← All regulators

Regulator profile · IR

Information Regulator (South Africa)

Data privacy regulation under POPIA. Access to information oversight under PAIA. Enforcing data subject rights and holding Responsible Parties accountable.

At a glance

Established
2016 (fully operational 1 July 2021)
Parent act
Protection of Personal Information Act 4 of 2013 (POPIA)
Penalty ceiling
R10 million and/or up to 10 years imprisonment
Key register
POPIA Information Officers Register
Website
https://www.justice.gov.za/inforeg

Scope of supervision

  • All Responsible Parties processing personal information in SA
  • Private bodies subject to PAIA access requests
  • Operators (data processors) mandated by Responsible Parties

Governing legislation

Acronym Full name and description
POPIA
Protection of Personal Information Act 4 of 2013
SA's comprehensive data protection law. Eight conditions for lawful processing. Fully enforceable from 1 July 2021.
PAIA
Promotion of Access to Information Act 2 of 2000
Gives effect to the constitutional right of access to information. Private bodies must maintain a PAIA Manual.

POPIA — eight conditions for lawful processing

# Condition and requirement Audit focus
1
Accountability
Responsible Party must ensure compliance and take responsibility for all processing activities.
Governance framework, Information Officer appointment and registration
2
Processing Limitation
Process only with a lawful basis and not in an excessive manner.
Lawful basis documentation, data minimisation assessment
3
Purpose Specification
Collect for specific, explicitly defined, and lawful purposes only.
RoPA purpose fields, privacy notice purpose statements
4
Further Processing Limitation
Further processing must be compatible with original purpose.
Secondary use controls, consent refresh mechanisms
5
Information Quality
Maintain complete, accurate, non-misleading, and up-to-date personal information.
Data quality controls, update request procedures
6
Openness
Notify data subjects of processing. Maintain a PAIA Manual describing information holdings.
Privacy notices, PAIA Manual publication, transparency mechanisms
7
Security Safeguards
Implement appropriate technical and organisational measures. Notify Regulator and data subjects of breaches.
Security policy, breach response plan, ISMS documentation
8
Data Subject Participation
Honour rights of data subjects: access, correction, deletion, and objection to processing.
Data subject rights procedures, response timelines (30 days), request logs

Key obligations on regulated entities

  1. Designate and register an Information Officer (IO) with the Information Regulator
  2. Develop and implement a POPIA Compliance Framework covering all eight conditions
  3. Conduct a Personal Information Impact Assessment (PIIA)
  4. Maintain Records of Processing Activities (RoPA) — complete and current
  5. Provide Privacy Notices to data subjects at point of data collection
  6. Implement a compliant consent management mechanism where consent is the lawful basis
  7. Establish procedures for data subject rights requests (access, correction, deletion) — respond within 30 days
  8. Execute written data processing agreements with all operators (third-party processors)
  9. Implement appropriate technical and organisational security safeguards
  10. Maintain a breach notification procedure — notify Regulator and affected data subjects
  11. Assess cross-border transfer adequacy before transferring personal information outside SA
  12. Compile and publish a PAIA Manual on the organisation's website
  13. Conduct annual POPIA awareness training for all staff processing personal information

Enforcement powers

  • Administrative fines up to R10 million
  • Criminal prosecution — up to 10 years imprisonment for certain offences
  • Compliance notices requiring remediation
  • Enforcement notices for specific processing cessation
  • Civil claims by affected data subjects

Key register: POPIA Information Officers Register (online portal)