POPIA Compliance Hub
Everything South African businesses need to know about the Protection of Personal Information Act — who it applies to, what it requires, and what happens if you get it wrong.
What is POPIA?
The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It was signed in 2013, but the bulk of the Act only became enforceable on 1 July 2021 after a grace period, and it is fully in force today. POPIA sets out how any organisation may lawfully collect, use, store and share personal information, and what must happen if that information is compromised.
It's enforced by the Information Regulator, an independent body with the power to investigate complaints, issue enforcement notices, and impose fines. POPIA shares a lot of its thinking with the EU's GDPR, so if you've dealt with GDPR before, the underlying logic will feel familiar — even though the specific obligations differ.
Who does it apply to?
POPIA applies to any "responsible party" — any person or organisation, in any sector or size — that processes personal information using automated or non-automated means in South Africa. That includes:
- South African businesses of any size, from sole proprietors to large enterprises
- Government departments and public entities
- Foreign organisations that market to, or process the personal data of, people in South Africa — POPIA's reach isn't limited to companies registered locally
If your business holds employee records, customer contact details, CVs, financial information, or anything else that identifies a person, POPIA applies to you. There's no small-business exemption.
The 8 conditions for lawful processing
POPIA doesn't ban the use of personal information — it sets eight minimum conditions that must be met whenever it's processed.
What happens if you don't comply?
The Information Regulator has moved into active enforcement, and non-compliance carries real financial and, in serious cases, criminal exposure:
Beyond the direct penalties, a publicly disclosed breach usually causes more lasting damage through lost customer trust and reputational harm than the fine itself.
Getting compliant: where to start
POPIA compliance is a programme, not a once-off project. These are the foundational steps most South African businesses still need to put in place:
Not sure where your business stands with POPIA?
Book a free Cyber Readiness Assessment — it covers the security safeguards POPIA requires, with a written summary of gaps.