Jurisdiction Guides / Africa
South Africa Privacy & Data Protection Laws
Every regime below can apply to a business handling South Africa residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
POPIA does not use the GDPR Article 3 model. Section 3(1) instead applies the Act wherever the responsible party is domiciled in South Africa, OR — if not domiciled there — 'makes use of automated or non-automated means in the Republic' (unless those means are used only to forward information through the country) — closer to the old pre-GDPR EU Directive 95/46/EC 'means/equipment' test than to a targeting test. Modeled here as an established-presence trigger since 'uses processing means located there' is the closest fit. Section 6 excludes purely personal/household activity, properly de-identified data, and processing by public bodies for national security/defense/law enforcement (with safeguards, not a blanket carve-out). No small-business, nonprofit, or sector-specific exemption. The Information Regulator has become materially more active since 2023, issuing enforcement notices and pursuing administrative fines.
Children & Minors Protections · 1
South Africa inverts the usual structure. s. 34 is a flat PROHIBITION — a responsible party may not process the personal information of a child at all — and s. 35 then lists the grounds that lift it: prior consent of a competent person (in practice a parent or guardian), an authorisation granted by the Information Regulator under s. 27(2), necessity for establishing, exercising or defending a right or obligation in law, compliance with an obligation of international public law, historical, statistical or research purposes serving the public interest with appropriate safeguards, or information the child deliberately made public with a competent person's consent. Starting from prohibition rather than from conditional permission changes the compliance posture: the question is not 'have we obtained consent?' but 'which s. 35 ground are we relying on, and can we evidence it?' The Regulator can only grant a s. 27(2) authorisation where processing is in the public interest and appropriate safeguards exist. A child is anyone under 18.
Cross-Border Data Transfer · 1
s. 72 bars sending personal information to a recipient in a foreign country unless one of the listed grounds applies. The main three are that the recipient is subject to a law, binding corporate rules, or a binding agreement providing an adequate level of protection; the remaining grounds are consent, necessity for a contract with the data subject, a contract concluded in the data subject's interest, and benefit to the data subject where consent is impracticable. 'Adequate' has a defined content: it must uphold principles substantially similar to POPIA's conditions for lawful processing AND include an onward-transfer restriction substantially similar to s. 72 itself — so a transfer agreement that secures the data at the first hop but says nothing about the recipient's own subprocessors does not satisfy the section. South Africa maintains no adequacy list, so the assessment is the exporter's to make and document.
Data Security & Breach Notification · 1
South Africa has no materiality threshold. Where there are reasonable grounds to believe that an unauthorised person has unlawfully accessed or acquired personal information, s. 22 requires notifying BOTH the Information Regulator and the affected data subjects — even a single record, and even where no harm is likely. That makes POPIA more reportable than almost every other regime in this dataset, and a business filtering incidents through a GDPR-style risk test will systematically under-report in South Africa. Notification must be as soon as reasonably possible after discovery, subject only to the legitimate needs of law enforcement or of determining the scope of the compromise and restoring system integrity — no fixed hour count. The Regulator publishes a prescribed form that must be used. Non-compliance with s. 22 is an interference with the protection of personal information under s. 73.
Other Africa jurisdictions