{
 "jurisdiction_id": "ZA",
 "jurisdiction": "South Africa",
 "url": "https://dataprotection.gi/jurisdictions/south-africa/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 32,
  "sub_modules": 57,
  "source_register": 10
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute in force and enforced, but regulator capacity constraints and narrower territorial reach than GDPR analogues justify amber rather than green.",
   "claims": [
    {
     "statement": "The Information Regulator established an Enforcement Committee under Section 50 of POPIA in July 2022 to consider complaints, investigations, findings and recommendations, including PAIA-related complaints.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-africa-information-regulator%C2%A0establishes",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA is supplemented by the Regulations Relating to the Protection of Personal Information (2018), which set out additional requirements and template forms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A 2026 sector-specific instrument, the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties (GN 7198/2026), now supplements the general POPIA Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/south-africa-privacy-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal information under POPIA is broadly defined and, unusually among global data protection laws, extends protection to identifiable existing juristic persons such as companies and trusts, in addition to natural persons.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/after-a-7-year-wait-south-africas-data-protection-act-enters-into-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA does not apply to the processing of personal information carried out for purely personal or household purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/after-a-7-year-wait-south-africas-data-protection-act-enters-into-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA applies to responsible parties domiciled in the Republic, or not domiciled there but using automated or non-automated means within the Republic, subject to a limited 'mere forwarding' exception.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DMASA / DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/20230227_dmasa_popia_coc_v4.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, POPIA does not contain explicit extraterritorial hooks for the offering of goods or services to, or monitoring of, data subjects from abroad.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Delegation of duties and authority to an Information Officer must be done formally and in writing, and Information Officers must be registered with the Information Regulator.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category regime is in force and broadly GDPR-aligned, but pseudonymisation/anonymisation concepts are undeveloped.",
   "claims": [
    {
     "statement": "POPIA establishes eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/national-assembly-passes-south-african-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 11 of POPIA, processing is lawful where the data subject, or a competent person where the data subject is a child, consents to the processing, provided other statutory requirements are met.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/south-africa-processing-childrens-personal",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 26 of POPIA prohibits the processing of special personal information, subject to the exceptions listed in Section 27(1).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-africa-regulator-releases-guidance-note-2",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Responsible parties relying on the Section 27-33 exceptions for special personal information must apply to the Information Regulator for prior authorisation via a prescribed application process.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-africa-regulator-releases-guidance-note-2",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No comprehensive pseudonymisation or anonymisation safe-harbour analogous to the GDPR's treatment of pseudonymised data was located in POPIA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework exists and is in force but is less prescriptive than GDPR on deadlines and omits portability; some sub-modules rely on secondary commentary only.",
   "claims": [
    {
     "statement": "POPIA does not establish an explicit right to data portability; the Information Regulator has not yet legislated such a right.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Comparative legal analysis identifies variation between POPIA and the GDPR in when data subject rights can be exercised and how a controller must respond to a data breach, with POPIA generally less prescriptive on timing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability and breach-notification duties are in force, but DPIA/privacy-by-design and precise breach timing are materially weaker than GDPR equivalents.",
   "claims": [
    {
     "statement": "Privacy by design, while mandated under GDPR Article 25, is not mentioned in POPIA at all and remains a best-practice/voluntary approach.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA has no specific data protection impact assessment requirement equivalent to GDPR Article 35, although risk-assessment obligations may be inferred when considering security safeguards.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under POPIA, unlike GDPR Article 37, there is no size/type/processing-scale threshold for appointing an Information Officer — all organisations are required to have one, defaulting to the head of the organisation absent a formal appointment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA does not currently elaborate joint-responsible-party or third-party/recipient relationships to the same granularity as the GDPR, though future Regulator regulations may address this.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA introduced a mandatory data breach notification obligation requiring responsible parties to report suspected unauthorised access to the Information Regulator and, in some cases, affected data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/after-a-7-year-wait-south-africas-data-protection-act-enters-into-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA's breach notification standard requires reporting 'as soon as reasonably possible,' without the GDPR's specific 72-hour benchmark for notifying supervisory authorities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A cross-border transfer restriction exists and is in force, but adequacy status (received/granted) and formal transfer-mechanism tooling (SCCs/BCRs/TIA) remain unconfirmed or absent in the sources reviewed.",
   "claims": [
    {
     "statement": "POPIA (in its original POPI Bill drafting, carried into the Act) restricts transfer of personal data outside South Africa unless the recipient country's laws provide a similar level of protection for the personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/national-assembly-passes-south-african-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA could plausibly be viewed as 'adequately protective' under GDPR-equivalence standards because stricter provisions were drawn from earlier GDPR drafts, but this remains a hoped-for outcome rather than a confirmed adequacy decision.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/after-a-7-year-wait-south-africas-data-protection-act-enters-into-force",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Major cloud providers established local South African data centres in anticipation of POPIA's cross-border transfer requirements coming into force.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/after-a-7-year-wait-south-africas-data-protection-act-enters-into-force",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Absent substantive sectoral-overlay evidence beyond the single 2026 health regulation; explicit gap discipline applied.",
   "claims": []
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing sub-module has reasonable evidence; other sub-modules are gaps.",
   "claims": [
    {
     "statement": "The Direct Marketing Association of South Africa (DMASA) developed a POPIA Code of Conduct intended to become enforceable against its members once recognised by the Information Regulator, covering direct marketing consent, co-responsible-party liability, and personal information impact assessments.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DMASA / DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/20230227_dmasa_popia_coc_v4.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Only the biometric-as-special-category link is substantively evidenced; ADM transparency, AI risk assessment, genetic data, and surveillance carveouts are unconfirmed gaps.",
   "claims": [
    {
     "statement": "Biometric information falls within POPIA's definition of special personal information, meaning its processing is prohibited under Section 26 unless a Section 27(1) exception (or Regulator prior authorisation under ss. 28-33) applies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core children's-data consent framework is confirmed and in force; age-verification, profiling-ban, and dependent-adult sub-modules are unconfirmed gaps.",
   "claims": [
    {
     "statement": "POPIA defines a child as anyone under 18, but commentary highlights ongoing challenges in verifying consent and applying the definition in digital contexts such as social media usage by children.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/south-africa-processing-childrens-personal",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sections 34 and 35 of POPIA impose stringent conditions for processing children's personal information, requiring valid consent from a competent person, with exceptions for legal rights, public interest, and historical research.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/south-africa-processing-childrens-personal",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-africa/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement architecture and penalty comparison are confirmed and in force; collective redress, private right of action, and a full 12-month enforcement activity ledger remain unconfirmed gaps.",
   "claims": [
    {
     "statement": "The GDPR typically imposes much larger fines than POPIA — up to €20 million or a percentage of global annual revenue — compared with POPIA's administrative fine ceiling of approximately ZAR10 million.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "POPIA provides for imprisonment of individuals who commit criminal acts involving personal information, whereas the GDPR leaves criminal sanctions to be determined at EU Member State level.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-africas-protection-of-personal-information-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Information Regulator held its first meeting late in 2016, and secondary commentary characterises its operations as still limited relative to comparable data protection authorities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/onetrustdataguidance_comparingprivacylaws_gdprvpopia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A 2026 regulation specific to health information processing by certain responsible parties (GN 7198/2026) has been added to South Africa's data protection legal framework alongside the core 2018 POPIA Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/south-africa-privacy-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}