Division 06 / Impact

Compliance That Builds
Reputation and Trust

22 Fixed-Fee Services in This Division

ESG strategy, POPIA/GDPR compliance, King IV governance, and B-BBEE advisory - protecting your business and building the stakeholder trust that unlocks capital and contracts.

Book a Consultation View All Divisions

Immediate Risk

POPIA review overdue?

POPIA has been enforceable since July 2021. Fines reach R10M. Most SA businesses are still non-compliant.

Immediate Risk

No valid Privacy Policy?

A generic or copied privacy policy is not POPIA-compliant. It exposes your business to complaints and regulator action.

Immediate Risk

No risk register?

Lenders, insurers, and DFIs increasingly require a live risk register before engagement. Without one, you are leaving capital on the table.

Audit Flag

Regulator investigation?

If you have received a complaint or investigation notice, you need specialist support immediately - not a generalist consultant.

Not sure where you stand? Take the 10-minute Business Health Check ->

What We Do

Core Services

Every service is delivered by a practitioner - not a generalist - with domain-specific credentials and measurable outcomes.

POPIA Compliance

Full POPIA gap analysis, policy development, staff training, data flow mapping, and PAIA manual development - with an appointed Information Officer if required.

ESG Strategy & Reporting

Material ESG assessment, target-setting, and integrated reporting aligned to GRI, SASB, and JSE Sustainability Disclosure Requirements.

King IV Governance

Board governance assessments, committee charter development, and King IV compliance reporting for listed, SOE, and large private entities.

B-BBEE Advisory

B-BBEE scorecard strategy, ownership structuring, skills development planning, and supplier development programme design to maximise your BBBEE rating.

GDPR & Data Protection

GDPR gap assessments and remediation for South African businesses with EU data subjects - including DPA agreements, breach protocols, and DPO services.

Regulatory Affairs

Ongoing regulatory monitoring, licence applications, and compliance calendars for heavily regulated sectors - financial services, healthcare, and mining.

Full Catalogue

Service Pricing

Fixed-fee engagements. Prices are standard rates - final scope confirmed at proposal stage for complex mandates. All prices exclude VAT.

Sign in or create a free account to unlock pricing and book services directly online.

CodeServiceModelInvestment (ZAR, excl. VAT)
IMP-001Process Efficiency Audit (Lean Six Sigma)Fixed ProjectR 16,500
IMP-002Standard Operating Procedures (per SOP)Fixed ProjectR 8,500
IMP-003Operational Excellence AssessmentFixed ProjectR 18,000
IMP-004ISO 9001 Gap AssessmentFixed ProjectR 14,500
IMP-005Continuous Improvement Programme DesignFixed ProjectR 22,000
IMP-006Process Governance FrameworkFixed ProjectR 14,500
IMP-007POPIA Compliance Gap AssessmentFixed ProjectR 14,000
IMP-008POPIA Full Implementation ProgrammeFixed ProjectR 78,000
IMP-009POPIA Document ToolkitFixed ProjectR 4,800
IMP-010GDPR Compliance ProgrammeFixed ProjectR 64,000
IMP-011Outsourced Information Officer (per month)RetainerR 6,500
IMP-012Privacy Impact AssessmentFixed ProjectR 12,000
IMP-013PAIA Section 51 ManualFixed ProjectR 8,500
IMP-014Data Breach Response PlanFixed ProjectR 12,000
IMP-015Annual Data Protection AuditFixed ProjectR 14,000
IMP-016King IV Governance AssessmentFixed ProjectR 22,000
IMP-017Enterprise Risk RegisterFixed ProjectR 22,000
IMP-018Internal Control FrameworkFixed ProjectR 18,500
IMP-019Compliance Programme DesignFixed ProjectR 28,000
IMP-020ESG Reporting FrameworkFixed ProjectR 28,000
IMP-021Business Continuity PlanFixed ProjectR 22,000
IMP-022Annual Governance Health CheckFixed ProjectR 16,000
22 Fixed-Fee Services
9+ Years Corporate Experience
100% Fixed-Fee Pricing
4h Enquiry Response Time
How It Works

Our Engagement Process

A structured, time-bound methodology that delivers results - not reports.

01

Compliance Audit

Gap analysis against applicable frameworks - POPIA, King IV, ESG, B-BBEE.

02

Remediation Plan

Prioritised, costed plan with clear ownership and timelines.

03

Implementation

Policy development, staff training, system changes, and documentation.

04

Ongoing Monitoring

Quarterly reviews, regulatory change alerts, and audit support.

Who We Serve

Impact Works Across Every Sector

Compliance obligations vary by industry. Our practitioners bring sector-specific knowledge to every engagement.

Financial Services

FSCA licensing, POPIA, FICA compliance, and risk governance for banks, insurers, and wealth managers.

Healthcare

Health data protection, POPIA health information rules, and clinical governance frameworks for hospitals and clinics.

Professional Services

Law firms, accounting practices, and consultancies needing client data governance and professional body compliance.

Technology & SaaS

POPIA and GDPR compliance for tech platforms processing user data across multiple jurisdictions.

Retail & E-Commerce

Consumer data governance, cookie compliance, marketing consent, and supply chain ESG requirements.

Mining & Resources

Environmental compliance, stakeholder reporting, and ESG frameworks aligned to JSE Sustainability Disclosure Requirements.

Education

Learner data protection, POPIA obligations for educational records, and governance frameworks for private institutions.

Manufacturing

Employee data compliance, supplier governance, B-BBEE strategy, and occupational safety regulatory requirements.

NGOs & NPOs

Donor reporting frameworks, governance structures for NPO Act compliance, and ESG alignment for impact investors.

Property & Construction

Client data governance, contractor compliance, CIDB requirements, and ESG reporting for large developments.

Better Value

Bundled Packages

Combine compliance services into a cohesive programme - and save up to 15% versus individual pricing. All prices exclude VAT.

Entry Level

POPIA Essentials

Everything a small-to-medium business needs to become POPIA compliant - fast. Gap assessment, core documentation, and staff training in one mandate.

  • POPIA Compliance Gap Assessment
  • Privacy Policy & PAIA Section 51 Manual
  • Data Flow Mapping
  • Staff Awareness Training (half day)
R 35,000

Delivered in 4-6 weeks - Fixed fee, no surprises

Enquire About This Pack

Operations Focus

Ops Sprint

Compliance, risk, and operational governance combined into a single 8-week engagement. Ideal for businesses preparing for a funding round or major contract.

  • POPIA Full Implementation
  • Enterprise Risk Register
  • Internal Controls Assessment
  • Compliance Calendar (12 months)
R 58,000

Delivered in 6-8 weeks - Includes 30-day post-delivery support

Enquire About This Pack

Enterprise

Full Programme

End-to-end compliance transformation - POPIA, GDPR, King IV, ESG, B-BBEE, and business continuity. For organisations that need to demonstrate full accountability to regulators and investors.

  • POPIA + GDPR Full Implementation
  • King IV Governance Programme
  • ESG Reporting (GRI/SASB aligned)
  • B-BBEE Strategy & Roadmap
  • Business Continuity Plan
  • Outsourced IO (12 months)
R 140,000

Delivered in 16-20 weeks - Annual retainer option available

Enquire About This Pack
Client Voices

What Our Clients Report

Compliance done right doesn't just protect you - it opens doors. Here's what our clients experienced.

After implementing Kaymerc X's POPIA compliance programme, we passed our Information Regulator audit without a single finding. Zero findings. That's the standard they set.

BD
B. Dlamini
Information Officer, Financial Services - Johannesburg

Their ESG framework helped us land a R15M contract with a JSE-listed client that required full ESG disclosure. It paid for itself many times over within the first quarter.

CE
C. Erasmus
CEO, Industrial Supplier - Gauteng
Questions Answered

Frequently Asked Questions

Key questions about our compliance, governance, and ESG services.

What are my POPIA obligations as a South African business?
Under POPIA, every organisation that processes personal information of natural persons has eight core obligations: (1) appoint a responsible party and Information Officer; (2) process data lawfully and with a valid legal basis; (3) collect only what is necessary (minimisation); (4) keep data accurate and up to date; (5) store data only as long as necessary; (6) secure data with appropriate technical and organisational measures; (7) notify the Information Regulator and affected persons of breaches; and (8) honour data subject rights (access, correction, deletion). Non-compliance is not a technicality - it is a statutory offence.
What fines can the Information Regulator impose for POPIA non-compliance?
The Information Regulator can impose administrative fines of up to R10 million per contravention. In addition, criminal penalties apply - responsible parties (individuals) can face imprisonment of up to 10 years. Beyond regulatory fines, data subjects can claim civil damages separately. The Regulator has begun enforcement action and is actively investigating complaints lodged against businesses of all sizes.
What is an Information Officer (IO) and does my business need one?
Under POPIA, every responsible party (any organisation that processes personal data) must appoint an Information Officer. For companies, this is automatically the CEO unless someone else is formally designated and registered with the Information Regulator. The IO is responsible for: ensuring POPIA compliance, handling data subject requests, managing data breach notification, and liaising with the Regulator. If you don't have the internal capacity or expertise, our Outsourced IO service (IMP-011) provides a qualified registered IO on retainer.
Does GDPR apply to my South African business?
Yes - if your business offers goods or services to EU residents, or monitors their behaviour (e.g. via website analytics, email marketing, or e-commerce), GDPR applies regardless of where your business is based. GDPR obligations include appointing an EU representative, maintaining Records of Processing Activities, executing Data Processing Agreements with EU data controllers, and notifying supervisory authorities of breaches within 72 hours. Fines reach €20M or 4% of global annual turnover - whichever is higher. We assess GDPR applicability as the first step of every engagement.
What is King IV and does my business need to comply?
King IV is South Africa's corporate governance code (2016). While it's mandatory for JSE-listed companies and state-owned entities, it applies on a "comply or explain" basis to all organisations. In practice, institutional investors, development finance institutions (DFIs), large corporates, and major government procurement processes increasingly require demonstrated King IV compliance. If you are pursuing growth capital, major contracts, or listing, King IV governance is not optional - it is a prerequisite. Our King IV Assessment (IMP-012) identifies your current position and produces a board-ready compliance report with a prioritised improvement roadmap.
What does Lean Six Sigma have to do with compliance and governance?
Lean Six Sigma (LSS) methodology applies directly to compliance and governance through process standardisation and waste elimination. Compliance failures often result from inconsistent, undocumented, or overly complex processes - exactly what LSS DMAIC (Define, Measure, Analyse, Improve, Control) addresses. We apply LSS methodology to compliance programme design, reducing the administrative burden of ongoing compliance while improving audit outcomes. Our practitioners hold Lean Six Sigma Black Belt certification (LSSBB), enabling us to build compliance frameworks that are both rigorous and operationally sustainable.
Do you provide an Outsourced Information Officer service?
Yes. Our Outsourced IO service (IMP-011) provides a qualified, registered Information Officer on a monthly retainer. The outsourced IO handles: registration with the Information Regulator, data subject access and deletion requests, staff query escalations, breach notifications (within 72 hours as required), annual compliance reviews, and regulator correspondence. This is significantly more cost-effective than employing a full-time compliance officer and ensures you always have a credentialled practitioner accountable for your obligations.
How do Impact's services integrate with the rest of Kaymerc X?
Compliance and governance are most powerful when they are built into your business infrastructure, not bolted on. Our integrated model means: Academy delivers the staff training that brings your POPIA and governance frameworks to life; Tech implements the cybersecurity and data infrastructure that makes compliance enforceable and auditable; Capital uses your governance credentials as leverage in funding applications; and Global ensures your compliance posture meets regulatory requirements in every African jurisdiction you operate in. One relationship. All disciplines. No coordination overhead.

Is your business compliance-ready?

Book a no-obligation discovery call. We'll identify the highest-leverage opportunities in your business within the first session.