Data Protection Matters
← All privacy laws

South Africa

POPIA

Protection of Personal Information Act 4 of 2013

Keywords

POPIASouth AfricaProtection of Personal Information ActInformation Regulatorresponsible partyoperatordata subjectinformation officerspecial personal informationsection 22security compromisedirect marketingcross-border transferprior authorisation
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's comprehensive data protection law. It gives effect to the constitutional right to privacy and sets minimum conditions for the lawful processing of personal information. It was signed in 2013, and its main provisions came into force on 1 July 2020, followed by a one-year grace period that ended on 30 June 2021.

Who it applies to

POPIA applies to the processing of personal information by a "responsible party" (the party that decides why and how data is processed) domiciled in South Africa, or using automated or non-automated means in South Africa. An "operator" processes data on the responsible party's behalf. Unusually, the Act protects the information of juristic persons (companies) as well as natural persons, and it applies to public and private bodies alike.

The eight conditions for lawful processing

POPIA is organized around eight conditions: accountability; processing limitation; purpose specification; further processing limitation; information quality; openness; security safeguards; and data subject participation. Processing must be lawful and reasonable, adequate, relevant and not excessive, and based on one of the justification grounds, such as consent, a contract, a legal obligation, or a legitimate interest.

Special personal information and children

The Act sets stricter rules for special personal information, such as religious or philosophical beliefs, race or ethnic origin, health, sex life, biometric information, and criminal behaviour. Processing of this data is generally prohibited unless an authorization or exception applies. Children's information may be processed only in limited circumstances, usually with consent from a competent person.

Individual rights

Data subjects can ask a responsible party to confirm whether it holds their information and to access it. They can request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained. They can object to processing, object to direct marketing, and complain to the Information Regulator.

Key obligations

Each responsible party must have an information officer, who is registered with the Information Regulator and who is responsible for compliance. Responsible parties must secure the information they hold, put written contracts in place with operators, and notify data subjects when they collect their data. Direct marketing by electronic communication generally requires prior consent. Some processing, such as transfers of special personal information to countries without adequate protection, needs prior authorisation from the Regulator.

Cross-border transfers

Personal information may be transferred to a third party in another country only if the recipient is subject to rules that provide adequate protection, such as binding corporate rules or an agreement, or if another listed ground applies, such as the data subject's consent or the transfer being necessary to perform a contract.

Data breaches

Under section 22, if there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects. Notice must be given as soon as reasonably possible after the discovery, subject to the needs of law enforcement or measures to restore the integrity of the system.

Enforcement and penalties

The Information Regulator, an independent body, enforces POPIA. It can investigate complaints, issue enforcement notices, and impose administrative fines of up to R10 million. Certain offences can lead to imprisonment of up to 10 years. Data subjects may also bring civil claims for damages.

The official text

The authoritative version is the Act as published in Government Gazette No. 37067 of 26 November 2013, available in English on the South African Government website. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, official (Government Gazette No. 37067)). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →