Loading Events

« All Events

  • This event has passed.

Info Sharing Session: Gearing Up For POPIA

25 March, 2021
9:00 am - 10:00 am


25 March, 2021 @ 9:00 am - 10:00 am

Gearing up for POPIA (Protection of Personal Information Act)

Presented by Karus Prinsloo (inlexso (Pty) Limited)

Thank you very much Karus for presenting at our info-sharing event on the 25th March 2021. Thank you also to all those who attended which was over 160 attendees.


Organisations are gearing up for 1 July 2021! The Protection of Personal Information Act (“POPIA”) has commenced and the year grace period for enforcing POPIA by the Information Regulator established in terms of POPIA, will end at 30 June 2021. The Information Regulator will be enforcing the Act from 1 July 2021.

During the Information sharing session, the following topics were covered:

A brief overview of POPIA:
An overview was provided of:

  • Some important definitions
  • How POPIA works
  • Business areas impacted by POPIA
  • Practical implications and consequences of non-compliance

The Role of the Information Officer:

  • Every organisation has an IO. This role introduced by The Promotion of Access to Information Act (PAIA).
  • Register IO with Information Regulator 1 May onwards
  • IO to take up duties after registering with the Information Regulator

POPIA Section 55: Duties and responsibilities of Information Officer & POPIA Regulation 4 Responsibilities of Information Officers

Duties of IO

  • Encouraging compliance with the conditions for the lawful processing of personal information
  • Dealing with information requests made to the responsible party
  • In event of the responsible party being investigated, working with the Information Regulator
  • “Otherwise ensuring compliance”
  • Other duties which may be prescribed.

Ensuring that:

  • A compliance framework is developed, implemented, monitored and maintained
  • A personal information impact assessment is done to ensure that adequate measures and standards exist in order to comply with the conditions for the lawful processing of personal information
  • A manual is developed, monitored, maintained and made available as prescribed in sections 14 and 51 of the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000)
  • internal measures are developed together with adequate systems to process requests for information or access thereto; and
  • internal awareness sessions are conducted regarding the provisions of the Act, regulations made in terms of the Act, codes of conduct, or information obtained from the Regulator.

Next steps:

  • Formulate an implementation plan (e.g. POPIA Readiness Assessment (PRA)
  • Identify areas of the business impacted
  • Have a POPIA champion for the organisation, pulling together all implementation initiatives from representatives across all areas of responsibility
  • Identify documents and processes to change

POPIA Readiness Assessment (PRA) in the BarnOwl Cloud

What is the BarnOwl cloud PRA solution:

  • BarnOwl Cloud is an action plan & task management SaaS (software as a service) sitting in the Microsoft Azure cloud pre-populated with
  • Inlexso’s PRA (POPIA Readiness Assessment) template of best-practice POPIA tasks

Easy to:

  • sign up for
  • assign participants (owners) to the various POPIA tasks
  • collaborate on POPIA tasks
  • monitor progress of your POPIA tasks
  • get the job done

The need for effective risk management

Key benefits:

  • Fast track POPIA compliance: pre-populated template of tasks (including a link to the relevant sections of the act)
  • Structured approach: manage your POPIA tasks in a structured way
  • Drive ownership: assign participants (owners) to tasks including the ability to assign internal and external participants
  • Real time progress monitoring: be able to track progress of tasks in real-time including alerts and notifications
  • Collaboration: Enable participants to upload evidence and participate in discussion forums against each task
  • Task driven: Drive ownership and accountability of tasks to get the job done

How do you sign up:

  • Sign up automatically via the BarnOwl Cloud link (anticipated launch date 7th April 2021). We will be sending out the BarnOwl Cloud link via email as close to the 7th April 2021 as possible.
  • Secure login and password (Microsoft Azure secure sign on – we do not store login details in the database
  • Enter your organisation name (totally distinct and secure multi-tenanted database)
  • Add participants (within your organisation or external to your organisation)
  • Start using the system (simple, user friendly and intuitive)

How much does it cost:

  • Free trial period of 30 days with sample PRA content
  • Thereafter cost effective ‘pay as you go’ pricing for the BarnOwl cloud solution (per month / annum) with sliding scale based on the number of users (participants)
  • PRA content pricing: TBA

Presentation and Video links:

Please see link for Gearing up for POPIA presentation here, the BarnOwl Cloud PRA presentation here and the info sharing recording here

Useful and associated links:




IT Web: More POPI act sections come into force

IT Web: Data from Experian breach dumped on the Internet

IT Web: Lombard Insurance engages SA authorities after data breach

IT Web: Life Healthcare reveals damage caused by data breach

IT Web: Stefanutti Stocks shuts down IT systems after cyber attack

https://barnowl.co.za/knowledge-centre/ and https://barnowl.co.za/videos/


Thank you:

Once again thank you Karus Prinsloo for your time and for your informative presentation. Thank you too, to all those who attended our info sharing session. We look forward to seeing you at our next info sharing session. Please keep a look out for our upcoming events at: https://barnowl.co.za/events/

Kind regards

Jonathan Crisp

Director – BarnOwl GRC and Audit software

About BarnOwl

BarnOwl is a fully integrated governance, risk management, compliance and audit software solution used by close to 200 organisations in Africa, Australasia and the UK. BarnOwl is a locally developed software solution and is the preferred risk management solution for the South African public sector supporting the National Treasury risk framework. Please see www.barnowl.co.za for more information.

About Karus Prinsloo, Legal Adviser and Trainer at inlexso (Pty) Limited


Karus is a seasoned and solution focused compliance, privacy and legal advisor and trainer and is employed by inlexso since 2015.

He has more than 10 years’ experience as consultant and in-house advisor in the legal and compliance environment, advising clients in industries such as logistics, mining, manufacturing, aviation, construction, financial services, banking, agriculture and property.

His experience as consultant, manager, director and in-house compliance specialist includes advising on, designing/ reviewing of compliance and risk management frameworks, drafting of policies, compliance monitoring, management reporting, preparing newsletters about regulatory amendments, preparing compliance content such as compliance manuals, self-assessment questionnaires, compliance calendars and compliance risk management plans (CRMPs) and providing training on compliance related matters.

His experience includes approximately 6 years as advisor and trainer in respect of the Protection of Personal Information Act (POPIA). He has assisted clients with POPIA readiness in industries such as retail, manufacturing, construction, aviation and tertiary education. POPIA training experience includes presenting on POPIA since 2014 and since 2017 on behalf of Enterprises University of Pretoria (Pty) Ltd.

Before joining inlexso (named EOH Legal Services at that stage) in 2015, Karus was a director of iThemba Legal & Compliance (Pty) Ltd, specialising in legal compliance and commercial law.

Karus has practiced as attorney and served as in-house compliance advisor, compliance consultant, company secretary and corporate legal advisor. He was admitted as attorney in 2003.

You can find more information about inlexso at www.inlexso.co.za or contact Karus at Karus.prinsloo@inlexso.co.za

About Jonathan Crisp, Director, BarnOwl GRC Software Solutions


Jonathan Crisp has a BSc Honours in Computer Science, as well a Risk-Based Internal Auditing certification. He has over 30 years’ experience in the IT industry and is one of the founding directors of IDI Technology Solutions.

IDI are the owners and software developers of the BarnOwl GRC and Audit software solution which is the preferred GRC solution in the public sector, endorsed by the Office of the Accountant General (OAG) of South Africa.

Jonathan is an active member of the Risk Intelligence Committee at IRMSA (Institute of Risk Management SA) and is a member of the IIA (Institute of Internal Audit SA).

You can find more information about BarnOwl at www.barnowl.co.za or contact Jonathan at jonathan@barnowl.co.za



Subscribe to BarnOwl's Information Portal

Subscribe to BarnOwl’s information portal today and receive our monthly newsletter with the latest GRC and audit insights, industry updates, priority access to exclusive events, tip of the month and more straight to your inbox!


GRCReady is the official provider of risk management content for the BarnOwl GRC software solution. GRCReady provides extensive risk libraries and risk maturity checklists/surveys which are integrated with BarnOwl.

GRCReady, based in Australia, offers a comprehensive and holistic library of products and associated services including templates, policies, procedures, guidelines, checklists etc. to help owners and directors of SMEs, startups and corporates to satisfy their corporate governance, risk management and regulatory compliance needs.

By integrating GRCReady's rich content libraries into BarnOwl's GRC software, we are able to offer our clients a state of the art, turnkey GRC solution.

GRCReady provides, arguably, the most comprehensive risk and governance maturity assessment framework with detailed steps and artefacts. BarnOwl's survey and action plan portal provides a simple and effective way to monitor and report on your current state of risk maturity and suggest and drive remedial action plans to take you to your desired state of risk and governance and maturity.

By integrating GRCReady's risk libraries with the BarnOwl GRC software, means that you don't have to start from scratch. In addition, ongoing updates and insights keep you informed and up-to-date on best practices.



Season Rhyrhm is BarnOwl's preferred partner in Botswana assisting with BarnOwl implementations, support services and client relationship management.

Season Rhythm is an established and distinguished player in the ICT sector in Botswana, specialising in a range of cutting-edge solutions. Season Rhythm leverages BarnOwl to provide tailored GRC&A services to businesses in Botswana facilitating:

  • Governance: Enabling organisations to establish and uphold effective governance structures, ensuring transparency and accountability in decision making processes.
  • Risk Management: Equipping businesses with tools to identify, assess and mitigate risks, safeguarding against potential threats and ensuring continuity in a business environment.
  • Compliance: Ensuring adherence to regulatory frameworks and industry standards, protecting businesses from non-compliance penalties and fostering trust among stakeholders.
  • Audit: Streamling the audit process with comprehensive tools for planning, execution and reporting, driving efficiency and accuracy in internal audit and compliance assessments.
  • www.sr.co.bw/ict


BarnOwl works closely with NSA in the field of GRC and assurance.

NSA is an education and risk & assurance advisory services provider, consisting of a team of professional consultants and facilitators who have been hand-picked on experience and expertise. NSA services include:

  • Strategic intervention: 30 expert consultants facilitating strategic planning, combined assurance, effective governance and risk management assignments.
  • Continuous professional development: CPD training for internal auditors, external auditors, accountants, risk managers, government officials, and psychologists.
  • Online learning: accredited training for the local government sector, including the Municipal Financial Management Program and Supply Chain Management.
  • Online skills development: skills in demand for 2030, including cybersecurity, Protection of Personal Information, Artificial Intelligence, Robotics and programming.

BarnOwl and NSA work closely with our clients to align and enable best practice GRC and assurance framework & methodologies within BarnOwl. NSA regularly presents online information sharing sessions together with BarOwl.



Nico Technologies is BarnOwl's preferred partner in Malawi assisting with BarnOwl implementations, support services and client relationship management.

Nico Technologies Limited is an established IT products and services provider in Malawi, specialising in managed IT services, IT infrastructure services, IT project management, digital solutions, digital transformation and IT advisory.

Nico Technologies uses BarnOwl extensively within their own organisation to automate and manage their own risk and compliance functions.



Morgan Solus is BarnOwl's preferred business continuity specialist consulting firm with its 'BCM toolkit' software. BarnOwl GRC together with the BCM toolkit, provides a comprehensive risk management and BCM software solution.

Morgan Solus is a specialist consultancy firm focusing on risk, resilience and continuity. Morgan Solus's core services are centred on resilience, crisis management, business continuity (BCM), IT services continuity and disaster recovery (DRP) and training.

The BCM toolkit ensures a consistent approach to implementing BCM and IT disaster recover and cuts down implementation timelines by 60% whilst driving up successful outcomes.

BarnOwl's extensive GRC and assurance functionally coupled with Morgan Solus's BCM toolkit provide the ultimate risk management and BCM software solution.



Arbutus Analytics is Barnowl's preferred data analytics software. BarnOwl GRC integrated with Arbutus Analytics, provides the ultimate in continuous risk monitoring.

Arbutus Analyzer is a powerful data access and analysis solution specifically developed for auditors, business analysts, and fraud investigators. Its robust performance and user-friendly features offer you the ability to access and analyse data quickly and simply.

BarnOwl GRC, integrated with the real-time metrics from Arbutus provides a strategic early warning system driving preventative and predictive capability facilitating effective business decision making business improvement.

www.arbutussoftware.com with local sub-sahara African distributor www.betasoftware.co.za


Barnowl works closely with Pax Resilience in the field of GRC and sustainability.

Pax Resilience offers solutions in risk, resilience and cyber security. Pax Resilience strive to create peace of mind by assisting you to build the resilience in your organisation so essential to survive and thrive in the volatile, uncertain, complex and ambiguous world we live in.

Pax Resilience regularly presents online information sharing sessions together with Barnowl.



Paige Law is the official provider of compliance content for the Barnowl GRC software solution. Paige Law provides an extensive Library of South African acts including provisions [CRMPs] and checklists which are integrated with Barnowl.

Paige Law specialises in compliance, Commercial Law, Legal process consultancy, managed legal services and POPIA/ GDPR.


Registered Address

75 Malibongwe Drive
Linden Ext
South Africa

Postal Address

PO BOX 3009


+27 (0) 11 540 9100


More Information: info@barnowl.co.za
Product Support: support@barnowl.co.za

Let Us Contact You
Let Us Contact You
I grant BarnOwl permission to contact me for marketing purposes*
*You will receive BarnOwl monthly newsletters & invitations to online events. You can unsubscribe at any time.


If you need assistance with your BarnOwl software, there are three channels available to you:



You will be emailed a ticket number from our issue tracking system and your request will be managed in
this ticket until it is completed.


You can view all your existing tickets or create new ones.


+27 (0) 11 540 9112
to speak to a support consultant

Let Support Contact You
Let Support Contact You