What you actually get, in detail
Most compliance software describes itself in a sentence and asks you to trust it. This page doesn't do that. If you're the kind of person who wants to know exactly what's inside before you sign up for anything, this is written for you. No signup required to read it, and everything below describes what's built and working today, not a roadmap.
The short version: you take a free quiz, start a 14-day trial with no card required, and land on a dashboard that already knows your estate's gaps. From there, PopiGuard turns the abstract obligation of “being POPIA compliant” into a concrete, trackable programme: a scored assessment, a task list with deadlines, a library of ready-to-sign policies, a breach register, a request-handling portal for residents and outside parties, and a verifiable certificate a bank or conveyancer can actually check. Below is what each of those pieces really does.
A free assessment first, not a sales call
Before anyone asks for a card, you can take a 10-question snapshot quiz that gives your estate an honest risk score in under three minutes. If a trustee or estate manager wants to go further, the trial itself is free for 14 days. You can work through your estate's actual compliance tasks with no payment details at all, and only decide to subscribe once you've seen what the fuller programme finds.
123 questions across every POPIA obligation that applies to an estate
The full assessment is organised into ten modules, each tied to the specific sections of POPIA (and, where relevant, the proposed Gated Access Code, not yet in force, plus PAIA and CSOS/STSMA) that govern how residential estates actually operate. This is not a generic, industry-agnostic checklist repurposed for HOAs.
01 Data Inventory & Personal Information Register
02 Lawful Processing Basis
03 Access Control & Security Safeguards
04 Third-Party Processors & Operator Agreements
05 CCTV, Surveillance & Biometric Data
06 Access Control Data & Visitor Management
07 Data Retention & Destruction
08 Rights of Data Subjects & PAIA Manual
09 Breach Response Readiness
10 Governance & Information Officer
The assessment only asks about what your estate actually has. If you tell it there's no biometric access system, it won't waste your time on biometric-specific questions later. At the end you get a scored PDF report, module-by-module, with every gap explained in plain language and tied to the section of law it comes from. Subscribers get one free retake every six months.
Every gap becomes a real task, not a line on a report
This is the part most compliance tools skip. A PDF that tells you what's wrong and then leaves you to figure out what to do about it isn't much more useful than the fine itself. PopiGuard turns each finding into a tracked task with a priority, a due date, and (for anyone who wants it) a plain-language walkthrough with a worked example of exactly how another estate closed that same gap. You can toggle between a “walk me through it” mode and a faster checklist mode.
A library of pre-filled, ready-to-adopt POPIA policies
Instead of starting from a blank page or a generic internet template, every policy in the vault (Privacy Notice, PAIA Manual, Breach Response Procedure, Operator Agreement, CCTV Policy, Data Retention Schedule and the rest) arrives pre-filled with your estate's own details. You review it, get it signed by your trustees, and upload the signed copy to build a real audit trail. If you already adopted a policy before joining, you can upload whatever evidence you have instead of starting over.
A breach register that guides you without pretending to be your lawyer
If a security compromise happens (a stolen laptop, an exposed visitor log, a misdirected email with resident data), the breach register walks you through documenting it and assessing how serious it is, based on the same factors POPIA itself asks about: was special personal information involved, is there real risk of harm, could it have been prevented, is it still ongoing. It can generate a draft notification to the Information Regulator and to affected residents.
Deliberate design choice
Nothing PopiGuard drafts is ever sent automatically. Every notification is marked as a draft that a human (ideally with a lawyer's eyes on it) reviews and sends manually. The tool's job is to make sure nothing gets forgotten under pressure, not to make legal decisions on your behalf.
Two different kinds of request, handled properly
Residents asking about their own data
A public, no-login form residents can use to ask what personal information the estate holds about them, correct it, delete it, or object to how it's used. Every request gets a reference number and a tracked 30-day clock.
Outsiders requesting a specific record
A separate, structured workflow for the harder case: an attorney, insurer or person involved in an incident formally requesting a specific record, like CCTV footage. This runs through its own decision process and produces the correct notice depending on the outcome, rather than being handled ad hoc over email.
Appointment, registration and continuity, not just a name on a form
Every estate is legally required to have a designated Information Officer, registered with the Information Regulator, before that person can take up their duties. The IO Support Centre walks whoever holds the role through appointing themselves, registering with the Regulator (including what to expect on the government portal itself), and (for continuity when the chairperson rotates) designating a deputy. It also keeps a vetting register for contractors and domestic workers, and tracks the agreements the estate needs with its managing agent, security company and any other operator.
A live compliance score, not a score that goes stale the day you get it
The score from your assessment isn't a fixed number that sits there aging. As tasks get closed, the dashboard's live score moves with it, module by module, so you can see real progress. A compliance calendar pre-loads the annual events every estate has to track (an annual review of your Information Officer registration, PAIA Manual availability, the next assessment refresh), with reminders before each one is due, and a monthly digest for the board.
A certificate that's verifiable, not just a PDF someone could have made themselves
Once an estate meets the criteria, PopiGuard can issue a compliance certificate with a unique reference and a QR code that links to a public, no-login verification page, showing status, score band and validity to anyone who scans it. This is aimed at the moment it actually matters: a conveyancer, a bank, or a prospective buyer's attorney checking an estate's standing during a property transaction, in seconds. Alongside it, a board report auto-compiles a year of compliance activity, and a Regulator Response Kit bundles everything the Regulator might ask for into a single download, with a cover page honest about any gaps that still exist.
Every estate's data is walled off from every other estate's
PopiGuard is a multi-tenant platform (one system serving many estates), which only works if what belongs to one estate is genuinely unreachable from another. That isolation is enforced at the database level, not just hidden behind a login screen, on every table that holds resident, trustee or incident data. It's the kind of thing you shouldn't have to take on faith, so it's built to be structurally true rather than merely promised.
What this page deliberately doesn't cover: the exact wording of every question, how the scoring is weighted, or the internal logic behind how a gap becomes a specific task. That's the part you'll see once you're actually using it. This page is about what you get, not how it's built underneath.
See your own estate's score
The free quiz takes about three minutes and needs no signup. If you want to go further, the 14-day trial needs no card.