POPIA Compliance Audit for an SME
Run a POPIA compliance audit for Precision Books Accounting (Pty) Ltd — a 45-employee Cape Town firm processing financial records for 3,200 SME clients — and deliver a gap analysis, remediation roadmap, and POPIA-compliant privacy notice. The Information Regulator recently issued a R5m fine to a peer firm.
Your role
Privacy Officer Consultant
Scenario
THE CLIENT Precision Books Accounting (Pty) Ltd (Reg 2014/226199/07). Head office: 3rd floor, Portside Tower, Bree Street, Cape Town. Branches: Bellville and George. Managing director: Mr Yusuf Hendricks CA(SA). Information Officer: NONE formally registered with the Information Regulator (offence in terms of s55 read with s107). WHAT THEY DO Bookkeeping, tax submissions (SARS eFiling), payroll (Sage Payroll Professional), VAT returns, and management accounts for 3,200 clients — 78% small businesses, 22% high-net-worth individuals. Approximately 40 clients are based in Botswana and Namibia (SACU cross-border processing). SYSTEMS INVENTORY (as at 20 May 2026) - Xero and Sage Business Cloud (data hosted in AWS Sydney and Dublin regions) - Google Workspace (Gmail, Drive, Meet) — global processing - WhatsApp Business (staff use personal WhatsApp Web to receive client documents — no MDM, no encryption at rest on staff laptops) - Dropbox Business (2TB) for large document transfers - Bitrix24 CRM (self-hosted at Teraco JB1) - Sage Payroll — houses ID numbers, banking details, dependants info for 3,200 employees across client base (~11,400 data subjects) - Paper archive: 8 lever-arch files/month kept in unlocked cupboard, Bree Street STAFF 45 employees, 12 with laptop access (10 firm-issued, 2 personal BYOD). No signed acceptable-use policy. No POPIA training since inception. Two staff members (both juniors) left in April 2026 and were not offboarded — their Google accounts remain active with Drive access. KNOWN INCIDENTS 1. Feb 2026: junior sent a clients bank statements to the wrong email address (typo). Not reported to Regulator or data subject. 2. Apr 2026: laptop stolen from Bellville branch — not encrypted, contained ~140 client tax returns. 3. May 2026: WhatsApp group Precision team (all 45 staff) used to share screenshots of client ID docs and bank confirmations. THE TRIGGER On 15 May 2026 the Information Regulator publicly fined a peer Cape Town firm R5,000,000 under s109(2) for failure to implement s19 security safeguards after a ransomware attack. Precisions board wants a full audit and remediation plan within 30 days. APPLICABLE LAW POPIA 4 of 2013 — all 8 conditions (ss 8–25), plus s55 (Information Officer duties), s72 (cross-border transfers), s22 (breach notification), s19 (security safeguards); Regulations 2018 (PAIA manual); ECTA 25/2002 s51 (unsolicited communications overlap); Financial Intelligence Centre Act 38 of 2001 (record retention overlap for accounting records — 5 years); Companies Act 71/2008 s24 (accounting records); Tax Administration Act 28/2011 s29 (record retention 5 years). DELIVERABLES (i) Full data-flow map (systems x purposes x lawful basis x retention x cross-border); (ii) gap analysis scoring each of the 8 conditions on 0-3 with remediation priority; (iii) 90-day remediation roadmap; (iv) POPIA-compliant privacy notice for the firms website; (v) draft Operator Agreements for AWS/Sage/Google; (vi) breach-response plan and Information Officer registration checklist.
Learning outcomes
- Map personal information flows
- Apply the 8 POPIA conditions
- Draft PAIA manual & privacy notice
- Prioritise remediation realistically
Tasks you'll complete
Data Flow Map
Table of data categories, systems, purposes, retention, cross-border status.
Gap Analysis
Score each POPIA condition 0-3 and list top 5 remediation priorities.
Draft Privacy Notice
POPIA-compliant privacy notice for the client's website.
Document pack
You'll receive 5 case documents when the simulation starts.