Regulation Finder/South Africa

South Africa

Comprehensive

Protection of Personal Information Act (POPIA)

Authority: Information Regulator | Enforcement: Active | Enacted: July 2021

Overview

South Africa's POPIA, fully enforceable since July 2021, provides comprehensive data protection aligned with international standards. The Information Regulator actively issues enforcement notices and guidance.

14-Topic Coverage

Data Protection Authority

Fully Addressed

Information Regulator oversees POPIA compliance with investigation and enforcement powers.

Data Subject Rights

Fully Addressed

Rights to access, correction, deletion, objection, and not to be subject to automated decisions.

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection, consent, or necessary for contract performance.

Breach Notification

Fully Addressed

Must notify Information Regulator and data subjects as soon as reasonably possible.

DPO Requirements

Fully Addressed

Information Officer must be registered with the Regulator.

Children's Data

Fully Addressed

Consent of competent person required for children under 18. Processing of children's data is restricted.

Penalties & Enforcement

Fully Addressed

Fines up to ZAR 10 million and/or imprisonment up to 10 years for certain offences.

Sector-Specific Rules

Fully Addressed

ECTA for electronic communications, NCA for consumer credit, health sector regulations.

AI & Automated Decisions

Partially Addressed

Section 71 provides rights regarding automated decisions. AI governance framework developing.

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept. All responsible parties have the same obligations.

Government Data

Fully Addressed

PAIA provides access to government information. POPIA applies to government processing.