Comprehensive Privacy Law
Protection of Personal Information Act, 2013
South Africa · July 1, 2020 (most substantive provisions)
Verify detailsPOPIA does not use the GDPR Article 3 model. Section 3(1) instead applies the Act wherever the responsible party is domiciled in South Africa, OR — if not domiciled there — 'makes use of automated or non-automated means in the Republic' (unless those means are used only to forward information through the country) — closer to the old pre-GDPR EU Directive 95/46/EC 'means/equipment' test than to a targeting test. Modeled here as an established-presence trigger since 'uses processing means located there' is the closest fit. Section 6 excludes purely personal/household activity, properly de-identified data, and processing by public bodies for national security/defense/law enforcement (with safeguards, not a blanket carve-out). No small-business, nonprofit, or sector-specific exemption.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.