Enternovate Open · Gavaza · v0.1.0
POPIA compliance toolkit for South African organisations. Eight conditions, a scored assessment, and the documents a responsible party needs.
POPIA is law, but the paperwork it demands is rarely the hard part. Gavaza turns the eight conditions of the Protection of Personal Information Act 4 of 2013 into a scored, repeatable assessment and produces the documents a responsible party must keep ready: the PAIA manual, privacy policy, records of processing, and a breach register with the section 22 notification checklist. Local-first, no account, no cloud. Gavaza is a tool, not legal advice — documents it generates are starting points for a qualified professional to review.
$ pip install git+https://github.com/enternovate/gavaza.git$ gavaza init --name "Acme (Pty) Ltd" --email privacy@acme.co.za$ gavaza conditions$ gavaza assess --interactive$ gavaza report --format md --out report.md$ gavaza generate --docs all --out docs/$ gavaza breach add --description "Phishing email" --affected 12$ gavaza requests new --name "A. Person" --email a@example.com --right access$ gavaza sections$ gavaza gdpr-map
gavaza init [--name N] [--email E]Create the company configurationgavaza assess [--interactive] [--answers FILE]Run the questionnairegavaza report [--format md|html|json|csv]Render the assessment reportgavaza generate [--docs paia privacy register operator dsr-form consent retention pia]Generate the document suitegavaza breach add|list|timelineManage the breach registergavaza evidence add|list|removeManage evidence filesgavaza requests new|list|status|overdueManage data subject requestsgavaza conditionsList the eight conditionsgavaza sections [--slug S]List the additional POPIA sectionsgavaza gdpr-map [--format md|json]Print the POPIA-GDPR mappingEvery variable is optional. The tool runs on defaults with no configuration.
GAVAZA_HOMENoData directory: config, results, docs, evidence, requests (default: ~/.gavaza)Xavani Agent drives Gavaza through the constellation MCP bundle (constellation-mcp), which exposes gavaza_* tools, and through the gavaza-compliance skill. Ask Xavani to “assess our POPIA readiness” and the CLI runs locally; nothing leaves the machine. Assessment results and evidence can be exported to the Nyarhi knowledge graph for long-term audit trails.
Xavani Agent docsConfig, results, documents and evidence live in ~/.gavaza on your machine. No accounts, no cloud.
The evidence store attaches hashed files to checklist items so you can demonstrate compliance without exposing the originals.
Generated documents are starting points. A qualified professional should review them before use.
The breach register supports section 22 notification preparation. POPIA requires notification as soon as reasonably possible, subject to the Act. Review generated guidance with your legal adviser.