POPIA
Protection of Personal Information Act
Regulates the lawful processing of personal information by public and private bodies to protect individuals' right to privacy.
Sections
8
Duties
11
Questions
20
Assessment from
R 35 000
What it covers
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary data protection legislation, modelled closely on the EU's GDPR framework. It gives effect to Section 14 of the Constitution, which guarantees the right to privacy. POPIA came fully into force on 1 July 2021 after a one-year grace period. It applies to any person or organisation (the 'responsible party') that determines the purpose and means of processing personal information in South Africa, regardless of whether the processing occurs inside or outside the country. Processing includes collection, storage, use, dissemination, deletion, and destruction of personal information. The Act establishes eight conditions for lawful processing, creates the Information Regulator as an independent enforcement body, grants data subjects eight enforceable rights, and imposes obligations around security safeguards, operator agreements, cross-border transfers, special categories of information, and breach notification. Non-compliance can result in administrative fines, criminal prosecution, civil damages claims, and reputational harm. Every organisation that touches personal data — employee records, customer databases, marketing lists, CCTV footage, health records — is affected.
Does this apply to you?
It applies if
- Your organisation collects, stores, uses, or shares personal information of any natural person (employee, customer, supplier contact, website visitor)
- You operate a website that uses cookies, analytics, or contact forms
- You process employee payroll or HR records
- You send marketing communications (email, SMS, WhatsApp, direct mail)
- You use CCTV cameras in the workplace or on premises
- You share personal information with third-party service providers (cloud, payroll, CRM, marketing platforms)
- You conduct credit checks or verify identities as part of onboarding
- You hold health, financial, criminal, or biometric records of any individuals
- You transfer personal information outside South Africa (to head office, cloud servers, or processors abroad)
Thresholds that change what's required
- Applies to all organisations regardless of size — there is no SME exemption under POPIA
- Heightened obligations apply when processing special personal information (health, race, religion, biometrics, criminal record, sexual orientation, trade union membership)
- Cross-border transfer restrictions apply when sending data to countries without adequate protection
Exemptions
- Processing by a natural person purely for personal or household purposes
- Processing for journalistic, literary, or artistic purposes where the responsible party has a reasonable belief it is in the public interest
- Processing by the Cabinet or Executive Council
- Processing that has been de-identified such that the individual cannot be re-identified
What the assessment covers
The assessment works through 20 questions across 11 duties, scored out of 238. Each answer generates the specific actions needed to close or prove that duty — and a “yes” only counts once its evidence is in, which is what makes the score defensible rather than self-declared.
The questions themselves are part of the assessment.
Find out where you stand on POPIA
Run the assessment, get your score, and get the exact list of what to fix — with the evidence trail an auditor will ask for.