#
Comprehensive statute in force and enforced, but regulator capacity constraints and narrower territorial reach than GDPR analogues justify amber rather than green.
Sub-modules (5)
Regulator And AuthorityAmber
The Information Regulator is POPIA's statutory DPA; it also oversees PAIA complaints and established a Section 50 Enforcement Committee in 2022 to handle complaints, investigations and findings.
Claims: CLM-ZA-a1b2c3d4
Act And InstrumentsGreen
Core instrument is POPIA, supplemented by the 2018 POPIA Regulations and the newly identified 2026 health-information regulations (GN 7198/2026), alongside PAIA for access-to-information overlap.
Claims: CLM-ZA-b2c3d4e5, CLM-ZA-c3d4e5f6
Material ScopeGreen
POPIA covers processing of personal information relating to identifiable living natural persons and, unusually, identifiable existing juristic persons, but excludes purely personal/household processing.
Claims: CLM-ZA-d4e5f6a7, CLM-ZA-e5f6a7b8
Territorial ScopeAmber
Application turns on domicile in the Republic or use of automated/non-automated means within it; POPIA lacks the GDPR's explicit 'offering goods/services' or 'monitoring' extraterritorial hooks.
Claims: CLM-ZA-f6a7b8c9, CLM-ZA-a7b8c9d0
Regulator Registration And FilingAmber
Every responsible party must formally appoint (or default to the head of the organisation as) an Information Officer, delegate in writing, and register with the Information Regulator.
Claims: CLM-ZA-b8c9d0e1
No periodic updates recorded against this sub-brief.
Sources and claims (8)
- ConfirmedDataGuidance — The Information Regulator established an Enforcement Committee under Section 50 of POPIA in July 2022 to consider complaints, investigations, findings and recommendations, including PAIA-related complaints.
- ConfirmedDataGuidance — POPIA is supplemented by the Regulations Relating to the Protection of Personal Information (2018), which set out additional requirements and template forms.
- ProbableDataGuidance — A 2026 sector-specific instrument, the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties (GN 7198/2026), now supplements the general POPIA Regulations.
- ConfirmedIAPP — Personal information under POPIA is broadly defined and, unusually among global data protection laws, extends protection to identifiable existing juristic persons such as companies and trusts, in addition to natural persons.
- ConfirmedIAPP — POPIA does not apply to the processing of personal information carried out for purely personal or household purposes.
- ConfirmedDMASA / DataGuidance — POPIA applies to responsible parties domiciled in the Republic, or not domiciled there but using automated or non-automated means within the Republic, subject to a limited 'mere forwarding' exception.
- ProbableDataGuidance — Unlike the GDPR, POPIA does not contain explicit extraterritorial hooks for the offering of goods or services to, or monitoring of, data subjects from abroad.
- ProbableIAPP — Delegation of duties and authority to an Information Officer must be done formally and in writing, and Information Officers must be registered with the Information Regulator.