Skip to content
GlanceDeskJurisdiction

Home › Law library › POPIA

ZA

POPIA

Protection of Personal Information Act 4 of 2013

Sourced. Last verified 9 October 2026

South Africa Privacy

Status
In force (fully effective 1 July 2021); amended POPIA Regulations effective 17 April 2025.
Who it applies to
Personal information of living individuals AND existing companies/juristic persons. Covers parties domiciled in South Africa, or not domiciled there but using processing means in South Africa (other than mere transit).
Size thresholds
No size threshold. Prior authorisation from the Regulator is needed for certain processing (e.g., credit reporting, some unique identifiers, special/children's data sent to non-adequate countries).
Regulator
Information Regulator (South Africa)
Breach or incident reporting
Notify the Information Regulator and affected people as soon as reasonably possible after discovering a security compromise (s22). Since 1 April 2025, reports must go through the Regulator's e-Portal.
Deadline to answer personal data requests
Access requests are handled under PAIA: private bodies must decide within 30 days of receipt (s56), extendable once by up to 30 days (s57).
Data protection officer
Every organisation has an Information Officer (by default the head) who must be registered with the Regulator before taking up duties; deputies may be designated.
Local representative
Being verified
Sending data abroad
Allowed if the recipient is bound by substantially similar protection (law, BCRs or agreement), the person consents, the transfer is needed for a contract, or it benefits the person.
Cookies and consent
Unsolicited electronic direct marketing needs opt-in consent, except to existing customers for similar products with an opt-out. Ask for consent only once. Opt-out is not valid consent (2025 regs). Calls count as electronic.
Maximum penalty
Administrative fine up to ZAR 10 million; up to 10 years' imprisonment for certain offences; civil damages claims also possible.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

E-Portal breach reporting mandatory from 1 April 2025; amended POPIA Regulations effective 17 April 2025 (new complaint forms, opt-out not valid consent, telephone request handling). Draft health/sex-life processing regulations published Sept 2025.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].