How to check a consultant actually knows POPIA, not just GDPR
Verify your POPIA consultant actually knows South African law, not just GDPR. Check registrations, references, enforcement knowledge and specific POPIA conditions.
A consultant who confuses POPIA with GDPR is a risk you can't afford. GDPR is the European Union's privacy law; POPIA is South Africa's. They overlap in philosophy but diverge sharply in definition, scope, consent rules, transfer restrictions, and what regulators actually enforce here. You need someone who lives in the South African legal and operational reality, not someone who has learned one framework and assumes it fits another.
The good hire will let you sleep because they know what the Information Regulator actually cares about, what your obligations genuinely are under POPIA's nine conditions, and how to structure your systems and policies so they hold up under scrutiny. They'll also know where POPIA is still unsettled — there's no ten-year case law library yet — and how to position you defensibly when the rules are still being written.
Check their active registration and real track record in South Africa
Start with the CIPC database. Search for the consultant's company registration number and confirm they're a legitimate legal entity. Then ask for their POPIA work history: client names or anonymised case studies that show they've actually done this in South Africa, not just read about it. Anyone worth hiring will have handled at least one full compliance project with a South African business, not just trained staff or reviewed policies for an offshore firm.
Ask them to name the nine POPIA conditions without hesitating. If they stumble or lean on GDPR's "pillars" instead, you've found a mismatch. A solid consultant will rattle off Purpose Limitation, Further Processing, Information Availability, openness, Security, Data Subject Participation, Accountability, and the Special Personal Data and International Transfer conditions with natural confidence.
Request proof they understand local enforcement and regulator behaviour
The Information Regulator of South Africa is not the ICO or a European Data Protection Authority. Ask your consultant: What has the Regulator actually done in the last two years? How many enforcement notices have been issued, and for what? What complaints do they see most often? If they can't point to real cases or say honestly that enforcement is still ramping up, they're not reading the landscape carefully enough.
Ask them to explain when and why a business might lodge a voluntary notification with the Regulator, versus when it's compulsory. Ask them what happens if you discover a breach after the fact — what's your window, what are the notification rules, and what does the Regulator expect? Their answer should be rooted in POPIA's actual text and Regulator guidance, not best-practice templates from overseas.
Phone their recent clients and ask specific questions
Request contact details for two or three references from the last 18 months — ideally businesses similar to yours in size or sector. When you call, don't just ask if they were satisfied. Ask:
- Did the consultant explain why POPIA is different from GDPR and not just imported the rules?
- Did they help you map your data flows and identify which POPIA conditions actually apply to your operations?
- Did they argue with you about something or push back on a shortcut you wanted to take?
- Have you been contacted by the Regulator since, and did their advice hold up?
- What did they do after the engagement ended — did they disappear or offer ongoing support?
A consultant who has genuinely earned trust will have references who remember specific problems they solved, not vague satisfaction.
Watch for overconfidence about unsettled ground
POPIA is still new. The Regulator's approach to certain grey areas — consent for existing customers, transfer mechanisms beyond adequacy decisions, what counts as a Special Personal Data processing justification — is still evolving. A real expert will tell you where they have confidence and where they'd recommend staying conservative until guidance lands. Anyone who claims absolute certainty about every edge case is overselling.
Also listen for how they talk about your industry's specific rules. If you're in financial services, healthcare, or telecoms, POPIA sits alongside sector regulators (FSCA, HPCSA, ICASA). A consultant who doesn't mention those intersections hasn't done their homework.
When you're ready to move forward, verify the person or team who will actually do the work — not just the senior consultant who pitched. Use Strove to find local cybersecurity consultants with POPIA expertise, check their reviews and credentials, and run these verification steps before you sign.
Common questions
- What's the fastest way to tell if a consultant is confusing POPIA with GDPR?
- Ask them to list the nine POPIA conditions from memory. If they describe GDPR's six lawful bases or hesitate, they haven't worked deeply in South African law. A consultant immersed in POPIA will answer instantly.
- Should I ask a POPIA consultant if they're registered with the Information Regulator?
- No — consultants don't register with the Regulator the way lawyers register with the Law Society or auditors with SAICA. Instead, verify they're a legitimate company through CIPC and ask for their work history and references in South Africa.
- What should I do if a consultant says POPIA and GDPR are basically the same?
- Keep looking. They're not the same. POPIA's conditions, enforcement mechanisms, and practical application in South Africa differ significantly. Hiring someone who doesn't understand that difference is a compliance gamble you'll lose.
- How recent should a reference be to count as useful?
- Ideally within the last 18 months. POPIA and the Regulator's approach are still evolving, so a client from 2020 may not reflect how the consultant handles today's landscape.
Find a verified provider on Strove
Compare vetted data protection compliance (popia) providers, check their credentials, and book or request a quote — all in one place.
Find a Business