POPIA
The Protection of Personal Information Act, and how it applies to Eques.
Last updated: August 2026
1. Purpose and Objectives
The Protection of Personal Information Act (POPIA) was enacted to give effect to the constitutional right to privacy enshrined in the South African Constitution, by safeguarding personal information when processed by responsible parties. The Act aims to balance the right to privacy against other rights, such as the right of access to information under PAIA. It establishes conditions for the lawful processing of personal information, provides persons with rights and remedies to protect their personal information, and established the Information Regulator to ensure respect for and promote, enforce and fulfil the rights protected by the Act.
2. Commencement Dates
The Act came into force in phases with the following commencement dates:
- 11 April 2014: Section 1, Part A of Chapter 5 (Sections 39 to 54), Sections 112 and 113 came into effect.
- 1 July 2020: The main operative provisions (Sections 2 to 38, Sections 55 to 109, Section 111, Section 114(1), (2) and (3)) came into effect. Parliament assented to POPIA on 19 November 2013.
- 30 June 2021: Sections 110 and 114(4) came into effect.
- 1 February 2022: Section 58(2), insofar as it becomes applicable to processing referred to in section 57, came into effect.
3. Territorial Scope
POPIA applies to the processing of all Personal Information entered into a record by or for a Responsible Party making use of automated or non-automated means, provided that:
- When the recorded Personal Information is processed by non-automated means, it forms part of a filing system.
- The Responsible Party is domiciled in South Africa.
- Where a Responsible Party is not domiciled in South Africa but makes use of automated and non-automated means to process Personal Information through South Africa.
4. Exclusions
POPIA does not apply to the processing of Personal Information:
- In the course of a purely personal or household activity.
- That has been de-identified and cannot be re-identified.
- By or on behalf of a public body in a matter which involves national security or the prevention or detection of unlawful activities.
- To the extent that adequate safeguards have been established in other legislation for the protection of Personal Information by the Cabinet or Executive Council of a province, or relating to judicial functions of the court.
- For journalistic, literary or artistic expression to the extent that such an exclusion is necessary to reconcile, as a matter of public interest, the right to privacy with the right to freedom of expression.
5. Eight Conditions for Lawful Processing of Personal Information
POPIA contains eight conditions that must be met for the lawful processing of personal information:
- Accountability (Section 8): The Responsible Party must ensure that all the conditions for lawful processing are met. The ultimate responsibility vests with the Responsible Party to ensure compliance with all measures to give effect to the eight conditions, both at the time of determining the purpose and means of processing and during processing itself.
- Processing Limitation (Sections 9 to 12): Personal information must be processed lawfully and in a manner that does not infringe the privacy of the data subject. Processing must be relevant, not excessive, and where required, consent must be obtained. The information must be collected directly from the data subject unless otherwise permissible.
- Purpose Specification (Sections 13 to 14): Personal information must be collected for a specific, defined and lawful purpose related to the function of the Responsible Party. Data subjects must be made aware of this purpose. Records must not be retained for longer than necessary and must be deleted or destroyed once the Responsible Party is no longer authorised to retain them.
- Further Processing Limitation (Section 15): Any further processing of personal information must be compatible with the purpose of the original collection. Compatibility is assessed based on the nature of the information, the relationship between the purposes, the reasonable expectations of the data subject, and the consequences of the further processing.
- Information Quality (Section 16): The Responsible Party must take reasonable steps to ensure that personal information is complete, accurate, not misleading and updated where necessary.
- Openness (Sections 17 to 18): The data subject must be aware that their personal information is being collected, for what purpose, and how it is to be used. The Responsible Party must maintain records of all processing operations.
- Security Safeguards (Sections 19 to 22): The Responsible Party must secure the integrity and confidentiality of personal information by taking measures to prevent loss, damage, or unauthorised access. Operators must treat all personal information as confidential. If there is a suspected breach, the Responsible Party must be notified. The Responsible Party has the ultimate duty to notify the Information Regulator and data subject of any security compromise where there are reasonable grounds to believe personal information has been accessed by an unauthorised party.
- Data Subject Participation (Sections 23 to 25): This includes the rights of data subjects to access, correct or delete their personal information. Data subjects have the right to request confirmation of whether the Responsible Party holds their personal information, request access to their personal information, request correction or deletion of their personal information, and object to or withdraw consent for the processing of their personal information.
6. Special Personal Information
POPIA provides additional protection for "Special Personal Information" which includes information concerning:
- Religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, or biometric information of a data subject.
- The criminal behaviour of a data subject to the extent that such information relates to the alleged commission of an offence or the disposal of such proceedings.
The general prohibition on processing Special Personal Information does not apply if:
- The processing is carried out with the data subject’s consent.
- The processing is necessary for the establishment, exercise or defence of a right or obligation in law.
- The processing is necessary to comply with an obligation of international public law.
- The processing is for historical, statistical or research purposes to the extent that it serves a public interest or appears impossible to obtain consent.
- The information is made public by the data subject.
7. Responsible Party and Operator Obligations
Responsible Party: The Responsible Party is a public body, private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information. The ultimate responsibility vests with the Responsible Party to ensure that the eight conditions are complied with. The Responsible Party will be held accountable even if non-compliance is caused by the operator.
Operator: The Operator is the public body, private body or any other person who processes the personal information for a Responsible Party in terms of a contract or mandate. POPIA requires a written agreement between the Responsible Party and the Operator to ensure that the Operator establishes and maintains appropriate security measures. Operators may only process personal information with the knowledge and authorisation of the Responsible Party, must treat all personal information as confidential, and must immediately notify the Responsible Party when there are reasonable grounds to believe that personal information under their control may have been accessed by any unauthorised person.
8. Cross-Border Data Transfers
A transfer of personal information to a third party in a foreign country may only be undertaken if:
- The third-party recipient is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection substantially similar to the principles for lawful processing of POPIA, and includes provisions similar to the restrictions on further transfers of personal information.
- The data subject consents to the transfer.
- The transfer is necessary for the performance of a contract between the data subject and the Responsible Party.
- The transfer is necessary for the conclusion of a contract, in the interest of the data subject, between the Responsible Party and a third party.
- The transfer is for the benefit of the data subject and it is not reasonably practical to obtain consent, and it is likely that, nonetheless, consent would be given.
9. Security Compromise Notification
Timeline for Notification: The Responsible Party must notify the Information Regulator and the Data Subject as soon as reasonably possible where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person. This has been interpreted in practice to mean within 72 hours of the potential security compromise. The Responsible Party may only delay notification to the data subject if a public body responsible for investigations or the Information Regulator determines that notification may impede a criminal investigation.
Requirements for Notification: The notification must be in writing and communicated via mail, email, prominently on the website, news media or as directed by the Regulator. The notification must at least:
- Describe the likely consequences of the security compromise.
- Describe the measures taken or proposed to be taken by the Responsible Party to address the security compromise.
- Provide a recommendation regarding measures to be taken by the data subject to mitigate possible adverse effects.
- If known, the identity of the unauthorised person who may have accessed or acquired the personal information.
10. Direct Marketing and Unsolicited Electronic Communications
General Prohibition: Direct marketing by means of unsolicited electronic communications (including automatic calling machines, SMS or email) is prohibited unless the data subject has given their consent.
Consent Requirements: The data subject’s consent must be requested in a prescribed manner and form. Any communication for the purpose of direct marketing must contain the contact details of the sender to enable the recipient to request that such communications cease. A data subject who is a subscriber to a printed or electronic directory should be able to unsubscribe for free.
National Opt-Out Registry: Under recent amendments to the Consumer Protection Act (CPA) Regulations (published 15 April 2026), direct marketers must register with the National Consumer Commission’s opt-out registry and conduct monthly cleansing of marketing databases. The new CPA opt-out registry does not replace POPIA; it adds another compliance step for direct marketers.
11. Information Officers
The Information Officer is responsible for ensuring compliance with POPIA. For public bodies, the administrative head is the default Information Officer and must designate Deputy Information Officers.
Duties and Responsibilities include:
- Ensuring compliance with lawful processing of personal information by the public body.
- Dealing with requests that relate to POPIA.
- Working with the Information Regulator on investigations that relate to prior authorisations.
12. Codes of Conduct
The Information Regulator must consult with affected stakeholders before approving a code of conduct and must publish the code on its website. Codes of conduct assist relevant bodies to decide whether it is appropriate for them to develop a code, clarify when the Regulator will develop a code on its own initiative, provide for stakeholder consultations, outline procedures for dealing with complaints, and create opportunities to develop best practices to improve compliance with POPIA.
13. Enforcement and Penalties
Interference with Protection of Personal Information: Interference is considered a breach of the conditions for the lawful processing of personal information or the provisions of a code of conduct.
Complaints Process: Any person who alleges interference with the protection of personal information may submit a complaint to the Information Regulator in a prescribed manner.
Powers of the Information Regulator: The Regulator has the power to investigate a complaint, summon and enforce appearance of the Responsible Party, administer oaths, enter and search premises after obtaining a warrant, and search and seize any equipment or record used for processing of personal information.
Penalties: Any person convicted of an offence can be subject to a fine or imprisonment for a period not exceeding ten years, or to both a fine and imprisonment. For certain offences, imprisonment for a period not exceeding twelve months and a fine may apply. Administrative fines of up to 10 million South African Rand may be imposed for infringements of certain provisions.
Civil Remedies: A data subject may institute civil action for damages in a court against a Responsible Party for breach of the provisions of the law. The Information Regulator may also institute civil action at the request of the data subject.
14. Relationship Between POPIA and PAIA
POPIA and the Promotion of Access to Information Act (PAIA) hold a special relationship. PAIA is an "access" law, all about freedom of information and the right of access to information held by both public and private bodies. POPIA, on the other hand, is about privacy and the prevention of exposure of information. PAIA sets limits on the types of information that can be accessed, while POPIA sets out the minimum standards regarding accessing and processing any personal information belonging to another.
15. New Health Information Regulations (March 2026)
In March 2026, the Information Regulator finalised and published Regulations relating to the processing of health information by certain responsible parties. These Regulations:
- Apply exclusively to the processing of health information (references to sex life information were removed).
- Apply to insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers and institutions working for them.
- Reiterate the general prohibition on processing special personal information, including health information.
- Emphasise security safeguards, requiring appropriate measures for the security and confidentiality of records, including physical and electronic records, and the proper disposal of health records.
- Reinforce that health information may not be transferred outside South Africa unless the requirements of section 72 of POPIA are met.
- Apply to every employer that processes the health information of their employees, including sick notes, medical records, and medical certificates.
See also our Privacy Policy, the Terms and Conditions, and the PAIA Manual.
