Provara Group · Compliance Insights · Last reviewed 3 September 2026
Privacy risk should be identified before it becomes a compliance problem.
A Personal Information Impact Assessment helps an organisation understand what a processing activity involves, how it could affect data subjects, whether existing safeguards are adequate and what needs to change before an informed privacy-risk decision can be made.
Reg 4
PIIA responsibility
Action
Remediation outcome
For a South African SMME, a PIIA under POPIA does not need to become an elaborate compliance exercise.
It does, however, need to answer the right questions.
Once an organisation understands what personal information it processes, the next question should not simply be whether its data-mapping spreadsheet is complete.
It should be: what could go wrong for the people whose information we process, and are our current controls good enough?
That is where the Personal Information Impact Assessment — or PIIA — becomes part of practical POPIA governance.
The Information Regulator describes a PIIA as a procedure examining the nature, scope, context and purposes of processing and helping the responsible party evaluate potential privacy risks and impacts associated with the collection, use, disclosure and management of personal information.
PIIA in simple terms
A PIIA is a structured way of asking: What are we processing? What could go wrong for the people involved? Are our controls good enough? If not, what must we fix?
The key principle
A PIIA should not simply identify risk. It should connect risk to controls, remediation, accountability and an informed decision.
In this guide
How to approach a PIIA under POPIA
01
Statutory foundation
What is a PIIA under POPIA?
Regulation 4 places additional duties and responsibilities on Information Officers. One of those responsibilities is to ensure that a Personal Information Impact Assessment is done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information.
This wording is important.
The purpose of a PIIA is not simply to decide whether a project can be labelled “high risk”. The statutory focus is whether the organisation has adequate measures and standards to comply with POPIA's lawful-processing conditions.
The Information Regulator also indicates that PIIAs should be undertaken early in the development of a project, processing activity or new business process rather than waiting until implementation is complete.
Legal distinction
POPIA does not use the GDPR formulation that an impact assessment is required only where processing is “likely to result in a high risk”. Regulation 4(1)(b) uses broader wording concerned with whether adequate measures and standards exist to comply with the conditions for lawful processing.
02
SMME implementation
Does a South African SMME need a PIIA?
POPIA does not create a small-business exemption from the Regulation 4 PIIA responsibility.
That does not mean every SMME needs an enterprise-scale privacy-risk methodology.
The assessment process can be designed around the organisation's actual processing environment, complexity and risk while still producing a meaningful view of whether appropriate controls are operating.
Simpler processing
Keep the assessment lean Confirm the activity, purpose, information involved, lawful-processing position, safeguards and material risks without unnecessary bureaucracy.
Greater complexity
Increase the depth Examine potential effects on data subjects, suppliers, systems, international processing, safeguards and residual risk in more detail.
Material concern
Escalate before proceeding Where material deficiencies remain, additional safeguards, specialist review, management consideration or separate regulatory analysis may be appropriate.
Practical SMME principle
Keep the process proportionate. Do not make the privacy risk invisible simply because the business is small.
03
Privacy-risk screening
When should processing receive deeper privacy scrutiny?
POPIA does not prescribe a statutory checklist of “high-risk PIIA triggers”.
An organisation can nevertheless use practical screening indicators to identify activities that deserve more detailed privacy-risk analysis.
Sensitive information Special personal information, children's information, health information, biometrics or criminal-behaviour information.
Employee or other monitoring CCTV, location tracking, system monitoring or other forms of systematic observation.
New technology AI-enabled processing, biometrics, analytics, profiling or materially new technological capability.
Scale Large volumes of records, broad populations or extensive combinations of personal information.
Significant decisions Processing that could materially affect employment, access to services, finances or other important interests.
International processing Offshore hosting, foreign recipients, international transfers or material access from another country.
Combining information Linking personal information from different systems, sources or responsible parties.
Vulnerable circumstances Processing where the relationship or circumstances could increase the potential effect on the data subject.
Keep the legal distinction clear These are practical governance screening indicators. They are not a statutory list of POPIA PIIA triggers. Their purpose is to help determine how deeply a processing activity should be examined.
04
Assessment methodology
How do you conduct a practical PIIA under POPIA?
A risk score has little value if the organisation has not first understood the processing activity behind it.
Start with the processing and build the risk analysis from there.
01
Describe the processing Define what is happening, why it is happening, its scope and the environment in which it operates.
02
Identify the information and people affected Understand whose information is involved and its nature, sensitivity and volume.
03
Test the POPIA requirements Consider the relevant lawful-processing conditions, including purpose, justification, minimality, transparency, retention, security and any additional provisions applicable to the information or activity.
04
Identify what could go wrong Consider potential consequences for data subjects if the processing is excessive, inaccurate, insecure, unexpected, unfair or otherwise inadequately controlled.
05
Consider likelihood and severity Assess how likely the adverse outcome is and how serious its effect could be.
06
Examine the existing controls Identify the technical, organisational, contractual and procedural safeguards already in place.
07
Determine what remains Assess the residual risk after existing safeguards have been taken into account.
A practical way to think about risk
Processing context + potential harm + likelihood − effective controls = residual risk
This is a practical governance model, not a formula prescribed by POPIA. A scoring system may help prioritise risk, but the reasoning behind the score should remain visible.
05
Risk treatment
Turn PIIA findings into accountable remediation
Identifying a risk does not resolve it.
If the PIIA shows that existing measures are inadequate, the finding should become an action with an owner, a target date and evidence of completion.
Processing
Change the design Reduce unnecessary information, narrow access, refine the purpose or redesign the activity where appropriate.
Transparency
Fix the notice Address differences between the real processing and what data subjects have been told.
Security
Strengthen safeguards Improve access controls, authentication, storage, monitoring, deletion or other appropriate safeguards.
Suppliers
Address operator risk Clarify roles, perform appropriate due diligence, implement required arrangements and resolve supplier-control weaknesses.
Retention
Reduce unnecessary exposure Resolve unjustified or excessive retention and establish an appropriate lifecycle.
Accountability
Assign ownership Give material remediation actions accountable owners, deadlines and evidence requirements.
Your remediation record should show
□ The privacy risk identified.
□ The weakness giving rise to it.
□ What needs to be fixed.
□ Who owns the action.
□ When it should be completed.
□ What evidence will prove completion.
□ What risk remains afterwards.
□ Any appropriate approval or management decision.
06
Separate regulatory test
Is a PIIA the same as POPIA prior authorisation?
No.
This is one of the most important distinctions for an Information Officer to understand.
A PIIA is part of the organisation's privacy-risk and compliance assessment. Prior authorisation is a separate statutory regime under Chapter 6 of POPIA.
Section 57(1) identifies four categories of processing for which prior authorisation from the Information Regulator is required before the relevant processing is carried out.
01
Certain unique-identifier processing Processing a data subject's unique identifier for a purpose other than the one for which it was specifically intended at collection, with the aim of linking the information with information processed by other responsible parties.
02
Certain criminal-behaviour information Processing information on criminal behaviour or unlawful or objectionable conduct on behalf of third parties.
03
Credit reporting Processing information for the purposes of credit reporting.
04
Certain foreign transfers Transferring special personal information referred to in section 26, or children's personal information referred to in section 34, to a third party in a foreign country that does not provide an adequate level of protection as contemplated in section 72.
Section 57(2)
Section 57(2) also permits the Regulator to apply the prior-authorisation regime, by law or regulation, to other types of information processing where that processing carries a particular risk for the legitimate interests of the data subject.
Sector-specific qualification
Section 57(3) provides that sections 57 and 58 are not applicable where a code of conduct has been issued and has come into force under Chapter 7 in a specific sector or sectors of society. Organisations operating under an applicable code should therefore consider that code as part of their analysis.
Section 57(4)
Prior authorisation ordinarily needs to be obtained only once, rather than every time personal information is received or processed. The position must be reconsidered if subsequent processing departs from the processing that was authorised.
What happens if prior authorisation applies?
Section 58 creates a notification and suspension process
Processing contemplated in section 57(1) must be notified to the Information Regulator. Once notified, the responsible party may not carry out that processing until the Regulator has completed its investigation or the responsible party has received notice that a more detailed investigation will not be conducted.
4 weeks
Initial decision
The Regulator must inform the responsible party whether a more detailed investigation will be conducted.
≤13 weeks
Detailed investigation
If a more detailed investigation is undertaken, the stated investigation period may not exceed 13 weeks.
At the conclusion of a detailed investigation, the Regulator must issue a statement concerning the lawfulness of the processing. If the responsible party has suspended processing as required and no decision is received within the statutory time periods, section 58(7) permits it to presume a decision in its favour and continue processing.
Why screening matters Section 59 makes contravention of section 58(1) or 58(2) an offence and refers the applicable penalty to section 107. Prior-authorisation screening should therefore be treated as a distinct regulatory control rather than merely another PIIA question.
07
Ongoing governance
When should a PIIA be reviewed?
A PIIA describes a particular processing environment at a particular point in time.
If that environment materially changes, the assumptions, safeguards and residual-risk conclusion may no longer remain valid.
Reassess when
□ The purpose of the processing materially changes.
□ New categories of personal information are introduced.
□ Processing volume or scale materially increases.
□ A new technology or significant functionality is introduced.
□ A new operator or material recipient is appointed.
□ International processing or transfer arrangements change.
□ A significant security compromise or control failure occurs.
□ Material complaints or data-subject concerns arise.
□ A legal or regulatory development changes the compliance position.
□ Remediation materially changes the residual-risk assessment.
Build privacy into change management
An effective way to keep PIIAs current is to include privacy-risk screening in procurement, new-system implementation, project initiation, product development and material changes to existing business processes.
08
Implementation discipline
Seven common PIIA mistakes
01 · Doing the PIIA after implementation Privacy risks can be harder and more expensive to fix once a project, system or supplier is already embedded.
02 · Treating the risk score as the assessment The important governance evidence is the reasoning, safeguards, findings and actions behind the number.
03 · Assessing cybersecurity only Privacy risk also includes excessive collection, unclear purpose, inaccurate information, unnecessary retention, unexpected use and inadequate transparency.
04 · Ignoring the people affected A PIIA should consider possible impact on data subjects, not merely organisational or project risk.
05 · Failing to screen for prior authorisation A PIIA does not replace the separate Chapter 6 prior-authorisation analysis.
06 · Creating remediation without owners A finding without an accountable owner and target date is unlikely to become a completed control.
07 · Never reviewing the PIIA Processing, technology, suppliers and regulation change. The assessment should change when its underlying facts change.
Practical example
An SMME introduces employee-monitoring software
Assume a business wants to introduce software that records employee system activity for security, productivity and operational-management purposes.
A PIIA should move the discussion beyond: “Can we install the software?”
Purpose What specifically is the monitoring intended to achieve?
Necessity Is the extent of monitoring genuinely required for those purposes?
Information Exactly what employee activity and personal information will be captured?
Transparency Do employees understand what is collected, why and how it may be used?
Access Who can see the monitoring information and for what purposes?
Retention How long is the detailed activity information genuinely required?
Supplier Where does the platform process the information and what operator controls exist?
Consequences Could the information influence performance, disciplinary or other significant decisions?
The PIIA brings those questions together before the business decides whether the processing should proceed unchanged, proceed with additional safeguards, be redesigned or require further review.
PIIA health check
Does your PIIA support a defensible decision?
01
Is the processing clearly described?
02
Do we know whose information is involved?
03
Have the relevant POPIA requirements been assessed?
04
Have potential effects on data subjects been considered?
05
Are existing safeguards identified and tested?
06
Has the remaining risk been documented?
07
Do remediation actions have owners and deadlines?
08
Has prior authorisation been screened separately?
09
Is there a clear privacy-risk decision?
10
Do we know when the assessment must be reviewed?
Frequently asked questions
PIIA under POPIA: practical questions
What is a PIIA under POPIA?
A Personal Information Impact Assessment is used to assess processing of personal information and whether adequate measures and standards exist to comply with POPIA's conditions for lawful processing. It should help identify privacy risks, existing safeguards and areas requiring remediation.
Does every SMME need to consider a PIIA?
Regulation 4 places responsibility on the Information Officer to ensure that a PIIA is done. POPIA does not create a general SMME exemption from that responsibility. The methodology and depth of assessment can nevertheless be proportionate to the organisation's processing environment, complexity and risk.
When should a PIIA be conducted?
The Information Regulator indicates that a PIIA should be undertaken at the early stages of developing a project, processing activity or new business process. Organisations should also consider reassessment when material aspects of existing processing change.
Is a PIIA the same as a DPIA?
Not exactly. “DPIA” is terminology commonly associated with the GDPR. South Africa's POPIA Regulations use the term Personal Information Impact Assessment (PIIA). Both involve privacy impact assessment, but the applicable legal requirements and tests should be assessed under the relevant law rather than treated as interchangeable.
Does high-risk processing automatically require prior authorisation?
No. Prior authorisation is a separate statutory regime under Chapter 6 of POPIA. Section 57(1) identifies specific categories of processing subject to prior authorisation, subject to the other provisions of section 57. A high internal privacy-risk rating does not by itself create prior authorisation.
Who should complete the PIIA?
Regulation 4 places responsibility on the Information Officer to ensure that the PIIA is done. In practice, the assessment will usually require input from the business or process owner and, depending on the activity, functions such as IT, security, HR, procurement, legal or other specialists.
What evidence should be retained after a PIIA?
A practical evidence trail may include the completed assessment, identified risks, existing safeguards, remediation actions, accountable owners, approvals or decisions, closure evidence and the basis for the residual-risk conclusion.
From assessment to governance
A good PIIA should improve the quality of the decision
A PIIA should not become another document produced solely to demonstrate that a compliance step was completed.
Its value lies in identifying privacy issues before they become embedded into systems, supplier arrangements and operational processes.
For a South African SMME, the process can remain practical: understand the activity, identify how people could be affected, test the safeguards, fix material gaps, document the decision and review it when circumstances change.
The objective is not simply to produce a PIIA. It is to make an informed, evidenced privacy decision.
Need a structured privacy-risk process?
Identify the risk. Turn the gaps into accountable action.
The Provara Group POPIA Compliance Programme gives South African SMMEs a structured implementation pathway for processing records, PIIA screening and assessment, privacy-risk remediation, prior-authorisation screening and retained governance evidence.
Regulatory basis
This guide has been reviewed for alignment, as at 5 September 2026, with the Protection of Personal Information Act 4 of 2013; the Regulations relating to the Protection of Personal Information, as amended; current Information Regulator material relating to Personal Information Impact Assessments; and the prior-authorisation regime contained in Chapter 6 of POPIA.
Regulation 4 requires the Information Officer to ensure that a Personal Information Impact Assessment is done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information.
The practical screening indicators, assessment tiers, scoring approach, remediation structure and review triggers described in this guide are governance methodologies. They are not presented as a statutory prescribed PIIA format, statutory risk-scoring methodology or statutory list of high-risk PIIA triggers.
A PIIA should not be confused with prior authorisation. Section 57(1) identifies four categories of processing requiring prior authorisation, while section 57(2) permits the regime to be applied by the Regulator, by law or regulation, to other types of processing carrying a particular risk for the legitimate interests of data subjects.
Section 57(3) provides that sections 57 and 58 are not applicable where a code of conduct has been issued and has come into force under Chapter 7 in a specific sector or sectors. Section 57(4) provides that prior authorisation ordinarily needs to be obtained only once unless subsequent processing departs from what was authorised.
Where section 58 applies, the relevant processing must be notified to the Information Regulator and may not be carried out while the statutory suspension in section 58(2) applies. Sections 58(3)–(7) regulate the decision and investigation periods and the circumstances in which a responsible party may presume a decision in its favour. Section 59 makes contravention of section 58(1) or 58(2) an offence.
Depending on the organisation and processing activity, additional requirements may arise from provisions governing special personal information and children's information, section 72, applicable codes of conduct, sector-specific legislation, regulatory requirements, the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026, contractual obligations or other laws.
Important: This article provides general compliance information and practical governance guidance. It is not legal advice, does not constitute a legal opinion and does not guarantee compliance. POPIA compliance depends on the organisation's actual processing activities, applicable authorisations, operating environment, controls, sector requirements and implementation.