ZASouth AfricaData protection law

POPIA

Protection of Personal Information Act

South Africa's data protection law works through eight conditions for lawful processing. It is particularly strict on direct marketing — and unusually blunt about sanctions.

POPIA at a glance

In force
Fully applicable since 1 July 2021
Supervision
Information Regulator
Penalty
Up to ZAR 10 m or imprisonment of up to 10 years
Model
Consent, strict for direct marketing

What is POPIA?

The Protection of Personal Information Act governs the processing of personal data in South Africa through eight conditions — among them purpose limitation, data minimisation, transparency and security. It is enforced by the Information Regulator.

Two points stand out internationally. First, the act also protects the data of legal entities, not only of natural persons. Second, alongside fines of up to ten million rand, the sanctions catalogue provides for imprisonment of up to ten years.

Who does POPIA apply to?

Processing in South Africa

Anyone based in the country, or using means of processing there, is covered.

Company data too

Unlike the GDPR and the LGPD, POPIA expressly protects the data of legal entities as well.

Direct marketing regulated separately

Electronic direct marketing to people who are not yet customers requires prior consent.

What does POPIA require of a website?

1

Lawfulness and purpose limitation

Data may only be collected for a defined, explicit purpose — and not kept longer than necessary.

2

Consent for direct marketing

Electronic marketing is subject to a consent requirement with a prescribed procedure.

3

Disclosure of processing

Data subjects have to know who processes what, for which purpose, and whether data goes abroad.

4

Security measures

Appropriate measures against loss and unauthorised access are mandatory; incidents have to be reported.

5

Appoint a responsible person

Every responsible party needs an Information Officer registered with the Regulator.

The solution

How does Aiara meet POPIA?

What POPIA requires of a website largely matches the European approach — Aiara meets it with the same configuration.

Consent before setting

Marketing and analytics scripts load only after agreement. That also covers the strictest POPIA requirement, the one on direct marketing.

Purposes visibly separated

Every category names provider, purpose and retention period — making purpose limitation traceable for data subjects rather than merely asserted.

A provable record

The Information Regulator asks for evidence in a review. Aiara logs every decision with time and scope.

Disclosures about transfers abroad

The generated privacy policy sets out which services transmit data abroad — one of the eight conditions.

Withdrawal at any time

Permanent access to the settings allows withdrawal without having to make contact first.

Frequently asked questions about POPIA

Official sources

This page summarises the legal position in plain language and is no substitute for legal advice.