WHAT IS THE POPI ACT AND WHAT IS ITS PURPOSE?

The Protection of Personal Information Act (POPIA, Act 4 of 2013) is the South African statute that regulates how the personal information of individuals is collected, stored, processed, shared, and destroyed by businesses, government, and other responsible parties. Its stated purpose, set out in Section 2 of the Act, is to give effect to the constitutional right to privacy contained in section 14 of the Constitution of the Republic of South Africa, to regulate the processing of personal information in a way that protects that right while balancing the right to access information, and to establish the Information Regulator as the independent supervisory body. The Act was signed into law on 26 November 2013 and reached full commencement in 2025–2026 after a phased rollout that began in 2014.
What POPIA Is, in One Sentence
POPIA — the Protection of Personal Information Act 4 of 2013 — is South Africa’s primary data-protection statute. The Act’s full long title sets out its reach: “To promote the protection of personal information processed by public and private bodies; to introduce certain conditions so as to establish minimum requirements for the processing of personal information.” POPIA applies to both public and private bodies that process personal information inside South Africa, and to parties outside South Africa that process personal information about South African data subjects using automated or non-automated means located in South Africa.
The Purpose of POPIA: Section 2, Unpacked
Section 2 of the Act sets out four overlapping purposes, each responding to a different aspect of the right to privacy. Read together they explain not only what the Act does, but why it was ever needed.
- Giving effect to the constitutional right to privacy. Section 14 of the Constitution protects everyone against the unlawful collection, retention, dissemination, and use of personal information. POPIA is the operational statute that turns that constitutional right into enforceable duties on the people who handle that information, subject to justifiable limitations aimed at balancing the right to privacy against other rights and protecting important interests such as the free flow of information within the Republic and across international borders.
- Regulating the processing of personal information. The Act sets out the ground rules — the eight conditions for lawful processing of personal information — for how personal information may be lawfully handled by responsible parties, in harmony with international standards.
- Providing persons with rights and remedies. The Act gives data subjects enforceable rights against processing that is not in accordance with the Act, including rights of access, correction, and deletion.
- Establishing the Information Regulator. POPIA creates an independent supervisory body — the Information Regulator — with voluntary and compulsory measures to ensure respect for, and to promote, enforce, and fulfil, the rights the Act protects.
Why POPIA Was Needed: The Problem It Solved
Before POPIA, South Africa had no single comprehensive data-protection statute. Privacy was protected piecemeal through the common law, the Constitution, and a patchwork of sector-specific laws — the Electronic Communications and Transactions Act 25 of 2002 for certain electronic data, the National Credit Act 34 of 2005 for credit information, and the common-law right to privacy recognised in Trinity Asset Management (Pty) Ltd v Grindstone Investments 114 (Pty) Ltd 2018 (2) SA 113 (CC).
Section 14 of the Constitution and the common-law right to privacy had existed for years but had no dedicated enforcement body and no detailed compliance framework for the way data is actually handled in modern business. POPIA closes that gap by giving the right teeth: an enforceable compliance framework, a dedicated regulator, administrative fines of up to R10 million for serious contraventions, and imprisonment of up to 10 years for the most serious offences. For Gauteng-based businesses — particularly the firms, employer organisations, and professional practices that operate across Burger Huyser Attorneys’ footprint — that step change is what makes POPIA a daily compliance task rather than a constitutional abstraction. The firm’s commercial practice, headquartered in Linden, Randburg, advises Gauteng clients on exactly this kind of POPIA-compliant drafting.
Who and What POPIA Covers
| Term | Definition |
|---|---|
| Responsible party | Anyone who determines the purpose and means of processing personal information (the data “controller” in EU GDPR language). |
| Operator | Anyone who processes personal information on behalf of the responsible party (the data “processor”). |
| Data subject | The natural person to whom the personal information relates. |
| Personal information | Broadly defined to include anything that can identify a living person: name, ID number, contact details, financial history, biometric data, opinions about the person, and even correspondence that identifies them. |
| Special personal information | A heightened category covering information about a person’s race, ethnicity, political persuasion, religious beliefs, trade union membership, health, sex life, and criminal behaviour. Processing this category requires a higher consent threshold or a specific statutory ground. |
The Eight Conditions for Lawful Processing
Section 2 says POPIA will “regulate the manner in which personal information may be processed.” Chapter 3, Part A is where that promise is kept — eight conditions set the minimum threshold for lawful processing of personal information. They are also the practical hook underneath the “what is its purpose” question: an organisation that ticks each box is, in broad terms, compliant.
| # | Condition | Section(s) | Core requirement |
|---|---|---|---|
| 1 | Accountability | Section 8 | The responsible party must ensure compliance and be able to demonstrate it. |
| 2 | Processing limitation | Sections 9–12 | Processing must be done lawfully and in a reasonable manner that does not infringe on the data subject’s privacy. |
| 3 | Purpose specification | Sections 13–14 | The purpose for which information is collected must be specific, explicitly defined, and lawful. |
| 4 | Further-processing limitation | Section 15 | Further processing must be compatible with the original purpose. |
| 5 | Information quality | Section 16 | Information must be complete, accurate, not misleading, and kept up to date. |
| 6 | Openness | Sections 17–18 | The data subject must be told what is being collected and why (typically through a privacy notice / POPI policy). |
| 7 | Security safeguards | Sections 19–22 | The integrity and confidentiality of personal information must be protected against loss, damage, or unlawful access. |
| 8 | Data-subject participation | Sections 23–25 | Data subjects must be able to access, correct, or delete their personal information on request. |
The Information Regulator: The Body That Enforces the Act
POPIA establishes the Information Regulator as an independent body, accountable to the National Assembly, in section 39 of the Act and the regulations made under it. The Regulator sits in Johannesburg and serves as the supervisory authority for both POPIA and the Promotion of Access to Information Act 2 of 2000 (PAIA). Its powers include receiving complaints, conducting investigations, issuing enforcement notices, and referring serious matters to the Enforcement Committee.
The Regulator publishes codes of conduct, guidelines, and frequently asked questions on its public-facing communications, and publishes its contact details through official channels. In Gauteng, the practical reality is that POPIA enforcement and the bulk of large-scale data-processing activity both sit in the same province: complaints, enforcement notices, and the work of the Enforcement Committee all flow through the Regulator’s Johannesburg office, which is why Gauteng-based businesses tend to feel POPIA’s day-to-day weight most directly.
Penalties for Non-Compliance
| Type of sanction | Maximum exposure | Source |
|---|---|---|
| Administrative fine (Information Regulator) | Up to R10 million | Section 109 (administrative penalties) |
| Criminal conviction — most serious offences | Imprisonment up to 10 years, or a fine, or both | Section 107 (criminal offences) |
| Civil liability to data subjects who suffer harm | Damages as awarded by a competent court | Common law and Act remedies |
The Regulator also has power to issue enforcement notices, compel remediation, and refer matters to the Enforcement Committee — a stepped process that often resolves into a settlement or compliance direction before any criminal prosecution is launched.
How POPIA Differs From PAIA
POPIA is not the same as the Promotion of Access to Information Act 2 of 2000 (PAIA), even though the same regulator administers both Acts.
| POPIA | PAIA | |
|---|---|---|
| Full title | Protection of Personal Information Act 4 of 2013 | Promotion of Access to Information Act 2 of 2000 |
| Core purpose | Governs how personal information is processed and protected. | Governs how a person may request access to records held by public and private bodies. |
| Administered by | Information Regulator | Information Regulator |
Practical Implications for Businesses and Individuals
For businesses, POPIA compliance translates into a handful of concrete obligations:
- Publish a POPIA-compliant privacy notice (typically called a POPI policy).
- Register the information officer with the Information Regulator in terms of section 55, where applicable.
- Appoint or designate an information officer and train staff.
- Have written operator agreements in place with any third-party processor.
- Respond to data-subject access and correction requests within the timeframes the Act prescribes.
For individuals, POPIA gives meaningful, enforceable rights: the right to be told what personal information is collected, to access it, to correct or delete it, and to object to its processing in certain circumstances. Direct marketing by electronic means is specifically restricted under section 69 of the Act — consent must be in place, with a defined exception for marketing a responsible party’s own similar products to existing customers, subject to a meaningful opportunity to opt out both at the point of collection and on each communication.
POPIA in Gauteng: Where the Practical Work Lands
POPIA is national law, so the substantive rules do not vary by province. But the practical enforcement and the bulk of large-scale data-processing activity both sit in Gauteng. The Information Regulator — the body POPIA creates to supervise and enforce the Act — is based in Johannesburg, and complaints, enforcement notices, and the Enforcement Committee all flow through that office. POPIA itself gives effect to section 14 of the Constitution, the right to privacy, which is enforced by the South African courts against any responsible party that processes personal information unlawfully; POPIA does not create that right, it operationalises it.
For Gauteng-based businesses — and in particular for the firms, employer organisations, and professional practices that operate across Burger Huyser Attorneys’ footprint — the daily work of compliance means publishing a POPIA-compliant privacy notice, appointing or designating an information officer, ensuring operator agreements are in place with any third-party processor, and answering data-subject access and correction requests within the timeframes the Act prescribes. Burger Huyser Attorneys’ commercial practice advises Gauteng clients on POPIA-compliant drafting of privacy notices, data-processing clauses for commercial and employment contracts, and operator agreements. The firm’s head office in Linden, Randburg (49 First Avenue, 011 888 0246) is the practical first point of contact, with branch access across Centurion, Pretoria, Sandton, Roodepoort, Bedfordview, Alberton, and Midrand for clients who prefer a regional meeting.
POPIA compliance touches almost every South African business that handles customer, employee, or supplier information, and the practical questions — what to put in a privacy notice, whether a marketing campaign needs fresh consent, how to respond to a data-subject access request, what to do if the Information Regulator sends an enquiry — are exactly the kind of work Burger Huyser Attorneys’ commercial practice handles. If you need help putting a POPIA-compliant framework in place for your business or responding to a Regulator complaint, contact the firm’s Linden head office on 011 888 0246 or visit 49 First Avenue, Linden, Randburg; the firm’s commercial attorneys can also meet at any of its Gauteng branches. Burger Huyser carries a 4.8/5 average rating across 250+ Google reviews (Trustindex verified “Top Rated Law Firm in South Africa”).
Frequently Asked Questions
When did the POPI Act come into force?
POPIA was signed into law on 26 November 2013. Certain sections — notably those establishing the Information Regulator — came into force on 11 April 2014. The bulk of the Act’s substantive obligations (sections 2 to 38, and 55 to 109) were brought into force on 1 July 2020, with the remaining provisions, including section 58(2), taking effect on 1 July 2021. The remaining sections, including those dealing with administrative fines, were brought into force by presidential proclamation in 2025, with full effect by April 2026.
Does POPIA apply to small businesses?
Yes. POPIA applies to any public or private body that processes personal information, regardless of size. The compliance burden scales with what personal information a business processes, but the duty to comply is the same. A sole proprietor who collects customer contact details is still a responsible party under the Act.
What counts as personal information under POPIA?
Personal information is any information that identifies a living natural person, including (but not limited to) name, identity number, address, contact details, financial, employment or medical history, biometric data, opinions about the person, and even personal correspondence. Some categories — race, religion, health, criminal behaviour — are treated as special personal information with a higher threshold for processing.
Do I need a POPIA policy?
If you collect or process personal information in the course of your business or organisation, yes. Section 18 of the Act requires responsible parties to maintain a documented policy on how personal information is processed. The standard practice is a publicly available privacy notice (often called a POPI policy) on the website and at reception.
Where do I complain if my personal information is being misused?
Complaints may be lodged with the Information Regulator, the South African data-protection authority, whose head office is in Johannesburg. The Regulator can investigate, mediate, and issue enforcement notices. Civil claims for damages may also be pursued through the courts.
Is POPIA the same as GDPR?
No. POPIA is South Africa’s domestic data-protection statute and applies to processing that falls within its jurisdictional scope. GDPR is the European Union’s General Data Protection Regulation. The two regimes are similar in spirit but differ in detail, including the legal grounds for processing, the age of consent for minors, breach-notification timelines, and cross-border transfer rules. South African businesses that handle EU residents’ data usually have to comply with both.
General Information Disclaimer: This article explains the general framework of the Protection of Personal Information Act 4 of 2013 and is general information, not legal advice for a specific compliance situation. POPIA compliance turns on the facts of what personal information a particular business or organisation processes, and businesses with compliance questions or individuals with complaints should consult a qualified attorney for advice on their own situation.
NEED TOP LEGAL SUPPORT IN SOUTH AFRICA? CONTACT OUR LAWYERS TODAY.
Contact our team of experienced law attorneys at Burger Huyser Attorneys to assist you in all matters and procedures.
CONTACT DETAILS

