POPIA Compliance Agent

The POPIA Compliance Agent maps how your organisation processes personal information and keeps that map current. It drafts PAIA manuals, privacy notices and section 21 operator agreements, reviews cross-border transfers under section 72 and helps you assess security compromises and prepare notifications to the Information Regulator and data subjects.

Ideal forInformation officers

The difference

From 2-3 weeks for a processing map and PAIA manual to 3-5 days

Your privacy team spends less time chasing spreadsheets and more time fixing the risks the map reveals.

Done by hand

2-3 weeks for a processing map and PAIA manual

With the Vanine agent

3-5 days

Time returned to your team

70%

Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.

A processing map you can actually maintain

Most POPIA inventories go stale months after the project ends. The agent updates the map as systems, suppliers and processes change, so your records reflect reality.

Cross-border transfers under control

Cloud services and offshore suppliers mean personal information often leaves South Africa. The agent checks each transfer against section 72 so you know which safeguard applies.

Faster, calmer breach response

When a security compromise happens, time matters. The agent helps you assess what was affected and drafts notifications quickly, with a record of every decision.

Capabilities

Turn POPIA from a once-off project into a living, evidenced programme.

Built for information officers, deputy information officers, privacy and compliance teams, in-house counsel and data protection attorneys in South African organisations.

Processing activity mapping

Builds a register of processing activities covering purpose, lawful basis, categories of data subjects and information, retention periods, systems and recipients.

PAIA manual drafting

Drafts and updates your PAIA manual under the Promotion of Access to Information Act, aligned with your processing register and information officer details.

Privacy notices

Prepares clear, plain-language privacy notices for customers, employees, job applicants and website users that reflect how you actually process information.

Operator agreements

Reviews supplier contracts for section 21 operator terms, including security safeguards and breach reporting, and drafts operator agreements or addenda where they are missing.

Section 72 transfer review

Identifies transfers of personal information outside South Africa and tests each against section 72, noting the safeguard relied on and any gaps to close.

Security compromise assessment

Guides the assessment of a security compromise under section 22 and drafts notifications to the Information Regulator and affected data subjects for approval.

How it works

From your systems to a result you sign off

Your information officer approves the register and documents, decides whether to notify, and submits notifications to the Information Regulator.

SharePointOutlookTeamsExcelWord
Any system you use
Connects

Connect the places your personal information records already live.

System inventories, supplier contracts, existing policies and data classifications from SharePoint, Microsoft Purview and your GRC or contract registers. Already use something else? We connect that too.

  • OpenAI Frontier
  • Your own AI platform or models
  • Microsoft 365 (Teams, SharePoint, Outlook, Excel)
  • Copilot Studio
  • Microsoft Purview
  • ServiceNow and GRC platforms
  • Supplier and contract registers
Works in

Runs in Teams, Copilot Studio or OpenAI Frontier, with sensitive steps routed to models hosted in South Africa where you require it.

Processing activity mapping
PAIA manual drafting
Privacy notices
Operator agreements
Section 72 transfer review
Security compromise assessment
Delivers to

A processing register in Excel or your GRC tool, draft PAIA manual, privacy notices, operator agreements and breach notification drafts in Word.

Step by step

  1. 01

    The agent starts with a scoping run or a trigger such as a new supplier or incident.

  2. 02

    It reads system, supplier and policy information and updates the processing map.

  3. 03

    It drafts or updates PAIA manuals, privacy notices and operator agreements.

  4. 04

    It flags section 72 transfers and gaps with recommended actions.

  5. 05

    Your information officer reviews and approves each document or notification.

  6. 06

    Approved documents are published and the register is updated with the evidence.

Deployment

Runs inside the tools your team already uses

The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.

Model Context Protocol

In the frontier assistant you already pay for

We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.

Adopting frontier AI across your teams
Called from ClaudeMCP connected

"Which systems hold personal information?"

Toolpopia_compliance.map_processing
entity
Retail group
information officer
Registered
Returned38 systems mappedEvery finding linked to its source document
Self-hosted

On a model you host yourself

Run the agent on open-weight models in your data centre or private cloud. Your personal information records never leave your network, which keeps POPIA and data residency straightforward.

  • Llama
  • Mistral
  • Ollama
  • or any OpenAI-compatible endpoint
Sovereign AI on your infrastructure
Bespoke systems

Inside your own software

Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.

  • REST API
  • Webhooks
  • Batch jobs
  • Embeddable review panel
Custom integrations from our software factory
Governance

Governed the same way, every route

Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.

  • Single sign-on through Entra ID, Okta or Google Workspace
  • Reads only the documents each user is already allowed to open
  • Every tool call written to an audit log you can export
How your data is handled

DATA SECURITY & PRIVACY

Your personal information records stay yours.

The agent runs inside your tenancy, reads only what each task needs, and never trains on your personal information records. Every step is logged so your auditors can see exactly what it touched.

Built for regulated work.

+
WHAT THE AGENT KEEPSONLY THE OUTPUTENCRYPTED AT REST0 BIT AES0% DELETABLE0 TRAINING RUNS

YOUR PERSONAL INFORMATION RECORDS NEVER LEAVE YOUR ENVIRONMENT

Precision AI for Institutional Workflows

Build once.Deploy across teams.Improve over time.