Regulations relating to the Protection of Personal Information, 2018 (POPIA Regulations) (South Africa)
za-popia-regs-2018 · Regulation
The Regulations relating to the Protection of Personal Information, 2018 are the principal subsidiary legislation made under the Protection of Personal Information Act 4 of 2013 (POPIA). They were published by the Information Regulator in Government Gazette No. 42110 (Government Notice R.1383) on 14 December 2018 and operationalise the procedural machinery of POPIA. The Regulations were subsequently amended, most recently by the POPIA Amendment Regulations 2025, published on 17 April 2025. The Regulations are largely administrative and procedural in nature, prescribing the forms and processes that give effect to rights and duties created by the Act. They cover the manner in which a data subject may object to processing and request correction or deletion of personal information; the responsibilities and duties of an Information Officer; the procedure for applying to the Regulator to issue or amend a code of conduct; the manner of obtaining a data subject's consent for direct marketing; and the procedures for submitting, investigating, conciliating, and settling complaints to the Information Regulator, including assessments and pre-investigation steps. Together with POPIA itself, these Regulations form the operative core of South Africa's data protection framework and are administered by the Information Regulator. This entry was created during a June 2026 documentation pass and is AI-drafted from public sources; the primary text is hosted on the Information Regulator's own website. Reviewer should confirm the consolidated current version (including the 2025 amendments) and finalise the citation. Source language: English.
- Principal subsidiary legislation under POPIA, published by the Information Regulator in GG No. 42110 (GN R.1383) on 14 December 2018; amended by the POPIA Amendment Regulations 2025 (17 April 2025).
- Prescribe forms and procedures for data subjects to object to processing and request correction or deletion.
- Set out the responsibilities and duties of the Information Officer.
- Provide the procedure for applying for, and issuing, codes of conduct.
- Regulate the manner of obtaining consent for direct marketing.
- Establish the procedures for lodging, investigating, conciliating, and settling complaints with the Information Regulator.
- Administered by the Information Regulator alongside POPIA.
- Reviewer action: confirm the consolidated current text including 2025 amendments and finalise the citation.