{"id":363,"date":"2022-04-14T10:37:03","date_gmt":"2022-04-14T08:37:03","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=23047"},"modified":"2025-06-26T13:03:56","modified_gmt":"2025-06-26T11:03:56","slug":"south-africa-popia-protection-of-personal-information-act-overview","status":"publish","type":"knowledge","link":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/","title":{"rendered":"South Africa\u2019s Protection of Personal Information Act (POPIA): A complete guide"},"content":{"rendered":"\n\n<p>South Africa\u2019s Protection of Personal Information Act (POPIA) is a legal framework to protect the country\u2019s residents from harm by protecting their personal information. It is enforced by the country\u2019s Information Regulator. It is sometimes referred to as POPIA or the POPI Act, but POPIA is preferred by regulators and the South African government. POPI is more commonly used as a synonym for data protection, rather than specifically referring to the legal framework.<\/p>\n<p>Who is affected by POPIA depends on context. It affects both those providing and processing personal information. On a day to day basis, it would likely affect companies and other organizations more, as they must achieve and maintain compliance with POPIA. Most individuals wouldn\u2019t be actively affected unless notified of a data breach or other violation affecting their personal information.<\/p>\n<p>POPIA is distinct from the Promotion of Access to Information Act (<a href=\"https:\/\/www.gov.za\/documents\/promotion-access-information-act\" target=\"_blank\" rel=\"noopener\">PAIA<\/a>), which is even older, having been passed in 2000. PAIA provides the constitutional right of access to information held by the South African government or by private organization, if it is required to protect or exercise individuals\u2019 rights. PAIA is enforced by the South African Human Rights Commission.<\/p>\n<p>South Africa\u2019s POPIA went into full effect in 2020, though it had been rolled out in sections starting from when it received Presidential assent seven years earlier. Enforcement then began in 2021. In modern terms, it is one of the older data privacy laws, predating the European Union\u2019s General Data Protection Regulation (GDPR) by several years.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-south-africa-s-protection-of-personal-information-act-popia\">What is South Africa\u2019s Protection of Personal Information Act (POPIA)?<\/h2>\n\n\n<p>The <a href=\"https:\/\/popia.co.za\/\" target=\"_blank\" rel=\"noopener\">Protection of Personal Information Act (POPIA)<\/a> is South Africa\u2019s federal data protection law to protect people\u2019s privacy, which is considered a human right. The Act outlines when it is legal for one entity, like a company, to process another entity\u2019s personal information, like that of an individual.<\/p>\n<p>POPIA received parliamentary assent on November 19th, 2013, however, the Act did not fully go into effect immediately. Sections have gone into effect since 2013, but a number of key sections didn\u2019t go into effect until July 1st, 2020, which the President proclaimed to be the date of commencement. Organizations had 12 months to work toward compliance with the Act, and enforcement began on July 1st, 2021.<\/p>\n<p>The Information Regulator was established on December 1st, 2016, and is responsible for enforcing POPIA. It handles both investigations of alleged violations as well as penalties where noncompliance has been demonstrated. The Information Regulator reports to the South African Parliament.<\/p>\n<p>POPIA has 12 Chapters, containing 115 Sections. The rights of data subjects are covered in <a href=\"https:\/\/popia.co.za\/section-5-rights-of-data-subjects\/\" target=\"_blank\" rel=\"noopener\">Section 5<\/a>. <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/\" target=\"_blank\" rel=\"noopener\">Chapter 3<\/a> of POPIA covers Conditions for Lawful Processing. <a href=\"https:\/\/popia.co.za\/section-11-consent-justification-and-objection\/\" target=\"_blank\" rel=\"noopener\">Section 11<\/a> outlines the conditions for data subjects\u2019 consent or objection, and other legal justifications and responsibilities for data processing:<\/p>\n<ul>\n<li>with the consent of the data subject or a competent person where the data subject is a child<\/li>\n<li>the processing is necessary to perform or conclude a contract, of which the data subject is a party<\/li>\n<li>to comply with a legal obligation of the responsible party (that one doing the processing)<\/li>\n<li>protection of legitimate interest of the data subject<\/li>\n<li>required for performance of public law duty by a public body<\/li>\n<li>to pursue legitimate interests of the responsible party or of a third party to whom the information is supplied<\/li>\n<\/ul>\n<p>Additionally, the responsible party bears the burden of proof for the data subject\u2019s (or competent person as representative\u2019s) consent, and the data subject or competent person may withdraw consent at any time.<\/p>\n<p>Data subjects may also object to the processing of their personal information at any time on reasonable grounds, via the prescribed manner, as long as prevention or termination of that data processing is not prevented by active legislation.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conditions-for-lawful-data-processing-under-south-africa-s-protection-of-personal-information-act\">Conditions for lawful data processing under South Africa\u2019s Protection of Personal Information Act?<\/h2>\n\n\n<p><a href=\"https:\/\/popia.co.za\/section-4-lawful-processing-of-personal-information\/\" target=\"_blank\" rel=\"noopener\">Section 4<\/a> outlines the lawful conditions of data processing:<\/p>\n<ul>\n<li>Accountability (<a href=\"https:\/\/popia.co.za\/section-8-responsible-party-to-ensure-conditions-for-lawful-processing\/\" target=\"_blank\" rel=\"noopener\">Section 8<\/a>)<\/li>\n<li>Processing limitation (<a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-2-processing-limitation\/\" target=\"_blank\" rel=\"noopener\">Sections 9-12<\/a>)<\/li>\n<li>Purpose specification (sections <a href=\"https:\/\/popia.co.za\/section-13-collection-for-specific-purpose\/\" target=\"_blank\" rel=\"noopener\">13<\/a> and <a href=\"https:\/\/popia.co.za\/section-14-retention-and-restriction-of-records\/\" target=\"_blank\" rel=\"noopener\">14<\/a>)<\/li>\n<li>Further processing limitation (<a href=\"https:\/\/popia.co.za\/section-15-further-processing-to-be-compatible-with-purpose-of-collection\/\" target=\"_blank\" rel=\"noopener\">Section 15<\/a>)<\/li>\n<li>Information quality (<a href=\"https:\/\/popia.co.za\/section-16-quality-of-information\/\" target=\"_blank\" rel=\"noopener\">Section 16<\/a>)<\/li>\n<li>Openness (Sections <a href=\"https:\/\/popia.co.za\/section-17-documentation\/\" target=\"_blank\" rel=\"noopener\">17<\/a> and <a href=\"https:\/\/popia.co.za\/section-18-notification-to-data-subject-when-collecting-personal-information\/\" target=\"_blank\" rel=\"noopener\">18<\/a>)<\/li>\n<li>Security safeguards (Sections <a href=\"https:\/\/popia.co.za\/section-19-security-measures-on-integrity-and-confidentiality-of-personal-information\/\" target=\"_blank\" rel=\"noopener\">19<\/a> to <a href=\"https:\/\/popia.co.za\/section-22-notification-of-security-compromises\/\" target=\"_blank\" rel=\"noopener\">22<\/a>)<\/li>\n<li>Data subject participation (Sections <a href=\"https:\/\/popia.co.za\/section-23-access-to-personal-information\/\" target=\"_blank\" rel=\"noopener\">23<\/a> to <a href=\"https:\/\/popia.co.za\/section-25-manner-of-access\/\" target=\"_blank\" rel=\"noopener\">25<\/a>)<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-does-south-africa-s-protection-of-personal-information-act-apply-to\">Who does South Africa\u2019s Protection of Personal Information Act apply to?<\/h2>\n\n\n<p>POPIA applies to \u201cany natural or juristic person who processes personal information\u201d by \u201cautomated or non-automated means\u201d (<a href=\"https:\/\/popia.co.za\/section-3-application-and-interpretation-of-act\/\" target=\"_blank\" rel=\"noopener\">Section 3<\/a>). So it does apply to individuals, though more commonly to companies, other organizations, and the government.<\/p>\n<p>Note that under the definitions in <a href=\"https:\/\/popia.co.za\/section-1-definitions\/\" target=\"_blank\" rel=\"noopener\">Section 1<\/a>, the \u201cresponsible party\u201d is \u201ca public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information\u201d.<\/p>\n<p>Also per <a href=\"https:\/\/popia.co.za\/section-3-application-and-interpretation-of-act\/\" target=\"_blank\" rel=\"noopener\">Section 3<\/a>, POPIA applies to responsible parties both \u201cdomiciled in the Republic\u201d, or not, i.e. POPIA is extra-territorial. The key consideration is if data subjects are located in South Africa, not whether the entity that is processing their data is located there.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-exclusions-from-south-africa-s-protection-of-personal-information-act\">Exclusions from South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p><a href=\"https:\/\/popia.co.za\/section-6-exclusions\/\" target=\"_blank\" rel=\"noopener\">Section 6<\/a> outlines exclusions from POPIA compliance requirements, which are fairly common in comparison to other data privacy laws:<\/p>\n<ul>\n<li>the data processing is for \u201cpersonal or household activity\u201d, i.e. not commercial<\/li>\n<li>the data has been anonymized sufficiently that it can\u2019t be de-anonymized<\/li>\n<li>if there are issues of national security, including public safety or combatting terrorism<\/li>\n<li>if the data processing is in service of the functions of law enforcement<\/li>\n<li>if the data processing is performed by government agencies, \u201cby the Cabinet and its committees or the Executive Council of a province\u201d<\/li>\n<li>if the data processing is in service of judicial functions of a court<\/li>\n<\/ul>\n<p><a href=\"https:\/\/popia.co.za\/section-7-exclusion-for-journalistic-literary-or-artistic-purposes\/\" target=\"_blank\" rel=\"noopener\">Section 7<\/a> has some further exclusions and specific requirements relating to \u201cjournalistic, literary or artistic expression\u201d. This section helps enable freedom of expression and the freedom of the press, while ensuring responsible actions, e.g. adherence to \u201cdomestic and international standards, and to professional codes of ethics.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-consumers-rights-under-south-africa-s-protection-of-personal-information-act\">What are consumers\u2019 rights under South Africa\u2019s Protection of Personal Information Act?<\/h2>\n\n\n<p><a href=\"https:\/\/popia.co.za\/section-5-rights-of-data-subjects\/\" target=\"_blank\" rel=\"noopener\">Section 5<\/a> covers the rights of data subjects under POPIA. They include rights to:<\/p>\n<ul>\n<li>be notified that their personal information is\/has been collected<\/li>\n<li>be informed if a processor holds their personal information and to request access to it<\/li>\n<li>request correction, destruction, or deletion of their personal information<\/li>\n<li>object to\/withdraw consent for the processing of their personal information, in whole or for specific purposes<\/li>\n<li>not be subject to decisions made by automated processing of personal information that\u2019s intended to provide a<\/li>\n<li>profile of them (which can include AI use)<\/li>\n<li>submit a complaint to the regulator regarding any alleged interference with their rights<\/li>\n<li>initiate civil proceedings regarding \u201calleged interference\u201d (aka the right to sue)<\/li>\n<\/ul>\n<p>POPIA does not include a right not to be discriminated against when exercising one\u2019s other rights as a data subject. The <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/the-eu-general-data-protection-regulation\/\">GDPR<\/a> doesn\u2019t either, though the <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/california-consumer-privacy-act\/\">CCPA<\/a> does. Note that POPIA uses an opt-in model of data subject consent, i.e. consumers\u2019 consent must be obtained prior to collection or processing of their personal information.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-key-definitions-from-south-africa-s-protection-of-personal-information-act\">Key definitions from South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p>Definitions of key terms in POPIA are in <a href=\"https:\/\/popia.co.za\/section-1-definitions\/\" target=\"_blank\" rel=\"noopener\">Section 1<\/a>.<\/p>\n<h4>Personal information<\/h4>\n<p>Covered in <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/\" target=\"_blank\" rel=\"noopener\">Chapter 3, Part A<\/a>, this is information that relates to \u201can identifiable, living, natural person\u201d or identifiable, existing juristic person. Personal information can include, but is not limited to:<\/p>\n<p><strong>(a)<\/strong> race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person;<br \/>\n<strong>(b)<\/strong> the education or the medical, financial, criminal or employment history of the person;<br \/>\n<strong>(c)<\/strong> any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person;<br \/>\n<strong>(d)<\/strong> biometric information of the person;<br \/>\n<strong>(e)<\/strong> personal opinions, views or preferences of the person;<br \/>\n<strong>(f)<\/strong> correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence;<br \/>\n<strong>(g)<\/strong> views or opinions of another individual about the person; and<br \/>\n<strong>(h)<\/strong> name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person<\/p>\n<p>It should be noted that while physical or mental health, religion, disability, ethnic origin, colour, sexual orientation, and some other information are included in POPIA\u2019s definitions of \u201cpersonal information\u201d, in fact they qualify as \u201cspecial personal information\u201d and thus require specialized and\/or restricted handling. In some cases processing of this type of information is prohibited.<\/p>\n<h4>Special personal information<\/h4>\n<p>This type of personal information is covered in <a href=\"https:\/\/popia.co.za\/section-26-prohibition-on-processing-of-special-personal-information\/\" target=\"_blank\" rel=\"noopener\">Section 26<\/a>, or, more specifically, there are prohibitions on processing this type of personal information due to the potential for it to be used harmfully. Types of personal information classified as \u201csensitive\u201d include:<\/p>\n<p><strong>(a)<\/strong> religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject; or<\/p>\n<p><strong>(b)<\/strong> criminal behaviour of a data subject to the extent that such information relates to\u2014<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li>the alleged commission by a data subject of any offence; or<\/li>\n<li>any proceedings in respect of any offence allegedly committed by a data subject or the disposal of such proceedings.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Processing special personal information is prohibited unless it is performed under the exceptions outlined in <a href=\"https:\/\/popia.co.za\/section-27-general-authorisation-concerning-special-personal-information\/\" target=\"_blank\" rel=\"noopener\">Section 27<\/a>, which include consent, legal obligations, the subject having already made the information public, and other stipulations.<\/p>\n<h4>Processing<\/h4>\n<p>This refers to \u201cany operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including\u2014<\/p>\n<p><strong>(a)<\/strong> the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use;<br \/>\n<strong>(b)<\/strong> dissemination by means of transmission, distribution or making available in any other form; or<br \/>\n<strong>(c)<\/strong> merging, linking, as well as restriction, degradation, erasure or destruction of information;<\/p>\n<h4>Data subject<\/h4>\n<p>The natural or juristic person to whom personal information relates. Refers to persons residing in South Africa. A juristic person is an organization legally recognized to have rights and responsibilities like a human individual.<\/p>\n<h4>Responsible party<\/h4>\n<p>POPIA does not refer to \u201ccontrollers\u201d like some other privacy laws, i.e. the party responsible for the collection and processing of data, and, as a result, safeguarding it as well. POPIA does refer to the responsible party, meaning \u201ca public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information\u201d.<\/p>\n<h4>Operator<\/h4>\n<p>Under some other privacy laws, the operator performs the processing for the controller. Under POPIA, the operator does this for the responsible party. Specifically, the operator is \u201ca person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party\u201d.<\/p>\n<h4>Regulator<\/h4>\n<p>The data protection authority, officially the Information Regulator (SAIR), as defined and with duties covered in <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-5\/part-a\/\" target=\"_blank\" rel=\"noopener\">Sections 39-54<\/a>, including education, guidance, research, monitoring, handling complaints and enforcement. This entity is also responsible to advise on and direct the evolution of the law.<\/p>\n<h4>De-identification<\/h4>\n<p>Some privacy laws refer to the anonymization of data. Under POPIA, the term is de-identification, which \u201cin relation to personal information of a data subject, means to delete any information that\u2014<\/p>\n<p><strong>(a) <\/strong>identifies the data subject;<br \/>\n<strong>(b)<\/strong> can be used or manipulated by a reasonably foreseeable method to identify the data subject; or<br \/>\n<strong>(c) <\/strong>can be linked by a reasonably foreseeable method to other information that identifies the data subject\u201d<\/p>\n<h4>Child<\/h4>\n<p>A natural person under the age of 18 who is not legally competent to consent to actions or decisions. A competent person (an adult of over the age of 18 legally able to make decisions for a child) is required where consent regarding a child\u2019s personal information is needed.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-definition-of-consent-under-south-africa-s-protection-of-personal-information-act\">Definition of consent under South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p>Per the definitions in Section 1, consent under POPIA is \u201cany voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information\u201d. Consent is one of the legal bases for data processing, as outlined in <a href=\"https:\/\/popia.co.za\/section-11-consent-justification-and-objection\/\" target=\"_blank\" rel=\"noopener\">Section 11<\/a>.<\/p>\n<p>Like the GDPR and some other international privacy laws, POPIA uses an opt-in model of consent, so generally data subject consent must be procured from a legally competent person, or their representative in the case of a child, before collecting or processing their data.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-legal-bases-under-south-africa-s-protection-of-personal-information-act\">Legal bases under South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p><a href=\"https:\/\/popia.co.za\/section-11-consent-justification-and-objection\/\" target=\"_blank\" rel=\"noopener\">Section 11<\/a> covers justifications for personal information processing, commonly referred to as \u201clegal bases\u201d in the GDPR and elsewhere. These requirements are quite similar to those listed in the GDPR:<\/p>\n<p><strong>(a)<\/strong> the data subject or a competent person where the data subject is a child consents to the processing;<br \/>\n<strong>(b)<\/strong> processing is necessary to carry out actions for the conclusion or performance of a contract to which the data subject is party;<br \/>\n<strong>(c)<\/strong> processing complies with an obligation imposed by law on the responsible party;<br \/>\n<strong>(d)<\/strong> processing protects a legitimate interest of the data subject;<br \/>\n<strong>(e)<\/strong> processing is necessary for the proper performance of a public law duty by a public body; or<br \/>\n<strong>(f)<\/strong> processing is necessary for pursuing the legitimate interests of the responsible party or of a third party to whom the information is supplied<\/p>\n<p>Justification like legitimate interest might seem convenient as it would not require obtaining data subject consent, but as with other laws, entities would not just be able to claim legitimate interest and start collecting and processing personal information at will. There are requirements specific to claiming legitimate interest (and any other legal basis) as well.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-companies-responsibilities-under-south-africa-s-protection-of-personal-information-act\">Companies\u2019 responsibilities under South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p>Under POPIA, companies are not the only organizations required to comply, but those inside and outside of South Africa (but doing business there) are substantially affected.<\/p>\n<p><a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/\" target=\"_blank\" rel=\"noopener\">Chapter 3<\/a> covers companies\u2019 responsibilities, i.e. conditions of lawful processing. <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/\" target=\"_blank\" rel=\"noopener\">Part A<\/a> of Chapter 3 outlines POPIA\u2019s eight conditions for processing personal information that are companies\u2019 responsibilities. The Information Regulator can conduct an assessment or audit of an organizations\u2019 POPIA compliance either by request or on its own initiative (<a href=\"https:\/\/popia.co.za\/section-40-powers-duties-and-functions-of-regulator\/\" target=\"_blank\" rel=\"noopener\">Section 40<\/a>).<\/p>\n<h4>Accountability<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/section-8-responsible-party-to-ensure-conditions-for-lawful-processing\/\" target=\"_blank\" rel=\"noopener\">Section 8<\/a>, the responsible party must ensure conditions for lawful processing, such as the general ones for processing of personal information, as well as specific conditions and prohibitions for processing of sensitive personal information or the information of children<\/p>\n<h4>Processing limitation<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-2-processing-limitation\/\" target=\"_blank\" rel=\"noopener\">Sections 9-12<\/a>, the responsible party does not infringe on data subjects\u2019 rights and limits processing to only that which is needed for the stated purpose, for which they have a legal basis, and respond to requests or complaints from data subjects regarding their personal information.<\/p>\n<h4>Purpose specification<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-3-purpose-specification\/\" target=\"_blank\" rel=\"noopener\">Sections 13-14<\/a>, the responsible party can only collect and process personal information for a specific, stated and legal purpose, can only retain the information for as long as necessary to fulfill the purpose, and must securely store, restrict access to, and delete the information as necessary.<\/p>\n<h4>Further processing limitation<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/section-15-further-processing-to-be-compatible-with-purpose-of-collection\/\" target=\"_blank\" rel=\"noopener\">Section 15<\/a>, for any further processing of the information beyond the stated and legal purpose, a number of conditions must be met, including, potentially, obtaining new data subject consent. This also affects retaining personal information after the period of time necessary for the original processing purpose.<\/p>\n<h4>Information quality<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/section-16-quality-of-information\/\" target=\"_blank\" rel=\"noopener\">Section 16<\/a>, the responsible party must reasonably ensure that personal information collected and processed is complete, accurate, and up to date. Related to this is being responsive to requests or complaints from data subjects regarding access to, update of, or deletion of their personal information.<\/p>\n<h4>Openness<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-6-openness\/\" target=\"_blank\" rel=\"noopener\">Sections 17-18<\/a>, the responsible party must maintain documentation regarding all processing activities, and take reasonable steps to ensure that data subjects are notified about the conditions of processing and can contact the responsible party. Information regarding processing activities and related requirements also need to be easily accessible to data subjects, e.g. via a website cookie or privacy policy.<\/p>\n<h4>Security safeguards<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-7-security-safeguards\/\" target=\"_blank\" rel=\"noopener\">Section 19-22<\/a>, the responsible party must take reasonable actions to ensure the security of all personal information processed, including if it is passed to other parties (e.g. the operator, for processing), and to take appropriate and immediate action if there is a breach of security, which would include contacting the Regulator and affected data subjects.<\/p>\n<h4>Data subject participation<\/h4>\n<p>Per <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-8-data-subject-participation\/\" target=\"_blank\" rel=\"noopener\">Sections 23-25<\/a>, data subjects have rights of request and access to their personal information, to which responsible parties must be responsive. There are also conditions under which such requests can be denied.<\/p>\n<h4>Information Officer<\/h4>\n<p>All organizations that are required to comply with POPIA must have an information officer, which is the same as a data protection officer or similar titles. Depending on the volume and types of duties, it may also be necessary to appoint one or more Deputy Information Officers (<a href=\"https:\/\/popia.co.za\/section-56-designation-and-delegation-of-deputy-information-officers\/\" target=\"_blank\" rel=\"noopener\">Section 56<\/a>). The information officer and any deputies must be registered with the Regulator by the responsible party before they can begin performing any duties.<\/p>\n<p><a href=\"https:\/\/popia.co.za\/section-55-duties-and-responsibilities-of-information-officer\/\" target=\"_blank\" rel=\"noopener\">Section 55<\/a> covers their duties and responsibilities, which include encouraging compliance, managing requests, working with the Regulator on investigations, and related duties. <a href=\"https:\/\/popia.co.za\/section-56-designation-and-delegation-of-deputy-information-officers\/\" target=\"_blank\" rel=\"noopener\">Section 56<\/a> covers the designation of deputy information officers, if needed.<\/p>\n<p>More granularly, the information officer will be involved in tasks like drafting and maintaining the privacy policy and other related documentation, conducting risk assessments, training employees, drafting and maintaining contracts with third parties, handling security issues \u2014 including data breaches \u2014 and reporting\/liaising with the Regulator and data subjects affected, and other tasks.<\/p>\n<h4>Data transfers<\/h4>\n<p>POPIA goes into less detail regarding data transfers (\u201ctransborder information flows\u201d) than the GDPR does, but there are still restrictions in the name of privacy and security, outlined in <a href=\"https:\/\/popia.co.za\/section-72-transfers-of-personal-information-outside-republic\/\" target=\"_blank\" rel=\"noopener\">Section 72<\/a>. Broadly, the conditions are similar to legal bases for personal information processing, e.g. contractual agreement, data subject consent, performance of a contract, legitimate interest, etc.<\/p>\n<p>POPIA does not have a requirement for adequacy decisions, i.e. international agreements among countries where it has been determined that the country or organization in question has established an adequate level of data protection. These decisions can significantly streamline contractual requirements and obligations between relevant parties when data transfers need to occur, or cause large headaches when companies have to reorganize operations because of a lack of them.<\/p>\n<h4>Reporting data breaches<\/h4>\n<p><a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/chapter-3\/condition-7-security-safeguards\/\" target=\"_blank\" rel=\"noopener\">Sections 19-22<\/a> cover security safeguards, including specific requirements in the event of a data breach. Unsurprisingly, two key requirements are the notifications to the Regulator and impacted data subjects (unless their identities can\u2019t be determined) as soon as reasonably possible (<a href=\"https:\/\/popia.co.za\/section-22-notification-of-security-compromises\/\" target=\"_blank\" rel=\"noopener\">Section 22<\/a>). There are also specifications for how notifications must be delivered and information they need to contain. The Regulator may also require the responsible party to publicize the breach if it would benefit data subjects (e.g. to help notify them where it was otherwise not possible).<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-south-africa-s-protection-of-personal-information-act-and-children\">South Africa\u2019s Protection of Personal Information Act and children<\/h2>\n\n\n<p>Under POPIA, children are classified as people under age 18, who are not considered legally competent. This is a higher age threshold than with the GDPR. In most cases, in order to process children\u2019s personal information, consent from their parent, guardian, or other legal representative (\u201ccompetent person\u201d) must be obtained in advance, though there are a number of other conditions under which it can take place, broadly following standard processing legal bases, but with additional bases.<\/p>\n<p>Processing of children\u2019s personal information is covered in <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-3-2\/part-c\/\" target=\"_blank\" rel=\"noopener\">Sections 34-35<\/a>, with the latter section covering conditions under which children\u2019s personal information can be processed.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-penalties-and-enforcement-under-south-africa-s-protection-of-personal-information-act\">Penalties and enforcement under South Africa\u2019s Protection of Personal Information Act<\/h2>\n\n\n<p>Enforcement is covered in considerable detail in POPIA in Chapter 10, <a href=\"https:\/\/popia.co.za\/protection-of-personal-information-act-popia\/chapter-10\/\" target=\"_blank\" rel=\"noopener\">Sections 73-99<\/a>. As noted, enforcement comes under the responsibility of the Information Regulator, which is a federal level government position. The Regulator is involved with investigating alleged violations, making referrals to other regulatory bodies, working toward securing warrants from a judge or magistrate, handing down penalties, and other actions.<\/p>\n<p>Under <a href=\"https:\/\/popia.co.za\/section-109-administrative-fines\/\" target=\"_blank\" rel=\"noopener\">Section 109<\/a>, the maximum fine for a POPIA violation is ZAR 10 million. Regarding potential fines, the Regulator must consider the following:<\/p>\n<p><strong>(a)<\/strong> the nature of the personal information involved<br \/>\n<strong>(b)<\/strong> the duration and extent of the breach or issue<br \/>\n<strong>(c)<\/strong> the number of data subjects (potentially) affected<br \/>\n<strong>(d)<\/strong> whether or not the breach raises an issue of public importance<br \/>\n<strong>(e)<\/strong> the likelihood of substantial damage or distress, including injury to feelings or anxiety suffered by data subjects<br \/>\n<strong>(f)<\/strong> whether the responsible party or a third party could have prevented the breach<br \/>\n<strong>(g)<\/strong> any failure to carry out a risk assessment or a failure to operate good policies, procedures and practices to protect personal information<br \/>\n<strong>(h)<\/strong> whether the responsible party has previously committed a POPIA-related offence<\/p>\n<p>POPIA also has provisions (<a href=\"https:\/\/popia.co.za\/section-107-penalties\/\" target=\"_blank\" rel=\"noopener\">Section 107<\/a>) for sanctions of \u201cnatural or juristic persons\u201d and prison sentences of up to 10 years for certain violations for responsible individuals, which isn\u2019t included in the GDPR or LGPD. Offenders can also be required to pay compensation to data subjects.<\/p>\n<p>Less \u201cofficial\u201d penalties for a POPIA violation include loss of reputation and loss of existing customers and failure to attract new ones, which can impact revenues.<\/p>\n\n<div id=\"uc-cta_69ebaa9f7ad24\" class=\"uc-cta uc-cta--illustration uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                            <div class=\"uc-cta__label like-label-m\">Checklist<\/div>\n                                        <div class=\"uc-cta__heading no-default-margin\">POPIA Compliance Checklist<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Companies that want access to South African markets need to be POPIA-compliant.<\/p>\n                <\/div>\n                                                    <div class=\"uc-cta__buttons\">\n                    <a id=\"ba66b81c-147e-4d1a-9100-1a9131acf7a8\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"https:\/\/usercentrics-poc.psapp.devresources\/popia-checklist\/\" target=\"\"><span>Download now<\/span><\/a>                <\/div>\n                                            <\/div>\n                            <div class=\"uc-cta__section\">\n                                                                    <div class=\"uc-cta__section__img-wrapper\">\n                                <img loading=\"lazy\" decoding=\"async\" width=\"1\" height=\"1\" src=\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2021\/09\/Checklist.png\" class=\"attachment-large size-large\" alt=\"icon Checklist\" \/>                            <\/div>\n                                                            <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69ebaa9f7ad24\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n<p>Technology continually evolves, requiring privacy law to evolve with it. The Protection of Personal Information Act in South Africa is older than many other privacy laws, but was rolled out over a number of years, so it is fairly up to date. Part of the Information Regulator\u2019s responsibilities are also to perform research and consult and work with Parliament to evolve the Act.<\/p>\n<p>Ongoing changes in technology will continue to be important considerations with POPIA, like third-party browser cookies, apps and particularly children\u2019s interactions with them, the proliferation of biometric data, AI and machine learning usage, and more. As a well established privacy law, POPIA is well situated to be influential in privacy legislation around Africa and elsewhere in the world.<\/p>\n<p>For companies, there are tools, such as those for consent management, to help navigate POPIA requirements and communicate them to users.<\/p>\n<p>If you have questions about how POPIA affects your business, or about consent management for websites and apps, we\u2019re happy to help. <a href=\"https:\/\/usercentrics-poc.psapp.devbook-a-consultation\/\">Contact one of our experts<\/a>!<\/p>\n\n<div class=\"uc-notice\">\n    <div class=\"uc-notice__icon\">\n        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M10.8177 17.0093H12.8177V11.0093H10.8177V17.0093ZM11.8177 9.00928C12.1011 9.00928 12.3386 8.91344 12.5302 8.72178C12.7219 8.53011 12.8177 8.29261 12.8177 8.00928C12.8177 7.72594 12.7219 7.48844 12.5302 7.29678C12.3386 7.10511 12.1011 7.00928 11.8177 7.00928C11.5344 7.00928 11.2969 7.10511 11.1052 7.29678C10.9136 7.48844 10.8177 7.72594 10.8177 8.00928C10.8177 8.29261 10.9136 8.53011 11.1052 8.72178C11.2969 8.91344 11.5344 9.00928 11.8177 9.00928ZM11.8177 22.0093C10.4344 22.0093 9.13442 21.7468 7.91775 21.2218C6.70108 20.6968 5.64275 19.9843 4.74275 19.0843C3.84275 18.1843 3.13025 17.1259 2.60525 15.9093C2.08025 14.6926 1.81775 13.3926 1.81775 12.0093C1.81775 10.6259 2.08025 9.32594 2.60525 8.10928C3.13025 6.89261 3.84275 5.83428 4.74275 4.93428C5.64275 4.03428 6.70108 3.32178 7.91775 2.79678C9.13442 2.27178 10.4344 2.00928 11.8177 2.00928C13.2011 2.00928 14.5011 2.27178 15.7177 2.79678C16.9344 3.32178 17.9928 4.03428 18.8927 4.93428C19.7927 5.83428 20.5052 6.89261 21.0302 8.10928C21.5552 9.32594 21.8177 10.6259 21.8177 12.0093C21.8177 13.3926 21.5552 14.6926 21.0302 15.9093C20.5052 17.1259 19.7927 18.1843 18.8927 19.0843C17.9928 19.9843 16.9344 20.6968 15.7177 21.2218C14.5011 21.7468 13.2011 22.0093 11.8177 22.0093Z\" fill=\"black\"\/>\n<\/svg>\n    <\/div>\n    <div class=\"uc-notice__content\">\n                <p><strong>To learn more about how POPIA compares to the GDPR and how compliance with one can prepare an organization for compliance with the other, read our article:<\/strong> <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/popia-vs-gdpr\/\"> POPIA vs. GDPR: an overview.<\/a><\/p>\n            <\/div>\n<\/div>\n\n\n","protected":false},"excerpt":{"rendered":"<p>South Africa\u2019s POPIA is a data privacy law that preceded the GDPR by five years. We look at how it addresses consumer rights, companies\u2019 responsibilities and enforcement.<\/p>\n","protected":false},"featured_media":7216,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-363","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>South Africa&#039;s POPI Act Explained | Usercentrics<\/title>\n<meta name=\"description\" content=\"Explore South Africa&#039;s POPI Act, understand its compliance requirements, enforcement, and discover how it safeguards personal data and privacy in the digital age.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"South Africa Protection of Personal Information Act (POPIA)\" \/>\n<meta property=\"og:description\" content=\"We explain what South Africa\u2019s Protection of Personal Information Act (POPIA) means for both consumers &amp; companies. Learn more about POPIA and what it means to you.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T11:03:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"South Africa Protection of Personal Information Act (POPIA)\" \/>\n<meta name=\"twitter:description\" content=\"We explain what South Africa\u2019s Protection of Personal Information Act (POPIA) means for both consumers &amp; companies. Learn more about POPIA and what it means to you.\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/\",\"name\":\"South Africa's POPI Act Explained | Usercentrics\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg\",\"datePublished\":\"2022-04-14T08:37:03+00:00\",\"dateModified\":\"2025-06-26T11:03:56+00:00\",\"description\":\"Explore South Africa's POPI Act, understand its compliance requirements, enforcement, and discover how it safeguards personal data and privacy in the digital age.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg\",\"contentUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg\",\"width\":1000,\"height\":1000,\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"South Africa\u2019s Protection of Personal Information Act (POPIA): A complete guide\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"South Africa's POPI Act Explained | Usercentrics","description":"Explore South Africa's POPI Act, understand its compliance requirements, enforcement, and discover how it safeguards personal data and privacy in the digital age.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"South Africa Protection of Personal Information Act (POPIA)","og_description":"We explain what South Africa\u2019s Protection of Personal Information Act (POPIA) means for both consumers & companies. Learn more about POPIA and what it means to you.","og_url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-26T11:03:56+00:00","og_image":[{"width":1000,"height":1000,"url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"South Africa Protection of Personal Information Act (POPIA)","twitter_description":"We explain what South Africa\u2019s Protection of Personal Information Act (POPIA) means for both consumers & companies. Learn more about POPIA and what it means to you.","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/","name":"South Africa's POPI Act Explained | Usercentrics","isPartOf":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg","datePublished":"2022-04-14T08:37:03+00:00","dateModified":"2025-06-26T11:03:56+00:00","description":"Explore South Africa's POPI Act, understand its compliance requirements, enforcement, and discover how it safeguards personal data and privacy in the digital age.","breadcrumb":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#primaryimage","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg","contentUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2022\/04\/South-Africas-Protection-of-Personal-Information-Act-an-overview-1.jpg","width":1000,"height":1000,"copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"South Africa\u2019s Protection of Personal Information Act (POPIA): A complete guide","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/south-africa-popia-protection-of-personal-information-act-overview\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/363\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media\/7216"}],"wp:attachment":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media?parent=363"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/tags?post=363"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_issue?post=363"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_tag?post=363"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/resource_tag?post=363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}