ZA

South Africa

Southern Africa

12Instruments
2Cases
4Regulators
80%Coverage
Overview

South Africa's regime is anchored by the Protection of Personal Information Act 4 of 2013 (POPIA), the country's principal data protection statute, assented to on 19 November 2013 and implemented in stages: the provisions establishing the Information Regulator came into force in April 2014, the bulk of the operative compliance provisions on 1 July 2020 (with a one-year transition), and enforcement from 1 July 2021. POPIA applies to any responsible party (the local term for a controller) processing personal information where it is domiciled in South Africa, or, if not, where it uses means in South Africa, excluding purely personal or household processing. POPIA requires compliance with eight conditions for lawful processing, accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data-subject participation, and imposes enhanced requirements on special personal information (health, race or ethnicity, biometrics, political persuasion, religious belief, trade-union membership, criminal behaviour, sexual orientation). Data subjects have rights of access, correction, deletion, and objection, including to electronic direct marketing. Responsible parties must notify both the Regulator and affected data subjects of a security compromise, restrict cross-border transfers to adequate jurisdictions or specified conditions, and appoint and register an Information Officer; penalties reach fines of up to R10 million and ten years' imprisonment. Enforcement rests with the Information Regulator, an independent body accountable to the National Assembly with broad powers over both public and private sectors, enforcement and information notices, investigations, fines, and criminal referrals, which also administers the Promotion of Access to Information Act. POPIA is one of the continent's most influential and well-developed laws; ATLPF currently documents the primary Act and its regulator, supporting a solid single-instrument-plus-regulator coverage position.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection51
AI Governance10
Fintech50
Cybercrime21
Digital Rights41
Platform Liability00
Telecoms11

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
za-paia-2000·Act

Promotion of Access to Information Act 2 of 2000 (PAIA)

South AfricaDigital RightsData ProtectionIn Force
Verified

Enacted 2 Feb 2000

za-const-privacy·Act

Constitution of the Republic of South Africa, 1996, Section 14 (Right to Privacy, including privacy of communications)

South AfricaDigital RightsData ProtectionIn Force
Verified

Enacted 18 Dec 1996

za-rica-2002·Act

Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002 (RICA)

South AfricaDigital RightsTelecomsIn Force
Verified

Enacted 30 Dec 2002

za-cyber-2020·Act

Cybercrimes Act 19 of 2020

South AfricaCybercrimeData ProtectionDigital RightsIn Force
Verified

Enacted 26 May 2021

za-emoney-2009·Guidance

Position Paper on Electronic Money (NPS 01/2009)

South AfricaFintechIn Force
Verified

Enacted 1 Nov 2009

za-npscyberdirective-2024·Guidance

Directive in Respect of Cybersecurity and Cyber-Resilience within the National Payment System (Directive 1 of 2024)

South AfricaFintechCybercrimeIn Force
Verified

Enacted 17 May 2024

za-cryptoasset-2022·Regulation

Declaration of Crypto Assets as a Financial Product under the FAIS Act

South AfricaFintechIn Force
Verified

Enacted 19 Oct 2022

za-npsact-1998·Act

National Payment System Act 78 of 1998

South AfricaFintechIn Force
Verified

Enacted 20 Oct 1998

za-paymentactivities-2025·Guidance

Draft Directive in respect of specific payment activities within the National Payment System (Activity-Based Authorisation)

South AfricaFintechDraft
Verified

Enacted 3 Mar 2025

za-ai-2024·Guidance

National Artificial Intelligence Policy Framework (Draft)

South AfricaAI GovernanceProposed
Verified

Enacted 25 Oct 2024

za-popia-regs-2018·Regulation

Regulations relating to the Protection of Personal Information, 2018 (POPIA Regulations) (South Africa)

South AfricaData ProtectionIn Force
Verified

Enacted 14 Dec 2018

za-popia-2013·Act

Protection of Personal Information Act 4 of 2013

South AfricaData ProtectionIn Force
Verified

Enacted 19 Nov 2013

Cases
za-cc-2021-amabhungane-rica

Constitutional Court of South Africa

South AfricaDigital RightsTelecomsSupreme Court / Court of Appeal
Verified

Decided 4 Feb 2021

"The Constitutional Court confirmed that RICA is unconstitutional to the extent it fails to provide adequate safeguards for the right to privacy under section 14 of the Constitution, including the absence of post-surveillance notification, inadequate independence in the appointment of the designated judge, and no special protections for journalists and lawyers, and held that bulk surveillance conducted by the National Communications Centre has no lawful basis. The declaration of invalidity was suspended for three years to allow Parliament to remedy the defects."

za-ir-2023-doj

Information Regulator of South Africa

South AfricaData ProtectionCybercrimeTribunal / Regulatory Body
Verified

Decided 3 Jul 2023

"The Information Regulator imposed a R5 million administrative fine on the Department of Justice and Constitutional Development for failing to comply with an enforcement notice, having found the Department in breach of its security-safeguard obligations under sections 19 and 22 of POPIA, specifically, its failure to renew antivirus, intrusion-detection and SIEM licences, which contributed to a 2021 ransomware breach that compromised personal information."

Notable gaps

ATLPF now holds both POPIA and its 2018 Regulations (as amended 2025), making South Africa a multi-instrument jurisdiction. Remaining documentation gaps: the Information Regulator's registered codes of conduct and guidance notes are not yet captured as separate instruments.