Protection of Personal Information Act 4 of 2013 (POPIA)
Protection of Personal Information Act 4 of 2013 (POPIA)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 July 2020.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain a lawful basis, such as the data subject's consent, before processing personal information, and limit processing to the purpose for which it was collected.
- Do not process special personal information, including a person's biometric information, health, race, or political persuasion, unless a listed ground under sections 27 to 33 applies.
- Do not base a decision that has legal or substantially similar consequences for a person solely on automated processing of their personal information, unless the person can make representations about the decision.
- Notify the Information Regulator and the affected person as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person.
- Before transferring personal information outside South Africa, confirm the recipient country, its binding rules, or an agreement provides an adequate level of protection, or that another listed transfer ground, such as the data subject's consent, applies.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
A conviction under sections 100, 103(1), 104(2), 105(1) or 106(1), (3) or (4) carries a fine or imprisonment of up to ten years, or both; a conviction under sections 59, 101, 102, 103(2) or 104(1) carries a fine or imprisonment of up to twelve months, or both (s. 107).
Penalty structure
Administrative fine cap the Information Regulator may impose by infringement notice under section 109(2)(c). A separate criminal conviction under section 107 carries a fine at the convicting court's discretion, or imprisonment of up to ten years, rather than a further fixed monetary cap.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- ZAR
- Fixed cap
- 10,000,000
Who enforces it
Enforcement body
Information Regulator of South Africa
What it reaches
Obligation class
Consent, Biometric, Breach notice, Data subject rights, Disclosure, Security, Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Chapter 3 conditions the lawful processing of personal information on a data subject's consent or another listed ground, limits collection and retention to the purpose for which the information was collected, and requires a responsible party (defined to include a public or private body) to keep the information secure.
Section 26 prohibits processing special personal information, including a data subject's religious belief, race, health, or biometric information, unless one of the grounds in sections 27 to 33 applies, and section 22 requires notifying the Information Regulator and the affected data subject as soon as reasonably possible after discovering that personal information was accessed or acquired by an unauthorised person.
Section 71 bars a decision with legal or substantially similar consequences for a data subject that is based solely on automated processing of their personal information intended to profile them, unless the data subject can make representations about it, and section 72 bars transferring personal information to a third party in a foreign country unless that country, or the recipient's binding rules or agreement, provides an adequate level of protection, or another listed ground such as the data subject's consent applies.
A data subject may institute a civil action for damages directly against a responsible party under section 99, and the Information Regulator may issue an administrative fine of up to R10 million under section 109 or refer conduct for prosecution, which for the most serious offences carries a fine or imprisonment of up to ten years under section 107.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_biometricsprocesses_voice