South Africa
South Africa Data Privacy Laws: The POPIA Guide (2026)

This guide compares South Africa's Protection of Personal Information Act 4 of 2013 (POPIA) to international data protection frameworks readers may already know, such as the GDPR, and sets out POPIA's own rules on commencement, lawful processing, penalties, and enforcement. For the practical step by step process of dealing with the Information Regulator or handling a recording that contains someone else's personal information, see our companion guides linked throughout.
Quick Answer: What POPIA Is and When It Applies
POPIA is South Africa's general data protection statute. It applies to any responsible party, public or private, that processes personal information within South Africa, or using automated or non automated means located in South Africa. The Information Regulator is the independent body that enforces it. Administrative fines can reach R10 million, and the most serious criminal offences carry up to 10 years imprisonment.

When POPIA Actually Took Effect
POPIA's commencement is often stated loosely, and the two real dates mean different things. Proclamation R.21 of 2020, published in Government Gazette No. 43461, determined 1 July 2020 as the date on which the bulk of POPIA commenced, including sections 2 to 38 (the conditions for lawful processing) and the enforcement and offences chapter, sections 55 to 109.
Section 114(1) of the Act itself then requires that "all processing of personal information must within one year after the commencement of this section be made to conform to this Act." That one year grace period ran from 1 July 2020 to 1 July 2021. The Information Regulator's own Rules of Procedure and its published guidance both confirm that the Regulator will not accept a complaint in which the cause of action arose before 1 July 2021. Both dates are real: POPIA came into force 1 July 2020, and the Regulator's complaint jurisdiction, tied to the compliance grace period, begins 1 July 2021.

The Eight Conditions for Lawful Processing
Section 4(1) of POPIA sets out eight conditions every responsible party must satisfy: accountability (section 8); processing limitation (sections 9 to 12); purpose specification (sections 13 and 14); further processing limitation (section 15); information quality (section 16); openness (sections 17 and 18); security safeguards (sections 19 to 22); and data subject participation (sections 23 to 25). Our companion guide, POPIA Explained, works through each condition and the data subject rights that flow from them in detail.

Who POPIA Protects: Natural and Juristic Persons
One feature that regularly surprises readers coming from a GDPR background is that POPIA's definition of personal information covers information "relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person." That qualifier, "where it is applicable," means a company or close corporation can be a data subject under POPIA, but the protection is conditional rather than an automatic mirror of the protection given to an individual. Section 6(1)(a) separately excludes purely personal or household processing from POPIA altogether, which is the same exclusion relevant to a personal recording covered in our recording laws guide.
Direct Marketing (Section 69)
Section 69(1) prohibits processing personal information for direct marketing by electronic communication, including automated calls, fax, SMS, or email, unless the data subject has consented, or is an existing customer of the responsible party. For an existing customer, section 69(3) requires that the contact details were obtained in the context of a sale, that marketing is limited to the responsible party's own similar products or services, and that the data subject was given a free and simple opportunity to object both when the information was collected and on every later communication. A responsible party may approach a data subject only once to ask for marketing consent under section 69(2)(a).
Penalties: Administrative Fines and Criminal Offences
Section 109 lets the Information Regulator impose an administrative fine, through an infringement notice, of up to R10 million.
Section 107 is more specific than it is often described. A fine or imprisonment of up to 10 years applies only to a contravention of sections 100, 103(1), 104(2), 105(1), or 106(1), (3) or (4), which cover obstructing the Regulator, failing to comply with an enforcement or information notice, offences by witnesses, and unlawful acts involving another person's account number. Every other offence under the Act, including sections 59, 101, 102, 103(2) and 104(1), carries a fine or up to 12 months imprisonment. A statement that "POPIA carries up to 10 years for any violation" overstates the law; the 10 year maximum is tied to that specific list of sections.
Civil Damages Claims (Section 99)
Section 99(1) allows a data subject, or the Information Regulator at the data subject's request, to institute a civil action for damages in a court having jurisdiction against a responsible party, whether or not there was intent or negligence. It is the court, under section 99(3), that may award an amount it considers just and equitable; the Regulator's own administrative powers under sections 95 and 109 are separate from this court based damages route. Defences available to a responsible party under section 99(2) include vis major, the plaintiff's own consent or fault, and that compliance was not reasonably practicable.
The Information Regulator: Real Enforcement Actions
The Information Regulator publishes its enforcement notices, and only a handful of matters appear on that public record. Confirmed enforcement notices include the National Police Commissioner and the South African Police Service (24 May 2023), the Department of Justice and Constitutional Development (10 May 2023), Dis-Chem Pharmacies Limited (5 February 2024), FT Rams Consulting (21 February 2024), the Department of Basic Education (20 November 2024), and WhatsApp (16 April 2025, for applying weaker privacy terms to South African users than European users). Readers dealing with a suspected POPIA violation of their own should see How to Complain to the Information Regulator, which covers Form 5, the online portal, and the Regulator's own timelines for acknowledging and processing a complaint.
POPIA vs. GDPR: Key Differences
Organisations dealing with both frameworks should note the practical differences. POPIA extends, conditionally, to juristic persons; the GDPR protects only natural persons. The GDPR grants a right to data portability that POPIA does not include. The GDPR requires supervisory authority notification of a breach within 72 hours; POPIA's section 22 requires notification "as soon as reasonably possible," with no fixed statutory deadline. POPIA's maximum administrative fine, R10 million, is far below the GDPR's maximum of the greater of 20 million euro or 4 percent of global annual turnover, but POPIA is the one with criminal imprisonment as a sanction, of up to 10 years for the specific offences described above. Neither statute maintains identical adequacy machinery: the EU keeps a formal adequacy list for cross border transfers, while POPIA's section 72 leaves each responsible party to assess adequacy for itself, subject to the same juristic person complication noted above when using standard contractual clauses drafted for GDPR compliance.
Cross Border Transfers (Section 72)
Section 72 restricts sending personal information outside South Africa unless the recipient country provides adequate protection through law, binding corporate rules, or a binding agreement, or one of section 72's other bases applies: the data subject's informed consent, necessity for a contract, or a transfer that benefits the data subject where consent cannot reasonably be obtained. POPIA keeps no official adequacy list of countries, unlike the EU's GDPR framework, so the burden of assessing and documenting adequacy sits with the organisation making the transfer.
For other South African legal topics, from labour law and traffic fines to criminal record expungement, see our South Africa Laws hub.
This guide is general legal information, not legal advice. For advice on your own situation, consult an attorney, or contact Legal Aid South Africa (0800 110 110) if you cannot afford one.
Frequently Asked Questions
Why do people give two different dates for when POPIA took effect?
POPIA commenced on 1 July 2020 under Proclamation R.21 of 2020, bringing the bulk of the Act, including all eight conditions, into force on that date. Section 114(1) then gave responsible parties a one year grace period to come into conformity. The Information Regulator treats claims arising before 1 July 2021 as outside its complaint jurisdiction, which is why that later date is often (imprecisely) described as when POPIA took effect.
How does POPIA compare to the EU's GDPR?
Both regulate the processing of personal information and set conditions for lawful processing, but POPIA extends its protection to juristic persons such as companies where applicable, which the GDPR does not, has no data portability right, has no fixed statutory breach notification deadline (the GDPR sets 72 hours), and uniquely allows criminal imprisonment of up to 10 years for the most serious offences. POPIA's maximum administrative fine of R10 million is far lower than the GDPR's maximum of the greater of 20 million euro or 4 percent of global turnover.
Does POPIA apply to a foreign company with no office in South Africa?
POPIA applies to processing carried out in South Africa or through automated or non automated means located in South Africa, regardless of where the responsible party is based. A foreign business that processes the personal information of people in South Africa using means situated there can fall within POPIA's scope.
Are companies and other juristic persons protected under POPIA the same way individuals are?
Not identically. POPIA's definition of personal information covers an identifiable, living natural person and, where it is applicable, an identifiable existing juristic person. That qualifier means juristic person protection is real but conditional, not a blanket mirror of the protection given to a natural person.
What happened in the WhatsApp case with South Africa's Information Regulator?
The Information Regulator issued a section 95 enforcement notice against WhatsApp, made public on 16 April 2025, after finding that WhatsApp applied different, weaker privacy terms and policies to South African users than it applied to users in Europe, in breach of several POPIA conditions including accountability and purpose specification.
Who decides a POPIA damages claim, the court or the Information Regulator?
The court. Section 99 lets a data subject, or the Information Regulator acting at the data subject's request, institute a civil action for damages in a court with jurisdiction, and it is the court that decides whether to award an amount it considers just and equitable. Section 99(2) gives the responsible party defences, including vis major, the data subject's own consent or fault, and that compliance was not reasonably practicable.
Does every POPIA offence carry up to 10 years imprisonment?
No. Section 107 splits criminal penalties by offence: a fine or up to 10 years imprisonment applies only to a specific list of offences, including obstructing the Regulator and unlawful acts involving another person's account number, while other offences, such as breaching the Regulator's confidentiality, carry a fine or up to 12 months imprisonment. Separately, the Information Regulator can impose an administrative fine of up to R10 million under section 109.
Is there an official list of countries POPIA treats as having adequate data protection?
No. Section 72 requires the recipient in a foreign country to be subject to a law, binding corporate rules, or a binding agreement that provides substantially similar protection to POPIA's conditions, but POPIA does not maintain a formal adequacy list the way the EU does for the GDPR. Each responsible party has to assess and document adequacy for itself, or rely on one of section 72's other bases, such as the data subject's consent.
Updates
Independently fact-checked against the cited primary sources
Information Regulator publishes a section 95 enforcement notice against WhatsApp, finding it applied weaker privacy terms to South African users than to European users.
Information Regulator issues an enforcement notice against the Department of Basic Education.
Information Regulator issues an enforcement notice against Dis-Chem Pharmacies Limited following a security compromise affecting customer personal information.
Sources and References
- Protection of Personal Information Act 4 of 2013 (POPIA), full text(inforegulator.org.za).gov
- Information Regulator: POPIA frequently asked questions, including commencement and complaint acceptance dates(inforegulator.org.za).gov
- Information Regulator: Rules of procedure relating to the manner in which a complaint must be submitted and handled(inforegulator.org.za).gov
- Information Regulator: published enforcement notices(inforegulator.org.za).gov
- Information Regulator eServices Portal(eservices.inforegulator.org.za).gov
- POPIA Explained: the eight conditions, rights and penalties(recordinglaw.com)
- How to complain to the Information Regulator (Form 5)(recordinglaw.com)
- What is the GDPR(recordinglaw.com)