Questions to ask before hiring for POPIA compliance
Ask these questions before hiring a POPIA consultant. Learn what answers signal genuine expertise vs evasion, and how to vet compliance help.
Hiring someone to guide your POPIA compliance is not a low-stakes handoff. You need to understand whether the person you're about to pay actually grasps what you do, what data you hold, and what the Information Regulator will care about. The tension is this: you need expert help, but you also need to be sure that expert isn't just following a template or selling you false certainty. The only way to know is to ask deliberate questions and listen to how they answer—not what they know in theory, but what they'll actually do for your business.
This is an interview script. Use it before you commit.
Questions about your business, not the law
Start here, and watch the answer carefully. A consultant who dives straight into POPIA sections and obligations before asking about you is not listening. A good consultant starts by understanding your world.
Ask: "Walk me through what data we collect, where it's stored, and who inside our business can access it right now."
A strong answer involves listening more than talking. They'll ask follow-up questions: What systems do you use? Does customer data sit in spreadsheets or databases? Does your email platform hold sensitive information? Are any contractors or cloud providers involved? A consultant who sits silently or redirects you back to generic POPIA principles hasn't started the real work yet. They should be mentally mapping your data flows before they talk about compliance frameworks.
Ask: "What would happen to us if a customer's data was lost or misused?"
This reveals whether the consultant understands your specific exposure. If you're a health clinic, data loss is existential. If you're a retail chain, the risk is different. An evasive answer—one that lists only POPIA penalties, which are serious but abstract—suggests they haven't thought about what compliance actually protects in your industry. A good answer names your dependencies: your reputation, customer trust, operational continuity, regulatory relationships.
Ask: "What does your process look like from here to sign-off?"
They should outline a realistic sequence: interviews with your team, audit of systems and policies, a risk assessment specific to your business, drafting or updating policies, staff training, and ongoing support. If the answer is vague or too speedy, that's a warning. Compliance is not done in a weekend. Equally, if they cannot describe the endpoint clearly, you won't know when you're actually compliant or what you'll have in hand.
Red flags in their answers
Listen for language that should trouble you:
- "We'll make sure you're compliant." No one can guarantee that. Compliance is a state of effort and good practice, not a certificate you tick off. A credible consultant will say they'll help you build processes that meet the regulation *as they stand now* and create the structure for you to stay compliant as circumstances change.
- "We handle all the POPIA stuff." They shouldn't. POPIA responsibility sits with your business. A consultant should help you build the systems and knowledge so your team owns the work. If they position themselves as the sole keeper of compliance, you'll be dependent and exposed the moment they leave.
- "Your industry doesn't really need to worry about this." Wrong. POPIA applies across sectors, and the Information Regulator has made clear they will investigate complaints. Dismissal is a sign of poor understanding, not reassurance.
- Vague about who they've worked with before. Ask for examples of compliance projects they've completed in your industry or a similar business. If they cite only household names or give no detail, it suggests limited real experience.
What to ask about ongoing support
Compliance is not a one-time project. Ask: "What happens after the engagement ends? If our business changes—new systems, new data sources, staff turnover—who helps us stay on track?"
A good consultant will outline an aftercare model: refresher training, periodic audits, a named contact for questions, or a retainer for ongoing advice. They might also explain what *you* need to do internally—who owns data protection as a responsibility, how often policies should be reviewed, what incidents trigger a response.
Ask: "If we need to report a data breach to the Regulator, will you help us?"
Yes is the right answer. If they hesitate or say that's outside their scope, you've found a gap. POPIA requires you to report certain breaches; having a partner who can advise you through that moment is crucial.
The consultant you hire should be able to answer these questions clearly and specifically about *your* business, not generic compliance doctrine. That's how you know they're worth the investment.
Common questions
- Should I ask about their POPIA qualifications or certifications?
- Yes, but ask what specific POPIA training or accreditation they hold, and ask for examples of compliance engagements they've completed. Avoid consultants who cite only international data protection frameworks (like GDPR) without naming POPIA projects. Request permission to contact a past client in your industry if possible.
- What's a realistic timeline they should give you for a compliance project?
- This depends on your business size and complexity, but a consultant should break it into phases with clear timelines for each stage. Be wary of anyone who guarantees completion in a few weeks or quotes a fixed price without first understanding your data landscape. They should explain what happens in each phase so you know when you'll have deliverables.
- Can they tell me what POPIA compliance will cost my business?
- Not upfront without knowing your circumstances. Instead, ask how they price their work—hourly, project-based, retainer—and what's included in each option. They should estimate the scope of work (interviews, audits, policy drafting, training) so you can budget. Ask if their estimate includes ongoing support or if that's separate.
- What if I'm unsure whether they actually understand my industry?
- Ask them to walk you through how they'd approach a business like yours, naming specific data types and risks you handle. If their answer is generic, request a reference from a similar client. A consultant with real industry experience should be able to speak to your operational reality, not just generic POPIA rules.
Find a verified provider on Strove
Compare vetted data protection compliance (popia) providers, check their credentials, and book or request a quote — all in one place.
Find a Business