Data Protection Atlas

POPIA (South Africa)

Tier 2 In force

South Africa’s comprehensive law, built around eight statutory ‘conditions for lawful processing’ rather than the GDPR’s principles-plus-lawful-bases structure — and one of the few laws in the world that protects juristic persons (companies) as well as people.

Identity

Citation
Protection of Personal Information Act 4 of 2013, South Africa
Jurisdiction
South Africa
Type
comprehensive

Assented 2013; in force 1 Jul 2020; compliance required from 1 Jul 2021

Amended by: POPIA Regulations 2018 (amended); read with PAIA

← South Africa overview

Structure

What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.

Chapters 1–2 — Purpose, application, exclusions (ss 1–7)

Definitions and carve-outs: purely household processing, de-identified data, certain state functions and journalism under a code of ethics.

  • s 1 Personal information defined broadly — expressly including identifiable juristic persons.
  • s 6 Exclusions: household, de-identified, national-security and journalistic processing.
Chapter 3 — The eight conditions (ss 8–25)

The heart of the Act: accountability; processing limitation; purpose specification; further-processing limitation; information quality; openness; security safeguards; and data subject participation.

  • ss 9–12 Processing limitation — lawful, minimal, with consent or another listed justification.
  • ss 19–22 Security safeguards — including the s 22 breach duty: notify the Regulator and subjects as soon as reasonably possible.
  • ss 23–25 Access and correction rights.
Chapter 3, Parts B–C — Special and children’s information (ss 26–35)

Default prohibitions on religious, health, biometric, criminal and children’s data, with listed exceptions and Regulator authorisations.

Chapters 5–7 — Regulator, prior authorisation, codes (ss 39–68)

An independent Regulator with a dual POPIA / PAIA mandate.

  • ss 57–58 Prior authorisation required for listed processing — unique identifiers, criminal data, credit reporting, some transfers.
Chapter 8 — Marketing, directories, automated decisions (ss 69–71)

Rights the public actually feels.

  • s 69 Electronic direct marketing is opt-in: one approach to ask, then consent — stricter than the GDPR’s soft opt-in.
  • s 71 Protections against solely automated decisions.
Chapter 9 — Transborder flows (s 72)

A single compact transfer section.

  • s 72 Transfers permitted where the recipient is bound by law, contract or binding corporate rules offering similar protection — or with consent or contractual necessity.
Chapters 10–11 — Enforcement and offences (ss 73–115)

Complaints, investigations, enforcement notices, offences and fines.

  • ss 100–107 Offences carrying fines to R10m or up to 10 years’ imprisonment.
  • s 109 Administrative fines to R10m.

Regulatory enforcement

Interactions and conflicts

Administered alongside PAIA (access to information) by the same Regulator, so subject-access and PAIA requests overlap in practice. Sectoral statutes (FICA, credit, health) continue in parallel, under the constitutional privacy right (s 14). Its juristic-person coverage regulates B2B data — a genuine conflict for GDPR-modelled compliance programmes, which assume only natural persons.

Sources

Never independently verified — seeded from the prototype.