Logo Lanfrica

ndlovumandla/popiaguard

Domaine:

digital infrastructure

Type de record:

software
Créateur:
ndl
Hôte:
POPIA Compliance Management Platform for South African SMEs — built with Next.js 15, TypeScript, Drizzle ORM, PostgreSQL # 🛡️ POPIAGuard > **POPIA Compliance Management Platform for South African SMEs** POPIAGuard is a full-stack web application that helps South African businesses comply with the **Protection of Personal Information Act (POPIA)** — South Africa's data protection law. It provides a centralised dashboard to manage data inventories, consent records, breach incidents, access requests, privacy policies, and compliance tasks. --- ## 📋 Table of Contents 1. What is POPIA? 2. Why You Need This 3. Features Overview 4. Tech Stack 5. Pages & How They Help Compliance - Dashboard - Data Inventory - Consent Manager - Breach Register - PAIA Requests - Privacy Policy - Compliance Tasks - Reports & Analytics - Audit Log - Team Management - Settings 6. Compliance Score 7. Prerequisites 8. Installation & Setup 9. Environment Variables 10. Database Setup 11. Running the App 12. Using Ollama (AI Policy Generator) 13. Project Structure 14. Security Features --- ## What is POPIA? **POPIA** (Protection of Personal Information Act 4 of 2013) is South Africa's comprehensive data privacy law — similar to Europe's GDPR. It came into full effect on **1 July 2021** and applies to **any organisation** that collects, stores, or processes personal information about South African residents. ### Key obligations under POPIA: | Obligation | What it means for your business | |---|---| | **Lawful processing** | You must have a valid legal reason to collect personal data | | **Purpose specification** | Data may only be collected for a specific, defined purpose | | **Information Officer** | Every organisation must designate a responsible person | | **Data subject rights** | People can access, correct, or delete their data | | **Security safeguards** | You must protect data against loss, theft, or unauthorised access | | **Breach notification** | You must report breaches to the Information Regulator within 72 hours | | **Privacy policy** | You must tell people what data you collect and why | ### Pen …