APEX
← Guides & resources

Compliance

POPIA compliance checklist for South African lenders

POPIA applies to every business that processes personal information in South Africa — and for lenders, the exposure is concentrated: client financial data, credit records, KYC documents. Penalties run to R10 million per infringement, with criminal prosecution possible in severe cases.

By the APEX Enterprise product & compliance teamGuide last reviewed 18 August 2026Reviewed by Intermediate Data Systems (Pty) Ltd

The checklist

1) An Information Officer appointed and registered. 2) Verifiable consent records. 3) Field-level access logging on personal information. 4) A DSAR workflow meeting the 21-business-day deadline. 5) Retention schedules and deletion enforced. 6) Anomaly detection on access patterns. 7) A documented breach response. 8) Tracked staff training.

The reality for spreadsheet lenders

Most of these controls can't be enforced on a workbook. The audit trail is assembled retroactively from inboxes; consent is a folder of forms; access logging doesn't exist.

System-enforced compliance

A platform enforces the controls continuously: field-level logging on every PII access, DSAR workflows with SLA tracking, anomaly detection, immutable audit history. Compliance stops being a project and becomes a property of the system.

Run the 12-point readiness check

A scored report naming your compliance gaps — and the control that closes each.

Start the readiness check

Common questions

Asked straight.

Yes — every responsible party must appoint an Information Officer and register them with the Information Regulator.