Law / South Africa

Protection of Personal Information Act 4 of 2013 (POPIA)

Protection of Personal Information Act 4 of 2013 (POPIA) ss. 1-21, 36-38 and 55-59 (application, the general conditions for lawful processing, exemptions, the Information Officer and prior authorisation)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2020.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain a lawful basis, such as the data subject's consent, before processing personal information, and limit processing to the purpose for which it was collected.
  • Secure the integrity and confidentiality of personal information in your possession with appropriate technical and organisational measures, identify the foreseeable risks to it, and keep those measures updated as risks change.
  • Where an operator processes personal information on your behalf, bind it by written contract to the same security measures, and require it to notify you immediately if it has reasonable grounds to believe the information was accessed or acquired by an unauthorised person.
  • Do not retain a record of personal information longer than the purpose for which it was collected requires, and destroy, delete, or de-identify it as soon as reasonably practicable once you are no longer authorised to keep it.
  • Register your information officer with the Information Regulator before that officer takes up duties under the Act.
  • Obtain the Information Regulator's prior authorisation before linking data subjects' unique identifiers across responsible parties, processing criminal-behaviour or credit-reporting information, or transferring special personal information or a child's information to a country without adequate protection.

What it reaches

Obligation class

Consent, Retention, Security, Governance, Licensing

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 3 applies the Act to personal information entered in a record by a responsible party domiciled in the Republic, or using automated or non-automated means there, and section 4 lists the eight conditions for lawful processing that Chapter 3 sets out: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.

Section 8 makes the responsible party accountable for those conditions from when it fixes the purpose and means of processing through the processing itself, and sections 9 to 12 require processing to be lawful, not excessive for its purpose, grounded in the data subject's consent or another listed basis, and ordinarily collected directly from the data subject.

Sections 13 to 16 limit collection to a specific and explicit purpose, bar retaining a record longer than that purpose needs, require further processing to stay compatible with the original purpose, and require the information to be kept complete, accurate and updated.

Sections 19 to 21 require a responsible party to secure the integrity and confidentiality of personal information with appropriate technical and organisational measures against loss, damage or unlawful access, to identify foreseeable risks and keep the safeguards updated, and to bind any operator it uses to the same measures by written contract.

Sections 36 to 38 let the Information Regulator exempt processing that serves the public interest, or clearly benefits the data subject, from one or more of these conditions. Section 55 bars an information officer from taking up duties under the Act until the responsible party has registered that officer with the Regulator.

Sections 57 to 59 require the Regulator's prior authorisation, on pain of prosecution for failing to notify, before processing that links unique identifiers across responsible parties, handles criminal-behaviour or credit-reporting information, or transfers special personal information or a child's information to a country without adequate protection.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app