South Africa Data Protection Law: POPIA and Your Privacy Rights (2026)

The Protection of Personal Information Act 4 of 2013, known as POPIA, is the law that governs how businesses, government bodies and other organisations in South Africa collect, use, store and share personal information. This section explains what POPIA covers, who it protects, and the Information Regulator that enforces it.
Information last verified on 23 July 2026. This page provides general legal information about South African data protection law and does not constitute legal advice in an individual case.
What POPIA Covers
POPIA regulates the "processing" of personal information, a term that covers collecting it, using it, storing it, sharing it and destroying it. It applies to a "responsible party" (the person or organisation that decides why and how personal information is processed) domiciled in South Africa, or using automated or non automated means located in South Africa, subject to the exclusions in section 6.
At the centre of POPIA are eight conditions for lawful processing set out in section 4(1): accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation. The full detail of each condition, plus your rights as a data subject and the penalties for non compliance, is covered on the POPIA explained page.
Who POPIA Protects
POPIA's core protection is for natural persons, meaning living individuals. It also extends to identifiable existing juristic persons, such as companies and close corporations, "where it is applicable" (section 1), so a company's information is not protected on exactly the same footing as an individual's in every case.
POPIA does not apply at all to the processing of personal information in the course of a purely personal or household activity (section 6(1)(a)), such as keeping your own address book, family photos or personal correspondence.
The Information Regulator
The Information Regulator is the independent body created to enforce both POPIA and the Promotion of Access to Information Act. It accepts complaints from data subjects, can attempt mediation, can issue an enforcement notice, and can impose an administrative fine of up to R10 million for a serious contravention. How to bring a complaint to the Information Regulator, including the acceptance rules and the timelines the Regulator works to, is covered on the Information Regulator complaint page.
The Constitutional Frame: Section 14
Section 14 of the Constitution of the Republic of South Africa, 1996, gives everyone a general right to privacy. POPIA gives that constitutional right practical effect specifically for personal information: it turns a broad constitutional guarantee into concrete rules about consent, access, correction and security that a responsible party must follow.
POPIA and Recording a Conversation
Recording a private conversation in South Africa is mainly a question for the Regulation of Interception of Communications and Provision of Communication related Information Act 70 of 2002 (RICA), which allows a party to a conversation to record it without telling the other party in most circumstances. POPIA is a separate law: once a recording exists, storing it, using it or sharing it as personal information can separately trigger POPIA's conditions. See South Africa's recording laws for the RICA side of this, and the South Africa data privacy overview for a wider look at data protection in South Africa.
What Is in This Section
- POPIA Explained: the eight conditions, your rights as a data subject, direct marketing rules and the penalties for non compliance.
- How to Complain to the Information Regulator: Form 5, the online portal, and what happens after you lodge a complaint.
For the wider South Africa hub, including labour, traffic and criminal records law, see South Africa Laws.
This page is general legal information about South African law and is not legal advice. For advice on a specific situation, consult an attorney, or contact Legal Aid South Africa on 0800 110 110 if you cannot afford one.
Frequently Asked Questions
What is POPIA?
POPIA is the Protection of Personal Information Act 4 of 2013, South Africa's main data protection law. The bulk of it commenced on 1 July 2020, with a one year compliance grace period under section 114(1) that ended on 1 July 2021.
What does POPIA's 'where it is applicable' qualifier mean for a company's information?
POPIA's core protection is for natural persons. Its definition of personal information also extends to identifiable existing juristic persons, such as companies and close corporations, but only where it is applicable, so a company's information is not protected on exactly the same footing as an individual's in every case.
Does complying with the GDPR mean a business already complies with POPIA?
No. POPIA and the European Union's General Data Protection Regulation share a broadly similar structure of principles for lawful processing, but they are separate laws with separate regulators and separate compliance obligations. One difference worth noting is that POPIA extends to identifiable existing juristic persons where it is applicable, while the GDPR protects only natural persons.
What is the difference between POPIA and RICA?
RICA governs the interception and recording of communications, including the rule that a party to a conversation may generally record it without the other party's knowledge. POPIA governs the wider processing of personal information, including what happens to a recording once it exists, such as storing or sharing it.
Who enforces POPIA in South Africa?
The Information Regulator enforces POPIA. It accepts complaints from data subjects, can attempt mediation, can issue an enforcement notice, and can impose an administrative fine of up to R10 million.
Sources and References
- Protection of Personal Information Act 4 of 2013, section 4(1) (the eight conditions for lawful processing)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, sections 1 and 6(1)(a) (definition of personal information, including juristic persons where applicable, and the purely personal or household exclusion)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 109 (administrative fines up to R10 million)(inforegulator.org.za).gov
- Information Regulator, Protection of Personal Information Act (POPIA) FAQ page(inforegulator.org.za).gov
- Constitution of the Republic of South Africa, 1996, section 14 (right to privacy)(justice.gov.za).gov
- Regulation of Interception of Communications and Provision of Communication related Information Act 70 of 2002, sections 2, 4, 5 and 6 (recording of communications)(justice.gov.za).gov