IOC Law / Africa Intelligence / South Africa

Data Protection and Privacy in South Africa

← Back to the South Africa guide

The Protection of Personal Information Act 4 of 2013 (POPIA) applies to responsible parties and operators processing personal information within its scope. It is built around accountability, processing limitation, purpose specification, further-processing compatibility, information quality, openness, security safeguards and data-subject participation.

The head of a private body is ordinarily its Information Officer. The Information Regulator states that public and private bodies must register Information Officers and that they may perform their duties only after registration. Registration is available through the Regulator’s eServices portal. A multinational based outside South Africa should consider the Regulator’s guidance on designating a locally accessible Deputy Information Officer.

Build compliance from actual data flows. Inventory customer, employee, supplier, website, CCTV, marketing and due-diligence data; identify purposes and lawful justification; issue notices; control collection and access; set retention and deletion; and establish data-subject request procedures. Special personal information, children’s information, direct electronic marketing, credit reporting and unique identifiers can trigger additional rules or prior authorisation.

An operator processing for a responsible party must be governed by a written contract requiring appropriate security measures and breach notification. Cloud, payroll, CRM, analytics, support and outsourcing contracts should allocate POPIA responsibility, sub-operators, audit, deletion and incident cooperation.

Section 72 controls transfers outside South Africa. A transfer normally needs an adequate law or binding agreement, consent or another statutory basis. Prior authorisation may be required for transferring special personal information or children’s information to a foreign country without adequate protection; the Regulator describes the prior-authorisation process.

Security compromises must be reported to the Regulator and affected data subjects in accordance with POPIA. From 1 April 2025 the Regulator requires notifications through eServices and publishes section 22 guidance. Maintain an incident plan, investigation capability and decision log. Assess the Promotion of Access to Information Act alongside POPIA and prepare and publish the required PAIA manual.