Regulations › Rest of world

POPIA

Protection of Personal Information Act (South Africa)

In force privacy
WhenIn effect since 1 July 2021
Who enforces itInformation Regulator
Who it applies toResponsible parties processing personal information in South Africa.

South Africa's comprehensive privacy law, based on eight conditions for lawful processing.

The law in brief

South Africa's Protection of Personal Information Act (POPIA) sets eight conditions for the lawful processing of personal information. It has applied in full since 1 July 2021 and is enforced by the Information Regulator, which has become more active, including with fines and enforcement notices.

It protects the personal information of both natural persons and existing juristic persons such as companies, which sets it apart from most privacy laws.

Who it applies to

  • Responsible parties processing personal information entered into a record, where the responsible party is domiciled in South Africa, or is not but uses means in South Africa to process it.
  • Operators processing personal information for a responsible party under contract.
  • Personal information relates to identifiable living natural persons and, where applicable, identifiable existing juristic persons.

What it requires

Eight conditions for lawful processing

Meet accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.

An information officer

The head of a private body is its information officer by default, and must be registered with the Information Regulator before taking up duties; deputies may be designated.

Security compromises

Notify the Information Regulator and the data subject as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorized person.

Direct marketing consent

Direct marketing by electronic communication requires the data subject's consent, unless they are an existing customer and marketing concerns similar products and services with an opt-out each time.

Cross-border transfers

Transfer personal information outside South Africa only where the recipient is subject to adequate protection, the data subject consents, or another listed ground applies.

People's rights

Data subjects can be notified of collection and of security compromises, access their information, request correction or deletion, object to processing, refuse direct marketing by electronic communication unless they consented, not be subject to certain automated decisions, and complain to the Information Regulator.

Enforcement and penalties

Administrative fines of up to R10 million, and criminal penalties including fines and imprisonment for certain offences. Data subjects can bring civil actions for damages.

What to do first

  1. Register your information officer with the Information Regulator and appoint deputies as needed.
  2. Map processing against the eight conditions, especially purpose specification and minimality.
  3. Fix direct marketing: electronic marketing to non-customers needs opt-in consent.
  4. Report security compromises to the Regulator through its portal and notify data subjects.
  5. Check prior authorization requirements and cross-border transfers.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources