Protection of Personal Information Act 4 of 2013
za-popia-2013 · Act
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's principal statute governing the processing of personal information. Assented to on 19 November 2013 and published in Government Gazette No. 37067 on 26 November 2013, POPIA was implemented in stages. Foundational provisions, including those establishing the Information Regulator, came into force on 11 April 2014. The bulk of the operative compliance provisions came into force on 1 July 2020, giving organisations a one-year transition period. Enforcement against non-compliant organisations commenced on 1 July 2021. POPIA applies to any responsible party (the South African equivalent of a data controller) that processes personal information entered into a record where that party is domiciled in South Africa, or, where it is not domiciled in South Africa, where it uses automated or non-automated means in South Africa to process personal information. Purely personal or household processing is excluded. The Act establishes the Information Regulator as an independent body accountable to the National Assembly. The Regulator has broad enforcement powers including the authority to issue enforcement notices and information notices, conduct investigations, assess fines, and refer matters for criminal prosecution over both public and private sector responsible parties. POPIA requires all responsible parties to comply with eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. These conditions govern every aspect of the data lifecycle from collection through disposal. Special categories of personal information, including health data, racial or ethnic origin, biometric data, political persuasion, religious or philosophical beliefs, trade union membership, criminal behaviour, and sexual orientation, may only be processed on specific narrow grounds. Data subjects have rights to access their personal information, to request correction or deletion, to object to processing (including objection to direct marketing by electronic means), and to complain to the Information Regulator. Responsible parties must notify both the Information Regulator and affected data subjects when a security compromise occurs. Criminal penalties include fines of up to R10 million and imprisonment of up to ten years for serious offences. Responsible parties must appoint an Information Officer, registered with the Information Regulator, to oversee POPIA compliance.
- Establishes the Information Regulator as South Africa's independent supervisory authority with full enforcement powers over public and private sector responsible parties, accountable to the National Assembly.
- Requires responsible parties to comply with eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.
- Imposes enhanced protection requirements for special personal information, including health data, racial or ethnic origin, biometric data, political persuasion, and sexual orientation, which may only be processed on narrow grounds.
- Grants data subjects rights of access, correction, deletion, and objection to processing, including a specific right to object to electronic direct marketing.
- Requires responsible parties to notify both the Information Regulator and affected data subjects of any security compromise involving unauthorised access to personal information.
- Restricts cross-border transfers of personal information to countries with adequate protection or where specific conditions are met, including data subject consent.
- Requires each responsible party to appoint and register an Information Officer with the Information Regulator to oversee POPIA compliance.
- Provides for administrative enforcement notices, fines of up to R10 million, and criminal penalties of up to ten years' imprisonment for serious non-compliance.