The short version: you take a free quiz, start a 14-day trial with no card required, and land on a dashboard that already knows your estate's gaps. From there, PopiGuard turns the abstract obligation of "being POPIA compliant" into a concrete, trackable programme — a scored assessment, a task list with deadlines, a library of ready-to-sign policies, a breach register, a request-handling portal for both residents and outside parties, and a verifiable certificate at the end of it that a bank or a conveyancer can actually check. Below is what each of those pieces really does.
01 · Where it starts
A free assessment first, not a sales call
Before anyone asks for a card, you can take a 10-question snapshot quiz that gives your estate an honest risk score in under three minutes. If a trustee or estate manager wants to go further, the trial itself is free for 14 days — you can work through your estate's actual compliance tasks with no payment details at all, and only decide to subscribe once you've seen what the fuller programme finds.
02 · The assessment
A 123-question assessment across every POPIA obligation that applies to an estate
The full assessment is organised into ten modules, each tied to the specific sections of POPIA (and, where relevant, the proposed Gated Access Code — not yet in force — PAIA, and CSOS/STSMA) that govern how residential estates actually operate — not a generic, industry-agnostic compliance checklist repurposed for HOAs.
- 01 Data Inventory & Personal Information Register
- 02 Lawful Processing Basis
- 03 Access Control & Security Safeguards
- 04 Third-Party Processors & Operator Agreements
- 05 CCTV, Surveillance & Biometric Data
- 06 Access Control Data & Visitor Management
- 07 Data Retention & Destruction
- 08 Rights of Data Subjects & PAIA Manual
- 09 Breach Response Readiness
- 10 Governance & Information Officer
The assessment only asks about what your estate actually has — if you tell it there's no biometric access system, it doesn't waste your time on biometric-specific questions later. At the end, you get a scored PDF report, module-by-module, with every gap explained in plain language and tied to the specific section of law it comes from. Subscribers get one free retake every six months to refresh their score as the estate changes.
03 · Turning gaps into action
Every gap becomes a real task, not a line on a report
This is the part most compliance tools skip. A PDF report that tells you what's wrong and then leaves you to figure out what to do about it isn't much more useful than the fine itself. PopiGuard turns each finding from the assessment into a tracked task with a priority, a due date, and — for anyone who wants it — a plain-language walkthrough with a worked example of exactly how another estate closed that same gap. You can toggle between "walk me through it" mode for someone new to compliance work, and a faster mode for someone who already knows what they're doing and just wants the checklist.
04 · Your policy vault
A library of pre-filled, ready-to-adopt POPIA policies
Instead of starting from a blank page or a generic internet template, every policy in the vault — Privacy Notice, PAIA Manual, Breach Response Procedure, Operator Agreement, CCTV Policy, Data Retention Schedule, and the rest of the set — arrives pre-filled with your estate's own details. You review it, get it signed by your trustees, and upload the signed copy to build a real audit trail. If you already adopted a policy before joining PopiGuard, you can upload whatever evidence you already have instead of starting over.
05 · When something actually goes wrong
A breach register that guides you without pretending to be your lawyer
If a security compromise happens — a stolen laptop, an exposed visitor log, a misdirected email with resident data — the breach register walks you through documenting it and assessing how serious it is, based on the same factors POPIA itself asks about: was special personal information involved, is there real risk of harm, could it have been prevented, is it still ongoing. It can generate a draft notification to the Information Regulator and to affected residents.
06 · Requests from residents, and from outsiders
Two different kinds of request, handled properly
Residents asking about their own data
A public, no-login form residents can use to ask what personal information the estate holds about them, correct it, delete it, or object to how it's used. Every request gets a reference number and a tracked 30-day clock — the deadline PAIA sets for access requests, applied across the board as a stricter-than-required standard for the rest.
Outsiders requesting a specific record
A separate, structured workflow for the harder case — someone outside the estate (an attorney, an insurer, a person involved in an incident) formally requesting a specific record, like CCTV footage of an incident. This runs through its own decision process and produces the correct notice depending on the outcome, rather than being handled ad hoc over email.
07 · Your Information Officer, covered
Appointment, registration, and continuity — not just a name on a form
Every estate is legally required to have a designated Information Officer, registered with the Information Regulator, before that person can actually take up their duties. The IO Support Centre walks whoever holds that role through appointing themselves, registering with the Regulator (including exactly what to expect on the government portal itself), and — if the estate wants continuity when the chairperson rotates — designating a deputy. It also keeps a vetting register for contractors and domestic workers, and tracks the agreements the estate needs in place with its managing agent, security company, and any other operator that touches resident data.
08 · Staying on top of it, ongoing
A live compliance score, not a score that goes stale the day you get it
The score from your assessment isn't a fixed number that sits there aging. As tasks get closed, the dashboard's live score moves with it, module by module, so you can see real progress rather than waiting a year for the next full assessment to find out if anything improved. A compliance calendar pre-loads the annual events every estate has to track — an annual review of your Information Officer registration details, PAIA Manual availability, the next assessment refresh — with reminders before each one is due, and a monthly digest for the board.
09 · Proving it, to people who'll actually check
A certificate that's verifiable, not just a PDF someone could have made themselves
Once an estate meets the criteria, PopiGuard can issue a compliance certificate with a unique reference and a QR code that links to a public, no-login verification page — showing the certificate's status, score band, and validity to anyone who scans it. This is aimed specifically at the moment it actually matters: a conveyancer, a bank, or a prospective buyer's attorney checking an estate's standing during a property transaction, in seconds, without a phone call.
Alongside the certificate, a board report auto-compiles a year of compliance activity — score history, task completion, the data subject request log, the breach register — into one document trustees can present without having to build it by hand. And if the Information Regulator ever issues a formal information notice, a Regulator Response Kit bundles everything they might ask for into a single download, with a cover page that's honest about any gaps that still exist rather than hiding them.
10 · The part you don't see
Every estate's data is walled off from every other estate's
PopiGuard is a multi-tenant platform — one system serving many estates — which only works if what belongs to one estate is genuinely unreachable from another. That isolation is enforced at the database level, not just hidden behind a login screen, on every table that holds resident, trustee, or incident data. It's the kind of thing you shouldn't have to take on faith, so it's built to be structurally true rather than merely promised.