Skip links
The Privacy Journey

Understand where your organisation is on its privacy journey and what to do next.

Eighteen phases take you from establishing accountability to auditing and continually improving. Start with an assessment, get your maturity level, and work a prioritised plan.

18 programme phases 5 maturity levels POPIA + PAIA
The privacy journey

One line, drawn from where you are to where the board needs you to be.

8 MOVES.
18 PHASES.

Follow the line, or pick up a step to see what it covers.

01/ 08
Discover
Assess
Remediate
Implement
Train
Monitor
Audit
Improve

Discover

Establish who is accountable, then find out what personal information the organisation actually holds and where it lives.

Programme phases in this step
01

Establish Privacy Governance

Establish accountability, leadership and the Information Officer.

Who is responsible for privacy?
02

Understand Personal Information

Identify what personal information the organisation holds and where it resides.

What personal information do we hold?

Assess

Test the legal footing for every processing activity, including the information that leaves South Africa.

Programme phases in this step
03

Establish Lawful Processing

Determine why and under what legal basis personal information is processed.

Are we processing information lawfully?
08

Manage Cross-Border Transfers

Identify and manage transfers of personal information outside South Africa.

Does personal information leave South Africa?

Remediate

Close the gaps the assessment exposes: the notices people see, the rules staff follow, and how long you keep information.

Programme phases in this step
04

Establish Transparency

Ensure data subjects are properly informed about how their information is collected and used.

Do people know how their information is being used?
05

Establish Policies & Procedures

Create the governance framework required to manage privacy consistently.

Do we have the right privacy rules and procedures?
09

Establish Retention & Destruction

Determine how long information is retained and how it is securely disposed of.

Why are we keeping this information, and when should it go?

Implement

Stand up the operating controls that carry the programme day to day, from requests and suppliers through to security and marketing.

Programme phases in this step
06

Implement Data Subject Rights

Establish a process for handling access, correction, objection and other data-subject requests.

Can we respond when people exercise their privacy rights?
07

Manage Third Parties & Operators

Ensure suppliers and service providers appropriately protect personal information.

Who else has access to our personal information?
10

Implement Security Safeguards

Protect personal information against loss, damage, unauthorised access and disclosure.

Is our personal information adequately protected?
12

Implement Privacy by Design

Build privacy considerations into new systems, projects and business processes.

Are we considering privacy before we launch?
13

Manage Direct Marketing & Tracking

Ensure marketing, cookies and tracking activities comply with privacy requirements.

Are our marketing and tracking activities privacy compliant?
14

Establish PAIA Compliance

Address the organisation’s obligations under PAIA alongside POPIA.

Can we properly manage information-access requests?

Train

Make privacy part of how people work, so the controls hold when nobody is watching.

Programme phases in this step
15

Implement Employee Awareness

Ensure employees understand their privacy and information-security responsibilities.

Does everyone know their role in protecting personal information?

Monitor

Watch for incidents and track performance, so problems surface early and the board sees the trend.

Programme phases in this step
11

Establish Breach Management

Ensure the organisation can detect, respond to and report privacy incidents.

What happens when something goes wrong?
17

Measure & Monitor

Establish privacy metrics, risk monitoring and management reporting.

How are we performing?

Audit

Keep the records that prove the controls exist and operate. Compliance you cannot evidence is compliance you cannot defend.

Programme phases in this step
16

Establish Compliance Evidence

Maintain the records and evidence necessary to demonstrate that privacy controls exist and operate.

Can we prove what we are doing?

Improve

Reassess as the organisation changes, address what has drifted, and draw the line again.

Programme phases in this step
18

Audit & Continually Improve

Regularly assess the programme, address gaps and improve as the organisation evolves.

Are we staying compliant as the business changes?
This website uses cookies to improve your web experience.
Home
Search