The Information Regulator (IR) has discretion in when to assess organisations’ data processing practices under both POPIA and PAIA. They follow prescribed procedures and inform applicants about the scope and reasons for the assessment. For POPIA assessments, factors considered include information officer presence, data type, training, security, retention policies, and cross-border data flows. A guidance note on direct marketing is coming soon. Unlike POPIA, PAIA assessments are not mandatory, but the IR encourages transparency and considers factors like the information’s purpose and potential impact of non-compliance. Resources are available for smaller organisations to ensure compliance. The IR avoids affordability-based penalties, but considers the organisation’s size and data volume.