130 Free Compliance Generators: Mexico LFPDPPP + South Africa POPIA
ComplyKit has added its 129th and 130th free compliance generators: the Mexico LFPDPPP Compliance Checklist and the South Africa POPIA Compliance Checker. Both generators are free, require no account, and produce AI-generated compliance assessment reports covering critical obligations under these two major data protection laws.
Mexico LFPDPPP Compliance Checklist (129th generator)
Mexico’s Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), enforced by INAI, applies to all private entities processing personal data in Mexico — regardless of size, revenue, or data volumes. With 130 million people, a booming tech sector, and Mexico as the US’s largest trading partner under USMCA, LFPDPPP compliance is essential for any SaaS company, e-commerce platform, or enterprise with Mexican operations or users. INAI penalties reach MXN 320 million; criminal sanctions for sensitive data misuse carry 3–5 year imprisonment terms.
The Mexico LFPDPPP Compliance Checklist covers 42 key obligations across six categories:
- Aviso de Privacidad & Lawful Bases (Arts. 13–23): Privacy notice at or before collection (full/simplified/short formats per INAI Lineamientos), all Art. 15–16 required elements, lawful basis documented for every processing activity (5 LFPDPPP bases), purpose limitation, datos sensibles explicit written consent (6 categories), children’s data parental consent, secondary purpose notification
- ARCO Rights (Arts. 22–36): Access 20-business-day response with disclosure history, rectification (correction + third-party notification), cancellation (blocking period + deletion), opposition (harm grounds + legitimate grounds to continue), ARCO intake channel accessible and free, INAI complaint pathway published
- Responsible Party Obligations (Arts. 6–12, 37–43): Data minimisation (proporcionalidad), quality obligation, retention limitation with automated deletion, privacy by design and default, encargado contracts (written, instruction-binding, confidentiality, sub-contractor controls, deletion on termination), records of processing activities inventory
- Security & Breach Notification (Arts. 19–20): Technical/administrative/physical safeguards (INAI Recomendaciones de Seguridad), designated privacy function, incident detection/containment procedures, INAI notification (prompt, significant risk threshold), individual notification for patrimonial/moral harm, incident register for INAI inspection, annual security review
- International Transfers (Arts. 36–37): Third-party transfer (cesiones): consent or Art. 37 exception; international transfer equivalent-protection requirement (contractual clauses/BCRs/consent); transfer inventory; financial sector CNBV/Ley Fintech assessment; cloud/SaaS encargado DPAs; US–Mexico USMCA cross-border assessment
- Consent, Governance & INAI (Arts. 7–12, 44–66): Consent architecture (express written for sensitive data; cannot be condition of service for non-essential), consent withdrawal mechanism, privacy programme documentation (mitigating factor in sanctions), INAI complaint and verification procedure readiness, penalty risk management MXN 320M + criminal sanctions
Who it’s for: Mexican companies of all sizes; SaaS and tech companies with Mexican users or customers; e-commerce platforms serving Mexico; US and European multinationals with Mexican operations; HR/employment services processing Mexican employee data; financial services (with additional CNBV/CONDUSEF rules); legal and compliance teams building LFPDPPP programmes; organisations that have received INAI complaints or verification notices.
South Africa POPIA Compliance Checker (130th generator)
South Africa’s Protection of Personal Information Act (POPIA — Act 4 of 2013) has been fully enforceable since July 1, 2021, with the Information Regulator (ICRSA) actively imposing fines — including a landmark ZAR 5 million fine against Dis-Chem Pharmacies in June 2023. South Africa’s 60 million population, growing tech ecosystem (Johannesburg and Cape Town as major tech hubs), and position as the gateway to African markets make POPIA compliance critical. Administrative fines reach ZAR 10 million; criminal penalties up to 10 years imprisonment.
The South Africa POPIA Compliance Checker covers 42 key obligations across six categories:
- Lawfulness & Processing Conditions (POPIA Conditions 1–3): Accountability condition (documented policies and procedures), processing limitation (6 lawful bases; special personal information explicit consent or Sections 27–32 exceptions), purpose specification (defined purposes; retention limitation), special personal information enhanced restrictions (6 categories including health/biometric/criminal), children’s personal information competent-person consent, consent architecture (freely given/specific/informed/unambiguous; withdrawal mechanism)
- Data Subject Participation Rights (Conditions 7–8; Sections 23–25): Access right 30-day response (categories/sources/recipients/purposes/retention/automated decisions), correction or deletion (third-party notification), right to object (compelling grounds or legal proceedings exception), direct marketing opt-in and unsubscribe, rights intake channel, automated decision human review, ICRSA complaint escalation pathway
- Responsible Party Obligations (Conditions 3–6): Privacy notice at or before collection (Section 18 — all required elements), further processing notification for new purposes, information quality steps, openness/transparency (privacy policy published; PAIA manual updated for POPIA), retention schedule with automated deletion, operator contracts Section 22 (written; instruction-binding; security; confidentiality; sub-operator controls; return/destruction), records of processing activities
- Security Safeguards & Breach Notification (Condition 7; Section 22): Technical/organisational security safeguards appropriate to risk, access controls (RBAC; MFA; access reviews), encryption (AES-256 at rest / TLS 1.2+ in transit), breach detection and containment, ICRSA notification (as soon as reasonably possible — 72-hour best practice), data subject notification for rights-affecting breaches, incident register for ICRSA inspection
- Cross-Border Transfers & Third-Party Sharing (Section 72): Adequate protection assessment or binding agreement (POPIA-equivalent obligations), EU transfers (binding agreement — no adequacy for South Africa), US transfers (contractual clauses equivalent), cross-border transfer inventory, cloud/SaaS operator contracts, domestic data sharing agreements, FSCA financial sector cross-border rules
- Information Officer, Governance & ICRSA (Chapter 4; Sections 55–73): Information Officer appointed and ICRSA-registered (mandatory), Deputy IO appointed for operational efficiency, PAIA manual updated with POPIA section (published on website), Privacy Impact Assessment for high-risk processing, staff POPIA training, ZAR 10M fine and 10-year criminal penalty risk management, ICRSA enforcement response procedures
Who it’s for: South African companies of all sizes (POPIA applies regardless of size); multinationals with South African operations or South African data subjects; SaaS companies processing South African personal information; financial services (FSCA Conduct Standard); healthcare and medical aid schemes; any organisation that has received a data subject complaint to ICRSA; compliance teams building POPIA programmes or adapting existing GDPR programmes for South Africa.
Browse all 130 generators
All 130 free compliance generators are at /generate. No account required. Covers GDPR, CCPA, SOC 2, HIPAA Security Rule, Brazil LGPD, Mexico LFPDPPP, South Africa POPIA, ISO 27001/27701, EU AI Act (GPAI + High-Risk), NIS2, DORA, PSD2/PSD3, FCA Consumer Duty, CSRD, CRA, NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5, CMMC 2.0, Digital Markets Act, EU Data Governance Act, EU Data Act, ePrivacy, AI Fairness, SOC 2 Trust Services Criteria, US State Privacy Laws, APRA CPS 230, Singapore PDPA, India DPDP Act, Saudi Arabia PDPL, Australia Privacy Act 2024, Thailand PDPA, Japan APPI 2022, South Korea PIPA 2023, PCI DSS v4.0 SAQ-D, UAE PDPL, Canada PIPEDA / Bill C-27, and more.