POPIA Explained: The 8 Conditions, Your Rights and Penalties (2026)

POPIA, the Protection of Personal Information Act 4 of 2013, is South Africa's main data protection law. This guide sets out its commencement dates, the eight conditions for lawful processing, your rights as a data subject, the direct marketing rules, and exactly which penalties apply to which contraventions.
Information last verified on 23 July 2026. This page provides general legal information about South African data protection law and does not constitute legal advice in an individual case.
When POPIA Came Into Force
POPIA commenced in two stages that are often confused. Under Proclamation No. R.21 of 2020, the bulk of the Act, including sections 2 to 38 (the eight conditions for lawful processing) and the enforcement and offences provisions in sections 55 to 109, took effect on 1 July 2020. Section 114(1) of POPIA then required every responsible party to bring existing processing into conformity with the Act within one year of that commencement, a grace period that ran out on 1 July 2021. The Information Regulator treats 1 July 2021 as the point its complaints jurisdiction opened: its own published position is that it will not accept a complaint whose cause of action arose before that date. Both dates matter and mean different things: POPIA has been law since 1 July 2020; the Regulator's complaint window opened a year later.
The Eight Conditions for Lawful Processing
Section 4(1) of POPIA sets out eight conditions that a responsible party must meet for processing personal information to be lawful:
- Accountability (section 8): the responsible party must ensure the conditions in this list, and the measures giving effect to them, are complied with at the time the purpose and means of processing are determined and during the processing itself.
- Processing limitation (sections 9 to 12): personal information must be processed lawfully and in a reasonable manner that does not infringe the data subject's privacy, and, subject to limited exceptions, with the data subject's consent, adequately and not excessively for the purpose.
- Purpose specification (sections 13 and 14): personal information must be collected for a specific, explicitly defined and lawful purpose, and generally not retained for longer than needed to achieve that purpose.
- Further processing limitation (section 15): further processing of personal information must be compatible with the purpose for which it was originally collected.
- Information quality (section 16): the responsible party must take reasonable steps to keep personal information complete, accurate, not misleading and updated where necessary.
- Openness (sections 17 and 18): the responsible party must maintain certain documentation and, subject to some exceptions, notify the data subject of what is being collected and why.
- Security safeguards (sections 19 to 22): the responsible party must secure the integrity and confidentiality of personal information through appropriate technical and organisational measures, and notify the Regulator and the data subject of a security compromise.
- Data subject participation (sections 23 to 25): the data subject has rights to access, correct and, in some circumstances, request deletion of their personal information, covered in the next section.
Your Rights as a Data Subject
Section 5 of POPIA gives a data subject a general right to have their personal information processed in accordance with the eight conditions above, flowing through into specific rights in sections 18 and 22 to 25.
Two of those rights matter most in practice. Under section 23, a data subject who has provided adequate proof of identity has the right to confirm, free of charge, whether a responsible party holds their personal information, and to request a record or description of that information, including any third parties who have had access to it. The responsible party must respond within a reasonable time, and may charge a prescribed fee for actually providing the record itself, but the initial confirmation is free.
Under section 24, a data subject can ask a responsible party to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or was obtained unlawfully, or to destroy or delete a record the responsible party is no longer authorised to keep under section 14 (the purpose specification condition).
These access and correction rights work alongside two further obligations built into the eight conditions themselves. The openness condition (sections 17 and 18) generally requires a responsible party to notify a data subject when it collects personal information directly from them, stating what is being collected and why, subject to limited exceptions. The security safeguards condition (sections 19 to 22) requires a responsible party to notify both the Information Regulator and the affected data subject if there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
What POPIA Does Not Cover
POPIA does not apply at all to the processing of personal information in the course of a purely personal or household activity (section 6(1)(a)), such as your own address book, family photographs kept for personal use, or private correspondence. It also does not apply to properly de identified information, and to certain public body processing connected to national security or the prevention, detection and prosecution of crime, subject to the conditions set out in section 6.
Direct Marketing Rules
Section 69 prohibits processing a data subject's personal information for direct marketing by electronic communication, including automatic calling machines, fax machines, SMSs or email, unless the data subject has given consent, or is already a customer of the responsible party.
The existing customer exception in section 69(1)(b) is a soft opt in, and it only applies if the three conditions in section 69(3) are all met: the responsible party obtained the data subject's contact details in the context of selling a product or service, the marketing is for the responsible party's own similar products or services, and the data subject was given a reasonable opportunity to object, free of charge and without unnecessary formality, both when the details were first collected and on every later communication.
Where consent is needed rather than relied on through the existing customer exception, section 69(2)(a) also limits a responsible party to approaching a data subject once to request that consent, if it has not already been given.
POPIA Compared With the GDPR
POPIA is often compared with the European Union's General Data Protection Regulation (GDPR), and the two share a broadly similar structure of principles for lawful processing. One concrete difference is worth flagging: POPIA's definition of personal information extends to an identifiable, existing juristic person, such as a company or close corporation, "where it is applicable" (section 1), while the GDPR protects only natural persons. Beyond that specific point, a business operating under both regimes should treat POPIA and the GDPR as separate laws with separate regulators and separate compliance obligations, not as interchangeable versions of the same rule.
Penalties for Non Compliance
POPIA backs its conditions with three separate consequences, and they are not interchangeable.
An administrative fine, imposed by the Information Regulator through an infringement notice, can reach up to R10 million (section 109). The Regulator delivers the infringement notice to the responsible party and, in that notice, sets out the amount of the fine it proposes, which the Act caps at R10 million but does not fix at any particular figure below that ceiling.
Criminal penalties on conviction are section specific under section 107, and the maximum is not the same for every offence. Up to 10 years' imprisonment, a fine, or both, applies only to a contravention of section 100 (obstructing the Regulator), section 103(1) (failing to comply with an enforcement or information notice), section 104(2) (offences by witnesses), or sections 105(1) and 106(1), (3) or (4) (unlawfully obtaining, disclosing or dealing in another person's account number). Every other offence under the Act, including a breach of the Regulator's own confidentiality obligations under section 101 and obstructing execution of a warrant under section 102, carries a maximum of 12 months' imprisonment, a fine, or both (section 107(b)).
A data subject can also bring a civil claim for damages in a court with jurisdiction under section 99, whether or not the responsible party acted intentionally or negligently. The Information Regulator may institute that action on the data subject's behalf, but it is the court, not the Regulator, that decides whether to award damages and how much.
Related Reading
For an overview of POPIA in the context of the wider section, see South Africa data protection law. To bring a complaint to the Information Regulator, including Form 5, the online portal and what happens after you lodge a complaint, see how to complain to the Information Regulator. For how POPIA interacts with recording a conversation, see South Africa's recording laws, and for a wider comparative look at data protection in South Africa, see the South Africa data privacy overview. The South Africa Laws hub links the wider site.
This guide is general legal information about South African law and is not legal advice. For advice on your own situation, consult an attorney, or contact Legal Aid South Africa (0800 110 110) if you cannot afford one.
Frequently Asked Questions
When did POPIA come into force?
The bulk of POPIA, including the eight conditions for lawful processing, commenced on 1 July 2020. Section 114(1) then gave responsible parties a one year grace period to bring existing processing into line, which ended on 1 July 2021, the date the Information Regulator treats as the start of its complaints jurisdiction.
What are the eight conditions for lawful processing under POPIA?
Section 4(1) lists accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
Can I ask a company what personal information it holds about me?
Yes. Under section 23 of POPIA, once you provide adequate proof of identity, you can confirm free of charge whether a responsible party holds your personal information and request a record of it, though a prescribed fee may apply to providing the record itself.
Can a business send me marketing messages under POPIA?
Only with your consent, unless you are already its customer for a similar product or service and it gave you a clear, free opportunity to opt out when it first collected your details, and on every later message, under section 69.
What happens if a business does not comply with POPIA?
The Information Regulator can impose an administrative fine of up to R10 million under section 109. Criminal penalties on conviction range up to 12 months' imprisonment for most offences and up to 10 years for the most serious, such as obstructing the Regulator or unlawfully dealing in someone's account number, under section 107.
Can I sue for damages under POPIA?
Yes. Section 99 allows a data subject, or the Information Regulator acting on their behalf, to bring a civil claim for damages in court. The Regulator does not award the damages itself; the court decides whether to award them and how much.
Sources and References
- Protection of Personal Information Act 4 of 2013, section 4(1) (the eight conditions for lawful processing)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 114(1) (one year compliance period after commencement)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 1 (definition of personal information, including juristic persons where applicable) and section 6(1)(a) (purely personal or household exclusion)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, sections 5, 23 and 24 (data subject rights, access free of charge, and correction or deletion)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 69 (direct marketing by electronic communication)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 109 (administrative fines up to R10 million)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 107 (criminal penalties on conviction, tiered by section)(inforegulator.org.za).gov
- Protection of Personal Information Act 4 of 2013, section 99 (civil action for damages)(inforegulator.org.za).gov
- Information Regulator, Protection of Personal Information Act (POPIA) FAQ page (commencement and the 1 July 2021 cut off for complaints)(inforegulator.org.za).gov