Home › Law library › POPIA
ZA
POPIA
Protection of Personal Information Act 4 of 2013
Sourced. Last verified 9 October 2026
South Africa Privacy
- Status
- In force (fully effective 1 July 2021); amended POPIA Regulations effective 17 April 2025.
- Who it applies to
- Personal information of living individuals AND existing companies/juristic persons. Covers parties domiciled in South Africa, or not domiciled there but using processing means in South Africa (other than mere transit).
- Size thresholds
- No size threshold. Prior authorisation from the Regulator is needed for certain processing (e.g., credit reporting, some unique identifiers, special/children's data sent to non-adequate countries).
- Regulator
- Information Regulator (South Africa)
- Breach or incident reporting
- Notify the Information Regulator and affected people as soon as reasonably possible after discovering a security compromise (s22). Since 1 April 2025, reports must go through the Regulator's e-Portal.
- Deadline to answer personal data requests
- Access requests are handled under PAIA: private bodies must decide within 30 days of receipt (s56), extendable once by up to 30 days (s57).
- Data protection officer
- Every organisation has an Information Officer (by default the head) who must be registered with the Regulator before taking up duties; deputies may be designated.
- Local representative
- Being verified
- Sending data abroad
- Allowed if the recipient is bound by substantially similar protection (law, BCRs or agreement), the person consents, the transfer is needed for a contract, or it benefits the person.
- Cookies and consent
- Unsolicited electronic direct marketing needs opt-in consent, except to existing customers for similar products with an opt-out. Ask for consent only once. Opt-out is not valid consent (2025 regs). Calls count as electronic.
- Maximum penalty
- Administrative fine up to ZAR 10 million; up to 10 years' imprisonment for certain offences; civil damages claims also possible.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Register your Information Officer (and any deputies) on the Regulator's portal.
- Report security compromises via the Information Regulator e-Portal as soon as reasonably possible.
- Get opt-in consent before electronic direct marketing to non-customers; remember opt-out is not consent.
- Keep an updated PAIA manual using the new 2025 prescribed forms.
- Record or log telephone requests for deletion or objection so they can be retrieved.
- Get prior Regulator authorisation before high-risk processing such as credit reporting.
- Decide access requests within 30 days.
Recent changes
E-Portal breach reporting mandatory from 1 April 2025; amended POPIA Regulations effective 17 April 2025 (new complaint forms, opt-out not valid consent, telephone request handling). Draft health/sex-life processing regulations published Sept 2025.
Sources
- Primary source: https://inforegulator.org.za/
- Second source: https://www.cliffedekkerhofmeyr.com/news/publications/2025/Sectors/Technology-Communications/Technology-and-Communications-Alert-21-May-Important-POPIA-amendments-to-note
- Regulator: Information Regulator (South Africa)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].