POPIA
Protection of Personal Information Act
South Africa's data protection law works through eight conditions for lawful processing. It is particularly strict on direct marketing — and unusually blunt about sanctions.
POPIA at a glance
- In force
- Fully applicable since 1 July 2021
- Supervision
- Information Regulator
- Penalty
- Up to ZAR 10 m or imprisonment of up to 10 years
- Model
- Consent, strict for direct marketing
What is POPIA?
The Protection of Personal Information Act governs the processing of personal data in South Africa through eight conditions — among them purpose limitation, data minimisation, transparency and security. It is enforced by the Information Regulator.
Two points stand out internationally. First, the act also protects the data of legal entities, not only of natural persons. Second, alongside fines of up to ten million rand, the sanctions catalogue provides for imprisonment of up to ten years.
Who does POPIA apply to?
Processing in South Africa
Anyone based in the country, or using means of processing there, is covered.
Company data too
Unlike the GDPR and the LGPD, POPIA expressly protects the data of legal entities as well.
Direct marketing regulated separately
Electronic direct marketing to people who are not yet customers requires prior consent.
What does POPIA require of a website?
Lawfulness and purpose limitation
Data may only be collected for a defined, explicit purpose — and not kept longer than necessary.
Consent for direct marketing
Electronic marketing is subject to a consent requirement with a prescribed procedure.
Disclosure of processing
Data subjects have to know who processes what, for which purpose, and whether data goes abroad.
Security measures
Appropriate measures against loss and unauthorised access are mandatory; incidents have to be reported.
Appoint a responsible person
Every responsible party needs an Information Officer registered with the Regulator.
How does Aiara meet POPIA?
What POPIA requires of a website largely matches the European approach — Aiara meets it with the same configuration.
Consent before setting
Marketing and analytics scripts load only after agreement. That also covers the strictest POPIA requirement, the one on direct marketing.
Purposes visibly separated
Every category names provider, purpose and retention period — making purpose limitation traceable for data subjects rather than merely asserted.
A provable record
The Information Regulator asks for evidence in a review. Aiara logs every decision with time and scope.
Disclosures about transfers abroad
The generated privacy policy sets out which services transmit data abroad — one of the eight conditions.
Withdrawal at any time
Permanent access to the settings allows withdrawal without having to make contact first.
Frequently asked questions about POPIA
Official sources
This page summarises the legal position in plain language and is no substitute for legal advice.