Medical Practices · Law Firms · Regulated Businesses
Your practice already has an Information Officer.
It is almost certainly the principal, the managing partner or the MD — POPIA appoints the head of the body by default, whether or not anyone has ever said so out loud. And under section 55(2), an Information Officer may only take up those duties once registered with the Regulator.
So the obligation is already yours. The question is only whether the paperwork, the mapping and the breach plan behind it exist yet.
What we find
Three gaps, in almost every practice we open up.
Why the timing matters. The Information Regulator has confirmed a rising volume of investigations, including own-initiative assessments, and has introduced a compliance monitoring programme that expects organisations to demonstrate POPIA implementation through documentation, internal controls and governance.
The pattern that matters for you: what is being asked for is evidence, not intent. A practice that has mapped its data can produce it. One that has not is assembling it under a deadline set by somebody else.
How it is structured
Four tiers. Start at the one that closes a real obligation.
Fixed fee against a written scope with a named exclusion list — never hourly. Most practices start at Tier 0 because it is small, fast and closes something that is already overdue. What it uncovers tells you honestly whether you need the rest.
Tier 0 — Officer Registration Sprint
R12,000 – R18,000Information Officer and Deputies correctly designated, a PAIA manual that matches what gets registered, and the registration itself submitted on the Regulator's eServices portal with the confirmation record kept on file.
Tier 1 — Regulator Readiness Pack
R55,000 – R95,000Full data mapping, breach-radius scoping, the manual and policy set, incident response and recovery planning, and registration. The eleven deliverables are listed below.
Tier 2 — Readiness Pack + Technical Hardening
R95,000 – R160,000Everything in Tier 1, plus remediation of the controls the mapping exposes. Taken when you would rather fix what is found than receive a report about it.
Tier 3 — Managed Readiness
R6,500 – R18,000 / monthQuarterly re-test, register and record upkeep, data subject request support, and breach on-call. Compliance decays quietly — staff turn over, systems get added, vendors change.
Tier 1 in full
What you actually receive.
- Personal information inventory. Every system, file share, camera, reader, register and third party holding personal information, by category — including special personal information such as health records, and children's information.
- Data flow maps. Collection point, transport, storage, access, retention, destruction — per flow, drawn rather than described.
- Breach-radius scope. Our signature analysis. For each store: how many data subjects, which categories, who and what could reach it in a compromise, what the notification obligation would be, and the three changes that shrink the radius most.
- Processing register with a lawful-basis note per flow.
- Operator and third-party register. Every processor — cloud host, payroll bureau, practice management vendor, billing bureau — with a gap list of missing operator agreements. The agreements themselves are drafted by the partner firm.
- Security safeguards assessment against POPIA's section 19 requirement: identity, access, logging, retention, encryption, backup, and evidence that a restore has actually been tested.
- Incident response and recovery plan. Detection, containment, the Regulator and data-subject notification runbook, evidence preservation, and a decision tree with named roles and timeframes.
- PAIA manual and the POPIA policy set — privacy notice, retention schedule, data subject request procedure, and consent and notice wording for your collection points.
- Data subject request workflow with response templates and a clock.
- Awareness session. Ninety minutes for the staff who actually touch the data — reception, practice admin, billing — not a generic e-learning module nobody finishes.
- Officer registration. Designation letters, delegation instrument, portal submission, confirmation record.
Where we stop
Three things we will not sell you.
Each of these is a boundary, not modesty. A provider who offers them either misunderstands the law or is hoping you do. They appear as written exclusions on every proposal we send.
Remediation beyond the assessment is also excluded unless Tier 2 is taken. We would rather you read that here than discover it in a scope argument later.
Common questions
Straight answers.
Who is the Information Officer of a medical practice or law firm?
POPIA designates the head of the private body as the Information Officer by default, so in most practices it is the principal, the managing partner or the MD — whether or not anyone has ever said so out loud. That person may authorise another natural person inside the organisation to act, but the authorisation has to come from within. The role carries personal duties, which is why it is worth knowing it sits with you before the Regulator tells you it does.
Does an Information Officer have to register with the Information Regulator?
Yes. Registration is compulsory and runs through the Regulator's eServices portal, and under section 55(2) of POPIA an Information Officer may only take up their duties after registration. That is the part most practices miss: the obligation is not suspended while you are unregistered — the duties simply sit with a person who is not yet permitted to perform them.
Can ASi Imperium act as our Information Officer?
No, and no external provider can. The Regulator's guidance is that the authorisation must be internal and the person should be an employee of the body at executive level or equivalent. We prepare the designation letters and delegation instrument, align the PAIA manual particulars with the registration, make the portal submission and keep the confirmation record, then train and support the person appointed. Any provider offering to be your outsourced Information Officer is selling something the Regulator's own guidance does not permit.
What is a breach radius?
For every place personal information sits, it is the answer to one question: if this were compromised tomorrow, how many people are affected, what categories are exposed, and would you have to notify the Information Regulator and the data subjects? For a practice holding health records or privileged client files the answer is rarely comfortable, and it is what turns a vague worry into a ranked list your partners can act on.
How long does Information Officer registration take?
The Officer Registration Sprint runs about two weeks. That covers the designation and delegation instruments, a PAIA manual that matches what gets registered, and the submission itself with the confirmation record kept on file. It is deliberately the smallest useful engagement — it closes a real obligation quickly, and what it uncovers tells you honestly whether you need the full readiness pack.
Do you give legal advice or advise on cyber insurance?
Neither. Our reports state findings of fact and technical recommendations. Legal opinions on lawful basis, liability and director exposure, along with operator agreements and any correspondence with the Regulator, go to a data protection law firm. On insurance, we produce the technical evidence an underwriter asks for and hand it to your own licensed broker. ASi Imperium is not an authorised financial services provider and does not recommend, compare or place cover.
Running a residential estate, body corporate or managing agency instead? The same programme narrowed to the boom gate is set out on POPIA at the Gate. Sector detail for medical practices and law firms sits on their own pages.
General information, not legal advice. This page describes technical assessment and compliance-support work and summarises publicly available regulatory material. It is not a legal opinion on your obligations — confirm the current requirements, or take advice, before relying on it. Fee ranges are indicative and every engagement is quoted as a fixed fee against a written scope after a short call. On insurance: ASi Imperium (PTY) LTD is not an authorised financial services provider; we do not recommend, compare or place cover, and insurance decisions require a licensed broker.
Who does this work. An engineering-led practice, certified in cybersecurity, cloud and networking, working to named standards rather than adjectives. Every engagement is scoped and authorised in writing before it starts. See our credentials — verification documents are provided to clients and procurement teams at onboarding. Our own PAIA manual is published.