Law / South Africa

South Africa

10 of 13 named instruments researched to a stage, across four of the six areas of law we track: 9 in force and 1 proposed. As of 19 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 6 instruments (6 in force) ’20 2021: 1 instrument (1 in force) 2022: 1 instrument (1 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (205 words)

South Africa's comprehensive data-protection regime is the Protection of Personal Information Act 4 of 2013 (POPIA), whose lawful-processing conditions and enforcement machinery commenced on 1 July 2020 with a one-year transitional period, so full compliance and Information Regulator enforcement began on 1 July 2021; the Information Regulator itself was established earlier, under Chapter 5 Part A. POPIA binds both public and private responsible parties, carries no general carve-out for publicly available personal information, treats biometric information (including voice recognition) as special personal information subject to heightened restrictions, prohibits processing a child's personal information outside a short list of grounds, restricts automated decision-making that has legal or substantially similar effect, and conditions any cross-border transfer on an enumerated adequacy, consent, or contractual ground.

A responsible party must register its information officer with the Regulator and obtain the Regulator's prior authorisation before certain higher-risk processing, such as linking unique identifiers across responsible parties or transferring special personal information abroad without adequate protection.

A data subject may bring a civil damages action directly against a responsible party for a breach of the Act, and the Information Regulator may issue administrative fines of up to R10 million or refer conduct for criminal prosecution carrying up to ten years' imprisonment.

Breach notification

Protection of Personal Information Act, notification of security compromises

POPIA, s. 22 (notification of security compromises)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 22(1) requires a responsible party, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, to notify both the Information Regulator and the affected data subject, unless the data subject's identity cannot be established.

Section 22(2) fixes the moment the notification is due from the discovery of the compromise: notification must be made as soon as reasonably possible after that discovery, taking into account the legitimate needs of law enforcement and any measures needed to determine the compromise's scope and restore the responsible party's information system.

Section 22(3) lets the responsible party delay only the data subject's notification, and only where a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation; section 22(4) requires the data subject's notification to be in writing, by at least one of several listed channels, and section 22(5) requires it to describe the compromise's likely consequences, the measures taken or proposed to address it, a recommendation for the data subject, and, if known, the unauthorised person's identity.

Section 21(2) separately requires an operator processing personal information for a responsible party to notify that responsible party immediately on the same reasonable grounds.

What it requires

Comprehensive regime

Protection of Personal Information Act 4 of 2013 (POPIA)

Protection of Personal Information Act 4 of 2013 (POPIA) ss. 1-21, 36-38 and 55-59 (application, the general conditions for lawful processing, exemptions, the Information Officer and prior authorisation)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 3 applies the Act to personal information entered in a record by a responsible party domiciled in the Republic, or using automated or non-automated means there, and section 4 lists the eight conditions for lawful processing that Chapter 3 sets out: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.

Section 8 makes the responsible party accountable for those conditions from when it fixes the purpose and means of processing through the processing itself, and sections 9 to 12 require processing to be lawful, not excessive for its purpose, grounded in the data subject's consent or another listed basis, and ordinarily collected directly from the data subject.

Sections 13 to 16 limit collection to a specific and explicit purpose, bar retaining a record longer than that purpose needs, require further processing to stay compatible with the original purpose, and require the information to be kept complete, accurate and updated.

Sections 19 to 21 require a responsible party to secure the integrity and confidentiality of personal information with appropriate technical and organisational measures against loss, damage or unlawful access, to identify foreseeable risks and keep the safeguards updated, and to bind any operator it uses to the same measures by written contract.

Sections 36 to 38 let the Information Regulator exempt processing that serves the public interest, or clearly benefits the data subject, from one or more of these conditions. Section 55 bars an information officer from taking up duties under the Act until the responsible party has registered that officer with the Regulator.

Sections 57 to 59 require the Regulator's prior authorisation, on pain of prosecution for failing to notify, before processing that links unique identifiers across responsible parties, handles criminal-behaviour or credit-reporting information, or transfers special personal information or a child's information to a country without adequate protection.

What it requires

Cross border transfer

Protection of Personal Information Act, cross-border transfer

POPIA, s. 72 (transfer of personal information outside the Republic)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 72(1) bars a responsible party in the Republic from transferring personal information about a data subject to a third party in a foreign country unless the recipient is subject to a law, binding corporate rules, or a binding agreement that effectively upholds substantially similar processing conditions and substantially similar onward-transfer restrictions, or unless the data subject consents, the transfer is necessary to perform a contract with or for the benefit of the data subject, or the transfer benefits the data subject and consent is not reasonably practicable to obtain but would likely be given.

Section 57(1)(d) separately requires a responsible party to obtain the Information Regulator's prior authorisation before transferring special personal information, or a child's personal information, to a country that does not provide an adequate level of protection.

What it requires

Data subject rights

Protection of Personal Information Act, rights of data subjects

POPIA, ss. 18, 23-25 and 69-71 (the information notice, access and correction, direct marketing and automated decision making)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 18 requires a responsible party, when it collects personal information, to take reasonably practicable steps to tell the data subject what is being collected and its source, the responsible party's identity, the purpose of collection, whether supplying the information is voluntary or mandatory, any transfer intended to a third country, and the data subject's rights of access, correction, objection and complaint to the Information Regulator; section 5 catalogues this and the Act's other data subject rights together.

Section 23 gives a data subject the right to confirm, free of charge, whether a responsible party holds their personal information and to access the record within a reasonable time, in a reasonable manner and an understandable form, and section 24 requires the responsible party to correct or delete personal information the data subject shows is inaccurate, irrelevant, out of date, incomplete, misleading or unlawfully obtained, and to tell the data subject what action was taken.

Section 69 prohibits processing personal information for direct marketing by electronic communication unless the data subject has consented or is an existing customer given a free and simple opportunity to object at collection and on every later marketing contact, and section 70 requires a public subscriber directory to give a data subject the chance to object, free of charge, before including their information.

Section 71 bars a decision with legal or substantially similar consequences for a data subject that is based solely on automated processing of their personal information intended to profile them, unless the data subject can make representations about it and the responsible party explains the underlying logic of the processing.

What it requires

Enforcement supervision

Protection of Personal Information Act, the Information Regulator, enforcement and penalties

POPIA, ss. 39-54 and 73-109 (the Information Regulator, enforcement, civil remedies, offences and administrative fines)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 39 establishes the Information Regulator as an independent juristic person with jurisdiction throughout the Republic. The Regulator's establishment under Chapter 5 Part A commenced ahead of most of the Act, since the Presidency's 1 July 2020 commencement proclamation covered sections 2 to 38 and sections 55 to 109 but not sections 39 to 54.

Section 73 defines interference with the protection of personal information as any breach of the Chapter 3 conditions, non-compliance with sections 22, 54, 69, 70, 71 or 72, or a breach of a code of conduct, and sections 74 to 94 let any person complain to the Regulator, which may conciliate, investigate, refer a matter to its Enforcement Committee, and, under sections 81 to 88, obtain a warrant to enter, search and seize evidence from a responsible party's premises.

Section 95 lets the Regulator serve an enforcement notice requiring a responsible party to take, or stop taking, specified steps, appealable to the High Court within 30 days under section 97, and section 99 lets a data subject, or the Regulator at the data subject's request, bring a civil action for damages against a responsible party for breach of any provision of the Act, regardless of intent or negligence.

Sections 100 to 106 create offences for obstructing the Regulator, breaching confidentiality, failing to comply with an enforcement or information notice, and unlawfully dealing in a data subject's account number; section 107 sets the penalties at up to ten years' imprisonment or a fine, or both, for the most serious of these, and up to twelve months for the rest, and section 109 lets the Regulator impose an administrative fine of up to R10 million by infringement notice, considering factors including the number of data subjects affected and whether the responsible party could have prevented the contravention.

What it requires

Sensitive categories

Protection of Personal Information Act, special personal information and children

POPIA, ss. 26-35 (special personal information and children)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa

In force since 1 July 2020. Binds public and private bodies.

What this law does

Section 26 prohibits processing personal information about a data subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information (a term the Act's definitions extend to fingerprinting, DNA analysis, retinal scanning and voice recognition), or their alleged criminal behaviour or related proceedings, unless section 27 applies.

Section 27 lifts the prohibition where the data subject consents, the processing is necessary to establish or defend a legal right, historical or research purposes apply, the information was deliberately made public by the data subject, or sections 28 to 33 authorise it for a specific category; sections 28 to 32 set narrower authorisations for religious bodies, race-based redress measures, trade unions, political organisations, and health or insurance processing, each barring disclosure to a third party without the data subject's consent, and section 33 authorises processing criminal-behaviour or biometric information by bodies charged with applying criminal law or by a responsible party that obtained it lawfully.

Section 34 separately prohibits processing a child's personal information unless section 35 applies, and section 35(1) permits it only with a competent person's prior consent, to establish or defend a legal right, to comply with international law, for historical or research purposes, or where the child made the information public with a competent person's consent; the Regulator may also authorise processing of a child's information in the public interest under section 35(2), subject to conditions safeguarding the child under section 35(3).

What it requires

Scraping law1 instrument, 1 in force

Research summary (315 words)

South Africa has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrimes Act 19 of 2020 criminalises unlawfully and intentionally accessing a computer system or data storage medium, and unlawfully and intentionally intercepting data, but neither offence turns on defeating a technical access control, so reading a public, unauthenticated page falls outside a plain reading of section 2 only to the extent the access is not itself unlawful; no reported South African case has tested a scraper's liability under either section.

That Act's Schedule repealed sections 85 to 88 of the Electronic Communications and Transactions Act 25 of 2002, which previously carried South Africa's unauthorised-access offence, so the earlier ECTA computer-misuse regime no longer applies and the Cybercrimes Act is the current law. No South African court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act 98 of 1978 permits fair dealing for research, private study, criticism, review, and reporting current events, and a quotation exception for press summaries, but contains no text-and-data-mining exception; the pending Copyright Amendment Bill, 2017 would add a general fair use exception whose section 12A the Constitutional Court held constitutional in June 2026, but the Bill has not been signed into law, so no text and data mining (TDM)-specific exception currently exists.

South African copyright law confers no sui generis database right; a compilation is protected only as a literary work to the extent it shows sufficient skill or effort in selection or arrangement. The Protection of Personal Information Act 4 of 2013 (POPIA) applies to personal information without a general carve-out for information that is publicly accessible, so scraping personal data from a public South African website remains subject to POPIA's lawful-processing conditions.

No South African statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrimes Act, unlawful access and unlawful interception of data

Cybercrimes Act 19 of 2020, ss. 2 (unlawful access) and 3 (unlawful interception of data)Cybercrimes Act 19 of 2020, Government Gazette No. 44651 text

In force since 1 December 2021. Binds public and private bodies.

What this law does

Section 2 makes it an offence to unlawfully and intentionally perform an act in respect of a computer system or data storage medium that places a person in a position to commit an access, interception, tool, or interference offence, and separately makes it an offence to unlawfully and intentionally access a computer system or data storage medium; a contravention carries a fine or imprisonment of up to five years under section 19(1).

Section 3 makes it an offence to unlawfully and intentionally intercept data, including electromagnetic emissions from a computer system carrying it, or to possess data known or reasonably suspected to have been unlawfully intercepted without a satisfactory exculpatory account; a contravention of section 3(1) or (2) carries a fine or imprisonment of up to ten years under section 19(2).

Both offences require the access or interception itself to be unlawful, so a plain reading does not by itself capture reading a public, unauthenticated page that defeats no access control. The Act's Schedule repealed sections 85 to 88 of the Electronic Communications and Transactions Act 25 of 2002, the earlier statute that had carried South Africa's computer-misuse offences.

What it requires

Age gating law1 instrument, 1 in force

Research summary (151 words)

South Africa has no social-media minor-access statute, app-store age-verification requirement, or age-appropriate design code, but has an adult-content age-verification and classification regime under the Films and Publications Act 65 of 1996, as amended by the Films and Publications Amendment Act 11 of 2019 (in force since 1 March 2022).

The amended Act lets a commercial online distributor apply to the Film and Publication Board for accreditation to self-classify the films, games, and publications it distributes, and bars distributing any film, game, or publication, whether self-classified or Board-classified, without a clearly visible label showing its age limit and content nature.

Knowingly distributing content classified X18, or content containing explicit sexual conduct that would justify an X18 classification, to a person under 18 years is a distinct offence carrying a fine of up to R750,000 or imprisonment of up to five years, independent of the general offence of distributing unclassified or refused-classification content.

Adult content age verification (AV)

Films and Publications Act, online distributor self-classification and age-restricted content offences

Films and Publications Act 65 of 1996 ss. 18C (self-classification) and 24A(4) (distribution of restricted content to a minor), as inserted and amended by the Films and Publications Amendment Act 11 of 2019Films and Publications Act 65 of 1996, as amended, consolidated text (South African Legal Information Institute)

In force since 1 March 2022. Binds private bodies.

What this law does

Section 18C lets the Film and Publication Board accredit a commercial online distributor to classify its own films, games, or publications, on condition the distributor applies the Board's classification guidelines and informs the Board of every 'XX' and 'X18' classification it makes, deferring to any classification the Board itself has already made.

Section 18C(6) separately bars distributing any film, game, or publication in South Africa unless it has been classified and carries a clearly visible label showing its age limit and content nature next to the Board's logo. Section 24A(2) makes it an offence, carrying a fine of up to R500,000 or imprisonment of up to five years, to distribute or exhibit an unclassified film, game, or a section 16(2) publication, or one classified 'refused classification' or 'XX'.

Section 24A(4) separately makes it an offence, carrying a fine of up to R750,000 or imprisonment of up to five years, to knowingly distribute or exhibit to a person under 18 years a film, game, or publication classified 'X18', or one containing explicit sexual conduct that would have justified an X18 classification, regardless of whether the distributor itself holds the relevant registration or accreditation.

Note and primary source

News aggregation law2 instruments, 1 in force, 1 proposed

Research summary (195 words)

South Africa has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright Act 98 of 1978 is the only enacted law reaching an aggregator's reproduction of news content.

Section 12(3) permits quoting from a lawfully public work, including a quotation from a newspaper or periodical article in the form of a press summary, subject to a fair-practice and extent-justified test with source and author attribution, and section 12(8)(a) removes copyright protection entirely from news of the day that are mere items of press information, a hot-news-adjacent carve-out with no reported decision applying it to a systematic aggregator.

No statute or reported case addresses whether a hyperlink is a communication to the public or whether framing changes the answer, and the Act predates the concept of a machine-readable text-and-data-mining opt-out.

The pending Copyright Amendment Bill, 2017 would add a general fair use exception at section 12A reaching reproduction for research, criticism, reporting current events, and other purposes assessed against a four-factor test; the Constitutional Court held in June 2026 that section 12A is constitutional, but the Bill has not been signed into law, so no general fair use or text-and-data-mining exception currently exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.