POPIA
Market regime · Protection of Personal Information Act 4 of 2013 (South Africa)
Republic of South Africa
South Africa
2013; in force July 2020, enforcement from July 2021
Information Regulator (South Africa)
You process personal information in South Africa, or use means located there
Curated, versioned & cross-mapped
The obligation, plainly.
POPIA structures data protection as eight conditions for lawful processing, from accountability and purpose specification through security safeguards to data-subject participation, with extra rules for special personal information, children's data and direct marketing.
It carries distinctive machinery: every organisation designates an information officer registered with the Information Regulator, and cross-border transfers run through section 72's grounds. The Regulator has moved from guidance to enforcement, which is why the conditions need evidence, not intentions.
Where programmes are tested.
The eight conditions
Accountability, processing limitation, purpose specification, further-processing limits, information quality, openness, security safeguards and data-subject participation, each demonstrable.
The information officer
Designated, registered with the Regulator, and actually running the compliance programme.
Special information and marketing
Stricter grounds for special and children's information, and consent discipline for direct marketing.
Section 72 transfers
Cross-border transfers only on the section's grounds: adequate protection, contract, consent or necessity.
Curated once, evidenced continuously.
- POPIA's conditions are curated and cross-mapped to the same privacy control set as the NDPA and GDPR, so a programme built once answers all three regulators.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
POPIA, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who does POPIA apply to?
Any responsible party domiciled in South Africa, and those outside it that use means in the country to process personal information. It covers juristic persons too, companies' information as well as individuals', which is broader than GDPR-style regimes.
What is an information officer and do we need one?
The accountable person for POPIA compliance, by default the head of the organisation, delegable, and registered with the Information Regulator before processing duties bite. It is an operative duty: the officer develops, implements and monitors the compliance framework.
What are the penalties under POPIA?
Administrative fines up to R10 million, and criminal liability with imprisonment for the most serious offences such as obstructing the Regulator or unlawful account-number processing. The Regulator has issued enforcement notices and fines, so the risk is practical, not theoretical.
How does POPIA differ from GDPR?
The architecture rhymes, conditions instead of principles, an information officer instead of a DPO, but POPIA covers juristic persons, handles direct marketing and account numbers with specific offences, and runs transfers through section 72's own grounds. Cross-mapping handles the overlap; the differences are why it is curated as its own framework.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.