Skip to content
Demonstration siteSample data only. Payments are disabled and no order is real.Demo logins

Data Protection

Preparing for a POTRAZ inspection

Inspections begin 1 September 2026. Here is what an inspector expects to see and how to prepare.

6 min read · Last updated 16 August 2026

From 1 September 2026, POTRAZ commences mandatory risk-based inspections of organisations processing personal information. Organisations that are not adequately prepared may face regulatory enforcement, financial penalties, reputational damage and operational disruption.

The separate Data Controller Licence deadline passed on 12 March 2025. If your organisation has not licensed, that is the first thing to address.

What inspectors look for

  • A valid Data Controller Licence.
  • An appointed Data Protection Officer with defined responsibilities.
  • Records of Processing Activities (ROPA) that are current and complete.
  • Data protection policies, procedures and published privacy notices.
  • Evidence of Data Protection Impact Assessments for high-risk processing.
  • A documented data breach response plan, and records of any incidents.
  • Evidence of staff privacy awareness training.
  • Contracts with processors containing the required data protection clauses.

How to prepare

  1. 1Commission a readiness review to establish where you actually stand.
  2. 2Close the licensing gap if you are not yet licensed.
  3. 3Appoint a DPO, internally or through an outsourced service.
  4. 4Build or refresh your ROPA and supporting documentation.
  5. 5Run training so staff can answer questions about their own obligations.
  6. 6Rehearse your breach response so the plan is more than a document.

Was this article helpful?

If it didn't answer your question, open a ticket and we'll help directly — and improve the article.