Financial Services

POPIA

Protection of Personal Information Act

Regulates the lawful processing of personal information by public and private bodies to protect individuals' right to privacy.

Issued by:Information Regulator of South AfricaEnforced by:Information Regulator of South Africa (enforcement division), with referral to the National Prosecuting Authority for criminal mattersCitation:Act 4 of 2013
Financial ServicesBankingInsuranceFintechHealthcarePharmaceuticalsMedical DevicesTechnologyData ProcessingTelecommunicationsConstructionMiningReal EstateManufacturingLogisticsSupply ChainRetailFMCGEducationLegal ServicesGovernment

Sections

8

Duties

11

Questions

20

Assessment from

R 35 000

What it covers

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary data protection legislation, modelled closely on the EU's GDPR framework. It gives effect to Section 14 of the Constitution, which guarantees the right to privacy. POPIA came fully into force on 1 July 2021 after a one-year grace period. It applies to any person or organisation (the 'responsible party') that determines the purpose and means of processing personal information in South Africa, regardless of whether the processing occurs inside or outside the country. Processing includes collection, storage, use, dissemination, deletion, and destruction of personal information. The Act establishes eight conditions for lawful processing, creates the Information Regulator as an independent enforcement body, grants data subjects eight enforceable rights, and imposes obligations around security safeguards, operator agreements, cross-border transfers, special categories of information, and breach notification. Non-compliance can result in administrative fines, criminal prosecution, civil damages claims, and reputational harm. Every organisation that touches personal data — employee records, customer databases, marketing lists, CCTV footage, health records — is affected.

Does this apply to you?

It applies if

  • Your organisation collects, stores, uses, or shares personal information of any natural person (employee, customer, supplier contact, website visitor)
  • You operate a website that uses cookies, analytics, or contact forms
  • You process employee payroll or HR records
  • You send marketing communications (email, SMS, WhatsApp, direct mail)
  • You use CCTV cameras in the workplace or on premises
  • You share personal information with third-party service providers (cloud, payroll, CRM, marketing platforms)
  • You conduct credit checks or verify identities as part of onboarding
  • You hold health, financial, criminal, or biometric records of any individuals
  • You transfer personal information outside South Africa (to head office, cloud servers, or processors abroad)

Thresholds that change what's required

  • Applies to all organisations regardless of size — there is no SME exemption under POPIA
  • Heightened obligations apply when processing special personal information (health, race, religion, biometrics, criminal record, sexual orientation, trade union membership)
  • Cross-border transfer restrictions apply when sending data to countries without adequate protection

Exemptions

  • Processing by a natural person purely for personal or household purposes
  • Processing for journalistic, literary, or artistic purposes where the responsible party has a reasonable belief it is in the public interest
  • Processing by the Cabinet or Executive Council
  • Processing that has been de-identified such that the individual cannot be re-identified

What the assessment covers

The assessment works through 20 questions across 11 duties, scored out of 238. Each answer generates the specific actions needed to close or prove that duty — and a “yes” only counts once its evidence is in, which is what makes the score defensible rather than self-declared.

The questions themselves are part of the assessment.

POPIA

Find out where you stand on POPIA

Run the assessment, get your score, and get the exact list of what to fix — with the evidence trail an auditor will ask for.