Description

Implementation of Protection of Personal Information Act (POPIA) after grace period

The operative provisions of the Protection of Personal Information Act (2013) including a new data protection regime come into effect after a one-year grace period following proclamation No. R21 in 2019. The Act introduces the rights to rectify, delete and access personal data and establishes rules for storing and transferring in other countries of personal data. Further, the Act specifies the limitations to processing certain categories of personal data. Finally, the Act establishes the "Information Regulator" as the supervisor body that should advise and monitor on data protection matters and enforce the prescriptions of the Act.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2009-08-24
under deliberation

On 24 August 2009, the Protection of Personal Information Bill (B9-2009) was introduced to the Nati…

2013-08-20
adopted

On 20 August 2013, the Protection of Personal Information Bill (B9-2009) was adopted after being pa…

2020-07-01
in force

The operative provisions of the Protection of Personal Information Act (2013) including a new data …

2021-06-22
adopted

The South African Information Regulator published the guidance on awarding exemptions from the cond…

2021-06-22
adopted

The Information Regulator has confirmed that the deadline for the registration of Information offic…

2021-07-01
in force

On 1 July 2021, the Protection of Personal Information (POPIA) was fully implemented after Section …

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Any
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
User notification requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
Preventive security requirement
Responsive security requirement
Purpose/processing limitation
Data storage/retention obligation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
User consent: Permit user opt-out
User notification requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: religious beliefs: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: biometric: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: ethnicity: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: political orientation: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: sexual orientation: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: information pertaining to minors: data processing
Regulatory tool
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): transfer: cross-border
Regulatory tool
Adequacy decision requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): storage (any form)

personal data (all forms): data processing

personal data: religious beliefs: data processing

personal data: biometric: data processing

personal data: ethnicity: data processing

personal data: political orientation: data processing

personal data: sexual orientation: data processing

personal data: information pertaining to minors: data processing

personal data (all forms): transfer: cross-border

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.