Privacy & Data Protection · South Africa
Protection of Personal Information Act
South Africa's principal data protection law, similar in structure to the GDPR. It sets eight conditions for lawful processing of personal information and created the Information Regulator to enforce compliance across public and private bodies.
REGULATORInformation Regulator (South Africa)
REGIONSouth Africa
EFFECTIVE1 July 2020 (full enforcement from 1 July 2021)
Who it applies to
- Any responsible party processing personal information in South Africa
- Public and private bodies of any size
- Organisations outside South Africa processing data using means located in the country
Key requirements
- Registration of an Information Officer with the Regulator
- Eight conditions for lawful processing, including accountability and security safeguards
- Special protection for children's data and special personal information
- Notification of security compromises to the Regulator and data subjects
- Cross-border transfer restrictions absent adequate protection
Maximum penaltyAdministrative fines up to R10 million, or imprisonment for up to 10 years for serious offences
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates POPIA compliance
Continuous monitoring, evidence and reporting for POPIA — alongside every other framework you need to satisfy.