Skip to main content
Has your work email already leaked?Run the 10-second check
Glossary

POPIA Protection of Personal Information Act

What is POPIA?

South Africa's data protection law. Requires responsible parties to notify the Information Regulator and affected subjects of breaches without unreasonable delay.

POPIA is South Africa’s data protection statute, broadly comparable in intent to the GDPR. It governs how a responsible party, the equivalent of a controller, may process the personal information of a data subject, and it became fully enforceable in July 2021. It applies to processing carried out by parties domiciled in South Africa, and to those outside it who process information within the country.

Lawful processing rests on eight conditions: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Security safeguards is the condition that turns into engineering work, requiring a responsible party to secure the integrity and confidentiality of personal information through appropriate and reasonable technical and organizational measures.

Breach duties are explicit. Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery. Notification to data subjects must describe the possible consequences and what the organization intends to do about it, which presumes you can establish what was actually reached.

How Vijilan covers this
See South Africa

Common questions

What does POPIA stand for?

POPIA stands for the Protection of Personal Information Act, South Africa’s national data protection law. It sets out how organizations may collect, use, store and share personal information, and it is enforced by the Information Regulator.

What are the POPIA breach notification requirements?

When there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the breach. The notice to data subjects must give enough detail for them to take protective steps, including the likely consequences and the measures the organization is taking.

What are the penalties under POPIA?

The Act provides for administrative fines of up to 10 million rand, and for criminal liability with imprisonment of up to 10 years for the most serious offences. The Information Regulator can also issue enforcement notices, and failing to comply with one is itself an offence.

Glossary

POPIA is one signal.
We watch the rest.

Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.