing, Notification, Training |
High-Risk Processing
| Code | Title |
|---|---|
| POPIASA-4 | Special Personal Information, Children, Information Quality, Documentation |
Individual Rights
| Code | Title |
|---|---|
| POPIASA-3 | Data Subject Rights (Access, Correction, Objection), Automated Decisions |
Purpose and Collection
| Code | Title |
|---|---|
| POPIASA-2 | Purpose Specification, Collection Limitation, Further Processing Limitation |
Security and Operator
| Code | Title |
|---|---|
| POPIASA-5 | Security Safeguards, Encryption, Access Control, Operator Obligations |
Transfer and Marketing
| Code | Title |
|---|---|
| POPIASA-6 | Transborder Information Flows, Direct Marketing |
Your Compliance Coverage
If you comply with POPIA, you already cover:
Vietnam PDPD
75%
6 controls mapped
Compare →Turkey KVKK
75%
6 controls mapped
Compare →Privacy Act 2020
75%
6 controls mapped
Compare →+ 134 more: Privacy Act 1988 (Australia) (75%), Bahrain PDPL (75%)
See all 137 mapped frameworks ↓Maps to 137 other frameworks
What is POPIA and who does it apply to?
POPIA is a compliance framework from South Africa with 8 domains and 8 controls. Protection of Personal Information Act It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does POPIA actually require?
POPIA has 8 controls organised across 8 domains. The largest domains are Accountability and Lawful Processing (1 controls), Enforcement (1 controls), Governance and Lifecycle (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of POPIA do I already cover?
POPIA maps to 137 other compliance frameworks. The top mapping partners are Vietnam PDPD (75% coverage), Turkey KVKK (75% coverage), Privacy Act 2020 (75% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement POPIA?
Start your POPIA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about POPIA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required