Description

Enforcement of Protection of Personal Information Act (POPIA)

On 1 July 2021, the Protection of Personal Information (POPIA) was fully implemented after Section 58(2) came into effect. Adopted in 2013, the POPIA applies to public and private “responsible parties” that process personal information (e.g. collect, receive or use data). The POPIA requires entities to obtain consent for the processing of personal information, enabling justifications such as contractual performance, legal obligations and legitimate interests of the data subject. Data subjects can withdraw consent and have the right to access, correct and delete their data, among others.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2009-08-24
under deliberation

On 24 August 2009, the Protection of Personal Information Bill (B9-2009) was introduced to the Nati…

2013-08-20
adopted

On 20 August 2013, the Protection of Personal Information Bill (B9-2009) was adopted after being pa…

2020-07-01
in force

The operative provisions of the Protection of Personal Information Act (2013) including a new data …

2021-06-22
adopted

The South African Information Regulator published the guidance on awarding exemptions from the cond…

2021-06-22
adopted

The Information Regulator has confirmed that the deadline for the registration of Information offic…

2021-07-01
in force

On 1 July 2021, the Protection of Personal Information (POPIA) was fully implemented after Section …

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Any
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
User notification requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
Preventive security requirement
Responsive security requirement
Purpose/processing limitation
Data storage/retention obligation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
User consent: Permit user opt-out
User notification requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: religious beliefs: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: biometric: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: ethnicity: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: political orientation: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: sexual orientation: data processing
Regulatory tool
Purpose/processing limitation
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data: information pertaining to minors: data processing
Regulatory tool
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1
personal data (all forms): transfer: cross-border
Regulatory tool
Adequacy decision requirement
Creation of other oversight body
Sanctions
Fine
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): storage (any form)

personal data (all forms): data processing

personal data: religious beliefs: data processing

personal data: biometric: data processing

personal data: ethnicity: data processing

personal data: political orientation: data processing

personal data: sexual orientation: data processing

personal data: information pertaining to minors: data processing

personal data (all forms): transfer: cross-border

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.