UNDERSTANDING WHAT CLASSIFIES AS “PERSONAL INFORMATION” IN RELATION TO THE POPI ACT

Updated: August 23, 2026
Reading Time: 12 min

Under the Protection of Personal Information Act 4 of 2013 (POPIA), “personal information” means information relating to an identifiable, living, natural person, and — where the context applies — an identifiable, existing juristic person such as a company, close corporation or trust. The Act does not stop at a single category: section 1 expressly enumerates identifying details (name, identity or passport number, e-mail, telephone, physical address), demographic descriptors (race, gender, age, religion, language, national origin, marital status), biometric information, financial and tax records, employment history, criminal record, medical and educational history, personal correspondence, and a person’s views and opinions. A separate, more restricted class — “special personal information” — covers religious or philosophical beliefs, race or ethnicity, trade-union membership, political persuasion, health or sex life, and biometric data used to uniquely identify a person, and may be processed only on the specific grounds set out in section 26 of the Act.

What “Personal Information” Means Under POPIA

POPIA is the Protection of Personal Information Act 4 of 2013, in force since 1 July 2021 with a one-year compliance grace period that ended on 1 July 2022. Section 1 of the Act defines personal information as information relating to an identifiable, living, natural person, and — where applicable — an identifiable, existing juristic person. The Act gives effect to the right to privacy in section 14 of the Constitution, and the Information Regulator — the body established under POPIA and headquartered in Braamfontein, Johannesburg — administers and enforces it.

For the definition to bite, the information must “relate to” an identifiable individual. The person must be identifiable from the information itself, or from the information combined with other information that is reasonably available to the responsible party. The connection must be more than incidental: information that happens to mention a name in passing, without tying that name to a recognisable profile, may not cross the threshold. Where the person is identifiable, the full catalogue of POPIA’s obligations — lawful processing grounds, consent, retention limits, security safeguards and breach notification — follows.

The Categories Enumerated in Section 1

Section 1 of POPIA itemises the categories that count as personal information when they relate to an identifiable person. The list is broad and overlaps; the same piece of information can sit in more than one category.

Category Examples
Identifying details Full names, identity or passport numbers, date of birth, e-mail addresses, telephone numbers, physical addresses
Demographic descriptors Race, gender, sex, pregnancy, marital status, national or ethnic origin, colour, sexual orientation, age, disability
Belief and cultural information Religion, conscience, belief, culture, language of origin
Biometric information Fingerprints, facial-recognition data, other unique biometric identifiers
Education history Schools attended, qualifications obtained, student records
Financial and tax information Banking details, income, tax numbers, financial history
Employment history Employer records, performance history, salary, disciplinary record
Health and medical history Medical records, mental-health history, blood type
Criminal record Prior convictions, arrests, pending charges
Private communications Letters, e-mails, SMS messages sent to or by the person
Views and opinions Expressions of intent, preferences, or personal views

Juristic Persons: A Narrower List Applies

POPIA extends to juristic persons — companies, close corporations, trusts and similar entities — but only a narrower set of categories applies to them, not the full natural-person list. The categories that apply to juristic persons include:

  • Registration numbers and trading names
  • Registered addresses and contact details
  • Names of directors, members or trustees where relevant
  • Financial information and financial history

Demographic categories such as race, gender, religion, language and marital status do not apply to juristic persons. A company filing with the Companies and Intellectual Property Commission (CIPC) discloses registration particulars, but the company itself does not have a religion or a sex. The juristic person must also be an “existing” juristic person — a deregistered company or a wound-up trust is outside the definition, and information about it falls back to the natural-person analysis if the individuals behind it remain identifiable.

Special Personal Information — A More Restricted Class

Section 26 of POPIA carves out a sub-category called “special personal information,” which is subject to stricter processing rules. The Act lists the following as special personal information:

  • Religious or philosophical beliefs
  • Race or ethnicity
  • Trade-union membership
  • Political persuasion or opinions
  • Health or sex life
  • Biometric information, when used to uniquely identify a person

Special personal information may generally be processed only on the specific grounds in section 26 — consent, a specific legal obligation, the information being manifestly public, or certain employment-context grounds. The general lawful-processing grounds in section 11 are not sufficient on their own, no matter how legitimate the underlying purpose. Where consent is the ground relied on, it must meet the section 1 standard: voluntary, specific and informed. A general consent to “process your personal information” does not clear the bar for special personal information, which is why many online forms treat sensitive fields with a separate, narrower opt-in.

What Falls Outside the Definition

Not everything that mentions a person is personal information. The Act and the case law have worked out several boundaries that are routinely misunderstood.

  • Information about deceased persons. The definition applies to living natural persons. Information about a deceased person is generally not protected under POPIA, unless the deceased specifically requested protection during their lifetime; once they are deceased, the protection lapses.
  • Aggregate or properly de-identified data. Statistics that cannot be re-linked to an identifiable individual are not personal information. The test is re-identification risk — if the data can be reverse-engineered back to a person, the protection still applies.
  • Information already lawfully in the public domain. Publication does not strip its classification as personal information — it remains personal information — but the public nature of the information may affect whether further processing is lawful under section 11. The fact that something has been published does not automatically authorise a new, unrelated use of it.
  • Information about a non-identifiable entity. A company whose ownership cannot be traced to any identifiable natural person is outside the definition, limited to the extent the non-identifiability holds.

Section 6 of POPIA also carves out limited exemptions, including for the National Intelligence Agency, the South African Secret Service, the South African National Defence Force, and the processing of personal information for purely household or personal activities.

Edge Cases Searchers Often Get Wrong

Some recurring scenarios sit on the definitional boundary. The table below sets out the most common points of confusion and how the Act treats them.

Scenario Is it personal information?
A generic business e-mail ([email protected]) Generally no — it does not identify a natural person
A personal e-mail that identifies the individual ([email protected]) Yes — directly identifies the data subject
Aggregate website analytics that cannot be linked back to users No — non-identifiable
A residential delivery address at unit level Yes — personal information of the recipient
The same address at building level without a unit number Probably not — may not identify a person
CCTV footage of an identifiable individual Yes — may qualify under the biometric limb
An IP address combined with a browsing record Yes, if the user is identifiable from the data
A contact shared by the data subject for one purpose Yes, but processing for a different purpose needs fresh grounds
Personal information stored on paper, USB, CCTV tape, or in the cloud Yes — the medium does not change the classification

The medium is not decisive. POPIA’s definition of “record” is deliberately broad — paper files, electronic databases, e-mails, CCTV recordings, biometric templates, and information held by third-party operators are all captured. What counts is whether the information itself identifies a person, not what kind of device it lives on.

Children and Biometric Data

Biometric data is treated as special personal information only when it is used to uniquely identify a person — not for every conceivable use of biometric data. A workplace clock-in that uses a fingerprint to identify a specific employee falls under the special-personal-information rule; a biometric measurement used in a purely statistical health study, where the data cannot be re-linked to an individual, does not.

Children’s personal information — the information of any natural person under 18 — is given extra protection under section 35 of POPIA. Responsible parties must take reasonable steps to verify the identity of the lawful guardian and to obtain proper consent before processing a child’s information, and apply greater care to the lawful-grounds analysis. The general definition of personal information still applies; the child-specific rules add safeguards on top, so a school, hospital, or online platform that processes children’s information is held to a higher standard than one that processes only adults’.

Medical and health information is treated as special personal information regardless of whether it identifies the person uniquely — the health-and-sex-life limb of section 26 captures it on its own, separate from the biometric rule.

How the Definition Feeds Into the Rest of POPIA

The definition of personal information is the gateway: once information qualifies, the Act’s full obligations apply. The architecture depends on three terms defined in section 1:

  • Data subject — the person to whom personal information relates.
  • Responsible party — the entity that determines the purpose and means of the processing (the public-facing “owner” of the data).
  • Operator — a third party that processes personal information on the responsible party’s instructions.

“Processing” is broadly defined and covers collection, storage, use, sharing, and even deletion of personal information. That breadth matters, because everyday back-office tasks — filing a record, e-mailing a client, archiving a CV — are all forms of processing. Once a piece of information is personal information, every step in its lifecycle is regulated.

Special personal information rules build on the general definition by adding stricter processing grounds. The two layers stack, not substitute. A responsible party processing health information must clear both the section 11 lawful-processing grounds and the section 26 special-information grounds before the act is lawful.

For businesses operating nationally from any of Burger Huyser Attorneys’ Gauteng branches — Linden (011 888 0246), Sandton, Pretoria, Centurion, Roodepoort, Bedfordview, Alberton, Midrand or Randfontein — the same statutory categories apply wherever the processing sits. The Information Regulator is the body for POPIA complaints and enforcement, and its guidance documents are published on the Department of Justice and Constitutional Development’s website. Where a question turns on a borderline category (a particular biometric use, children’s data, deceased-person records), the practical answer usually requires case-by-case analysis rather than a one-line reading of section 1.

Frequently Asked Questions

Does the POPI Act apply to information about a deceased person?

No. The POPI Act expressly defines personal information as information relating to a living natural person (or, where applicable, an existing juristic person). Information about a deceased person falls outside the Act unless the deceased specifically requested protection during their lifetime; once they are deceased, the protection lapses.

Is a person’s e-mail address considered personal information under POPIA?

Yes — e-mail addresses are expressly listed in section 1 as personal information when they relate to an identifiable person. A work e-mail that contains an individual’s name ([email protected]) clearly identifies that individual and is personal information; a generic inbox such as [email protected] generally does not.

What is “special personal information” under POPIA?

Special personal information is a smaller, more sensitive subset covered by section 26 — religious or philosophical beliefs, race or ethnicity, trade-union membership, political persuasion, health or sex life, and biometric information used to uniquely identify a person. It may be processed only on the limited grounds set out in section 26 (such as consent, a specific legal obligation, or where the information is manifestly public), and stricter rules apply than to ordinary personal information.

Does POPIA apply to companies or juristic persons?

Partially. The definition extends to identifiable, existing juristic persons (companies, close corporations, trusts and similar entities), but only a narrower set of categories applies to them — typically registration numbers, registered trading names, registered addresses and contact details, names of directors or members where relevant, and financial information. Demographic categories such as race, gender and religion do not apply to juristic persons.

Is information that is already in the public domain still considered personal information?

Yes — being publicly available does not change the classification of information as personal information. It may, however, affect whether processing that information is lawful under POPIA, particularly under the lawful-processing grounds in section 11. The fact that information has been published does not automatically permit further use for a new, unrelated purpose.

What about the personal information of children?

Section 35 of POPIA imposes extra obligations when processing the personal information of children (any natural person under 18). Responsible parties must take reasonable steps to verify the identity of the lawful guardian and to obtain proper consent before processing, and apply greater care to the lawful-grounds analysis. The general definition of personal information still applies; the child-specific rules add safeguards on top.

Does it matter what form the personal information is held in?

No. POPIA’s definition of “record” is deliberately broad — it covers information recorded in any form, including paper files, electronic databases, e-mails, CCTV recordings, biometric templates, and information held by third-party operators. The medium of storage does not change whether the information qualifies as personal information.

Where a business needs practical guidance on how POPIA’s definition of personal information applies to its specific processing activities — HR records, client databases, supplier information, employee monitoring, or marketing lists — Burger Huyser Attorneys’ commercial and cyber-law capability can help route the question to the right practitioner. The firm operates from its head office in Linden, Randburg (011 888 0246) and across its Gauteng branches; contact the office to direct a POPIA-related enquiry to the appropriate practitioner.

General Information Disclaimer: This article summarises the definition of “personal information” under the Protection of Personal Information Act 4 of 2013 for general informational purposes. It is not legal advice for any specific situation, and POPIA’s interaction with other legislation (such as the Consumer Protection Act, the National Credit Act, the Electronic Communications and Transactions Act, or industry-specific codes) requires careful case-by-case analysis. For specific questions about processing personal information in a South African context, consult a qualified attorney, and confirm current requirements with the Information Regulator.

NEED TOP LEGAL SUPPORT IN SOUTH AFRICA? CONTACT OUR LAWYERS TODAY.

Contact our team of experienced law attorneys at Burger Huyser Attorneys to assist you in all matters and procedures.

CONTACT DETAILS

DISCIPLINARY HEARINGS