Data Protection Atlas

South Africa

Tier 2 Comprehensive law Africa

Principal framework: POPIA (in force 2021) (2013). Regulator: Information Regulator. POPIA fully applied from 1 July 2021; the Regulator enforces both POPIA and PAIA and has issued enforcement notices against major public and private bodies. Electronic direct marketing is opt-in (s 69).

At a glance

Principal law
Protection of Personal Information Act, 2013 (Act 4 of 2013) — POPIA
Regulator
The Information Regulator (South Africa)
Breach notification
Notify the Information Regulator and affected subjects as soon as reasonably possible
Maximum penalty
Fines to R10m or imprisonment to 10 years for offences
DPO required
Every body designates an Information Officer, registered with the Regulator
Digital consent age
Under 18 — competent-person consent
Extraterritorial reach
Processing in South Africa or using means located there

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
ZA

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

Sources

Never independently verified — seeded from the prototype.