Medical Practices · Law Firms · Regulated Businesses

Your practice already has an Information Officer.

It is almost certainly the principal, the managing partner or the MD — POPIA appoints the head of the body by default, whether or not anyone has ever said so out loud. And under section 55(2), an Information Officer may only take up those duties once registered with the Regulator.

So the obligation is already yours. The question is only whether the paperwork, the mapping and the breach plan behind it exist yet.

What we find

Three gaps, in almost every practice we open up.

No registrationThe Information Officer has never been designated in writing or registered on the Regulator's eServices portal.
No PAIA manualOr one downloaded years ago, never matched to how the practice actually works, and inconsistent with what would be registered.
No breach planNothing written for the day patient records or privileged client files are exposed — no roles, no clock, no notification runbook.

Why the timing matters. The Information Regulator has confirmed a rising volume of investigations, including own-initiative assessments, and has introduced a compliance monitoring programme that expects organisations to demonstrate POPIA implementation through documentation, internal controls and governance.

The pattern that matters for you: what is being asked for is evidence, not intent. A practice that has mapped its data can produce it. One that has not is assembling it under a deadline set by somebody else.

How it is structured

Four tiers. Start at the one that closes a real obligation.

Fixed fee against a written scope with a named exclusion list — never hourly. Most practices start at Tier 0 because it is small, fast and closes something that is already overdue. What it uncovers tells you honestly whether you need the rest.

Tier 0 — Officer Registration Sprint

R12,000 – R18,000

About two weeks

Information Officer and Deputies correctly designated, a PAIA manual that matches what gets registered, and the registration itself submitted on the Regulator's eServices portal with the confirmation record kept on file.

Tier 1 — Regulator Readiness Pack

R55,000 – R95,000

The full programme

Full data mapping, breach-radius scoping, the manual and policy set, incident response and recovery planning, and registration. The eleven deliverables are listed below.

Tier 2 — Readiness Pack + Technical Hardening

R95,000 – R160,000

Assessment and remediation

Everything in Tier 1, plus remediation of the controls the mapping exposes. Taken when you would rather fix what is found than receive a report about it.

Tier 3 — Managed Readiness

R6,500 – R18,000 / month

Ongoing

Quarterly re-test, register and record upkeep, data subject request support, and breach on-call. Compliance decays quietly — staff turn over, systems get added, vendors change.

Tier 1 in full

What you actually receive.

  1. Personal information inventory. Every system, file share, camera, reader, register and third party holding personal information, by category — including special personal information such as health records, and children's information.
  2. Data flow maps. Collection point, transport, storage, access, retention, destruction — per flow, drawn rather than described.
  3. Breach-radius scope. Our signature analysis. For each store: how many data subjects, which categories, who and what could reach it in a compromise, what the notification obligation would be, and the three changes that shrink the radius most.
  4. Processing register with a lawful-basis note per flow.
  5. Operator and third-party register. Every processor — cloud host, payroll bureau, practice management vendor, billing bureau — with a gap list of missing operator agreements. The agreements themselves are drafted by the partner firm.
  6. Security safeguards assessment against POPIA's section 19 requirement: identity, access, logging, retention, encryption, backup, and evidence that a restore has actually been tested.
  7. Incident response and recovery plan. Detection, containment, the Regulator and data-subject notification runbook, evidence preservation, and a decision tree with named roles and timeframes.
  8. PAIA manual and the POPIA policy set — privacy notice, retention schedule, data subject request procedure, and consent and notice wording for your collection points.
  9. Data subject request workflow with response templates and a clock.
  10. Awareness session. Ninety minutes for the staff who actually touch the data — reception, practice admin, billing — not a generic e-learning module nobody finishes.
  11. Officer registration. Designation letters, delegation instrument, portal submission, confirmation record.

Where we stop

Three things we will not sell you.

Each of these is a boundary, not modesty. A provider who offers them either misunderstands the law or is hoping you do. They appear as written exclusions on every proposal we send.

We cannot be your Information Officer. The Regulator's guidance is that the authorisation must come from within the body, and that the person should be an employee at executive level or equivalent. We prepare the instruments, make the submission, and train and back the person appointed — but the role stays inside your practice. "Outsourced Information Officer" is not a service anyone can lawfully provide to you.
We do not advise on insurance. Underwriters ask for evidence most practices cannot currently produce — control inventory, access and backup evidence, incident history, breach-radius analysis. We produce exactly that and hand it to your own broker. ASi Imperium is not an authorised financial services provider; we do not recommend cover, compare policies or take commission.
We do not give legal advice. Our reports state findings of fact and technical recommendations. Legal opinions on lawful basis, liability and director exposure, operator agreements, and any correspondence with the Regulator go to a data protection law firm — and we say so in the report rather than blurring the line. Our manual and policy templates are reviewed and approved by that firm.

Remediation beyond the assessment is also excluded unless Tier 2 is taken. We would rather you read that here than discover it in a scope argument later.

Common questions

Straight answers.

Who is the Information Officer of a medical practice or law firm?

POPIA designates the head of the private body as the Information Officer by default, so in most practices it is the principal, the managing partner or the MD — whether or not anyone has ever said so out loud. That person may authorise another natural person inside the organisation to act, but the authorisation has to come from within. The role carries personal duties, which is why it is worth knowing it sits with you before the Regulator tells you it does.

Does an Information Officer have to register with the Information Regulator?

Yes. Registration is compulsory and runs through the Regulator's eServices portal, and under section 55(2) of POPIA an Information Officer may only take up their duties after registration. That is the part most practices miss: the obligation is not suspended while you are unregistered — the duties simply sit with a person who is not yet permitted to perform them.

Can ASi Imperium act as our Information Officer?

No, and no external provider can. The Regulator's guidance is that the authorisation must be internal and the person should be an employee of the body at executive level or equivalent. We prepare the designation letters and delegation instrument, align the PAIA manual particulars with the registration, make the portal submission and keep the confirmation record, then train and support the person appointed. Any provider offering to be your outsourced Information Officer is selling something the Regulator's own guidance does not permit.

What is a breach radius?

For every place personal information sits, it is the answer to one question: if this were compromised tomorrow, how many people are affected, what categories are exposed, and would you have to notify the Information Regulator and the data subjects? For a practice holding health records or privileged client files the answer is rarely comfortable, and it is what turns a vague worry into a ranked list your partners can act on.

How long does Information Officer registration take?

The Officer Registration Sprint runs about two weeks. That covers the designation and delegation instruments, a PAIA manual that matches what gets registered, and the submission itself with the confirmation record kept on file. It is deliberately the smallest useful engagement — it closes a real obligation quickly, and what it uncovers tells you honestly whether you need the full readiness pack.

Do you give legal advice or advise on cyber insurance?

Neither. Our reports state findings of fact and technical recommendations. Legal opinions on lawful basis, liability and director exposure, along with operator agreements and any correspondence with the Regulator, go to a data protection law firm. On insurance, we produce the technical evidence an underwriter asks for and hand it to your own licensed broker. ASi Imperium is not an authorised financial services provider and does not recommend, compare or place cover.

Running a residential estate, body corporate or managing agency instead? The same programme narrowed to the boom gate is set out on POPIA at the Gate. Sector detail for medical practices and law firms sits on their own pages.

Who does this work. An engineering-led practice, certified in cybersecurity, cloud and networking, working to named standards rather than adjectives. Every engagement is scoped and authorised in writing before it starts. See our credentials — verification documents are provided to clients and procurement teams at onboarding. Our own PAIA manual is published.