Solution

Build for POPIA from the start

Retrofitting data protection into a working system costs several times what designing for it would have.

Book a consultation

Compliance is an architecture decision, not a document

POPIA is usually treated as a policy exercise: write the privacy notice, add a consent checkbox, file it. Then an actual request arrives asking what personal information you hold about someone and where it went, and the system cannot answer, because nobody designed it to.

Almost every expensive compliance problem is really an architecture problem that was cheap to solve at design time and is not cheap now.

What you get

The deliverables, specifically.

Know what you hold and why

Personal information mapped to a lawful basis and a purpose at design time, so the answer exists before anyone asks.

Consent as a record, not a checkbox

What was agreed, when, and to what, stored as data that can be produced later rather than implied by a form submission.

Audit trail by default

State changes recorded as they happen. Reporting then becomes a query rather than a reconstruction.

Retention and deletion that actually run

A retention rule that is written in a policy and not implemented in the system is not a retention rule.

How it runs

From first call to handover.

01

Map the personal information

What is collected, from whom, why, where it goes and who can see it.

02

Design the record structures

Consent, audit and retention as first-class parts of the data model.

03

Build access control properly

Who can see what, enforced by the system rather than by convention.

04

Prove it works

Run a real access request and a real deletion against the system before you need to.

Is this the right piece of work?

A good fit when

  • You are building something new that will hold customer personal information
  • You could not currently answer a request about what you hold on someone
  • You are in a sector where a client or regulator will eventually ask

We will say no when

  • You need a legal opinion. We build systems; we are not your attorneys and will say so.
  • You want a certification badge without changing anything underneath it.

The Samloryx platform records consent events as data and keeps a privacy position the business can actually stand behind. See the security page for what is and is not claimed.

Other problems we solve

Ship software faster

When releases take weeks and nobody is sure why, the problem is usually the process around the code rather than the people writing it.

Add engineering capacity

More work than people, but not enough certainty to justify permanent hires yet.

See what is actually happening

Decisions made on assembled spreadsheets are decisions made on last month's data.

Not sure this is the right starting point?

A short call costs nothing and usually makes the answer obvious. If a different piece of work suits you better, we will say so.

Book a consultation