EnglishZU
South Africa flag

South Africa

South Africa Data Privacy Laws: The POPIA Guide (2026)

Independently fact-checked against primary sources (last audited July 23, 2026). · 5 primary sources cited on this page. How we verify our legal content

South Africa Data Privacy Laws: The POPIA Guide (2026)

Frequently Asked Questions

Why do people give two different dates for when POPIA took effect?

POPIA commenced on 1 July 2020 under Proclamation R.21 of 2020, bringing the bulk of the Act, including all eight conditions, into force on that date. Section 114(1) then gave responsible parties a one year grace period to come into conformity. The Information Regulator treats claims arising before 1 July 2021 as outside its complaint jurisdiction, which is why that later date is often (imprecisely) described as when POPIA took effect.

How does POPIA compare to the EU's GDPR?

Both regulate the processing of personal information and set conditions for lawful processing, but POPIA extends its protection to juristic persons such as companies where applicable, which the GDPR does not, has no data portability right, has no fixed statutory breach notification deadline (the GDPR sets 72 hours), and uniquely allows criminal imprisonment of up to 10 years for the most serious offences. POPIA's maximum administrative fine of R10 million is far lower than the GDPR's maximum of the greater of 20 million euro or 4 percent of global turnover.

Does POPIA apply to a foreign company with no office in South Africa?

POPIA applies to processing carried out in South Africa or through automated or non automated means located in South Africa, regardless of where the responsible party is based. A foreign business that processes the personal information of people in South Africa using means situated there can fall within POPIA's scope.

Are companies and other juristic persons protected under POPIA the same way individuals are?

Not identically. POPIA's definition of personal information covers an identifiable, living natural person and, where it is applicable, an identifiable existing juristic person. That qualifier means juristic person protection is real but conditional, not a blanket mirror of the protection given to a natural person.

What happened in the WhatsApp case with South Africa's Information Regulator?

The Information Regulator issued a section 95 enforcement notice against WhatsApp, made public on 16 April 2025, after finding that WhatsApp applied different, weaker privacy terms and policies to South African users than it applied to users in Europe, in breach of several POPIA conditions including accountability and purpose specification.

Who decides a POPIA damages claim, the court or the Information Regulator?

The court. Section 99 lets a data subject, or the Information Regulator acting at the data subject's request, institute a civil action for damages in a court with jurisdiction, and it is the court that decides whether to award an amount it considers just and equitable. Section 99(2) gives the responsible party defences, including vis major, the data subject's own consent or fault, and that compliance was not reasonably practicable.

Does every POPIA offence carry up to 10 years imprisonment?

No. Section 107 splits criminal penalties by offence: a fine or up to 10 years imprisonment applies only to a specific list of offences, including obstructing the Regulator and unlawful acts involving another person's account number, while other offences, such as breaching the Regulator's confidentiality, carry a fine or up to 12 months imprisonment. Separately, the Information Regulator can impose an administrative fine of up to R10 million under section 109.

Is there an official list of countries POPIA treats as having adequate data protection?

No. Section 72 requires the recipient in a foreign country to be subject to a law, binding corporate rules, or a binding agreement that provides substantially similar protection to POPIA's conditions, but POPIA does not maintain a formal adequacy list the way the EU does for the GDPR. Each responsible party has to assess and document adequacy for itself, or rely on one of section 72's other bases, such as the data subject's consent.

Updates

Independently fact-checked against the cited primary sources

Information Regulator publishes a section 95 enforcement notice against WhatsApp, finding it applied weaker privacy terms to South African users than to European users.

Information Regulator issues an enforcement notice against the Department of Basic Education.

Information Regulator issues an enforcement notice against Dis-Chem Pharmacies Limited following a security compromise affecting customer personal information.

Sources and References

  1. Protection of Personal Information Act 4 of 2013 (POPIA), full text(inforegulator.org.za).gov
  2. Information Regulator: POPIA frequently asked questions, including commencement and complaint acceptance dates(inforegulator.org.za).gov
  3. Information Regulator: Rules of procedure relating to the manner in which a complaint must be submitted and handled(inforegulator.org.za).gov
  4. Information Regulator: published enforcement notices(inforegulator.org.za).gov
  5. Information Regulator eServices Portal(eservices.inforegulator.org.za).gov
  6. POPIA Explained: the eight conditions, rights and penalties(recordinglaw.com)
  7. How to complain to the Information Regulator (Form 5)(recordinglaw.com)
  8. What is the GDPR(recordinglaw.com)
Share: