Comprehensive regime
Protection of Personal Information Act 4 of 2013 (POPIA)
Protection of Personal Information Act 4 of 2013 (POPIA)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa
In force since 1 July 2020. Binds public and private bodies.
What this law does
Chapter 3 conditions the lawful processing of personal information on a data subject's consent or another listed ground, limits collection and retention to the purpose for which the information was collected, and requires a responsible party (defined to include a public or private body) to keep the information secure.
Section 26 prohibits processing special personal information, including a data subject's religious belief, race, health, or biometric information, unless one of the grounds in sections 27 to 33 applies, and section 22 requires notifying the Information Regulator and the affected data subject as soon as reasonably possible after discovering that personal information was accessed or acquired by an unauthorised person.
Section 71 bars a decision with legal or substantially similar consequences for a data subject that is based solely on automated processing of their personal information intended to profile them, unless the data subject can make representations about it, and section 72 bars transferring personal information to a third party in a foreign country unless that country, or the recipient's binding rules or agreement, provides an adequate level of protection, or another listed ground such as the data subject's consent applies.
A data subject may institute a civil action for damages directly against a responsible party under section 99, and the Information Regulator may issue an administrative fine of up to R10 million under section 109 or refer conduct for prosecution, which for the most serious offences carries a fine or imprisonment of up to ten years under section 107.
What it requires