POPIA (South Africa)
Tier 2 In forceSouth Africa’s comprehensive law, built around eight statutory ‘conditions for lawful processing’ rather than the GDPR’s principles-plus-lawful-bases structure — and one of the few laws in the world that protects juristic persons (companies) as well as people.
Identity
- Citation
- Protection of Personal Information Act 4 of 2013, South Africa
- Jurisdiction
- South Africa
- Type
- comprehensive
Assented 2013; in force 1 Jul 2020; compliance required from 1 Jul 2021
Amended by: POPIA Regulations 2018 (amended); read with PAIA
Structure
What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.
Chapters 1–2 — Purpose, application, exclusions (ss 1–7)
Definitions and carve-outs: purely household processing, de-identified data, certain state functions and journalism under a code of ethics.
- s 1 Personal information defined broadly — expressly including identifiable juristic persons.
- s 6 Exclusions: household, de-identified, national-security and journalistic processing.
Chapter 3 — The eight conditions (ss 8–25)
The heart of the Act: accountability; processing limitation; purpose specification; further-processing limitation; information quality; openness; security safeguards; and data subject participation.
- ss 9–12 Processing limitation — lawful, minimal, with consent or another listed justification.
- ss 19–22 Security safeguards — including the s 22 breach duty: notify the Regulator and subjects as soon as reasonably possible.
- ss 23–25 Access and correction rights.
Chapter 3, Parts B–C — Special and children’s information (ss 26–35)
Default prohibitions on religious, health, biometric, criminal and children’s data, with listed exceptions and Regulator authorisations.
Chapters 5–7 — Regulator, prior authorisation, codes (ss 39–68)
An independent Regulator with a dual POPIA / PAIA mandate.
- ss 57–58 Prior authorisation required for listed processing — unique identifiers, criminal data, credit reporting, some transfers.
Chapter 8 — Marketing, directories, automated decisions (ss 69–71)
Rights the public actually feels.
- s 69 Electronic direct marketing is opt-in: one approach to ask, then consent — stricter than the GDPR’s soft opt-in.
- s 71 Protections against solely automated decisions.
Chapter 9 — Transborder flows (s 72)
A single compact transfer section.
- s 72 Transfers permitted where the recipient is bound by law, contract or binding corporate rules offering similar protection — or with consent or contractual necessity.
Chapters 10–11 — Enforcement and offences (ss 73–115)
Complaints, investigations, enforcement notices, offences and fines.
- ss 100–107 Offences carrying fines to R10m or up to 10 years’ imprisonment.
- s 109 Administrative fines to R10m.
Regulatory enforcement
Interactions and conflicts
Administered alongside PAIA (access to information) by the same Regulator, so subject-access and PAIA requests overlap in practice. Sectoral statutes (FICA, credit, health) continue in parallel, under the constitutional privacy right (s 14). Its juristic-person coverage regulates B2B data — a genuine conflict for GDPR-modelled compliance programmes, which assume only natural persons.
Sources
Never independently verified — seeded from the prototype.