Skip to main content
South Africa · Reviewed September 2026

What Is POPIA? Protection of Personal Information Act 4 of 2013

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's principal comprehensive personal-information statute. The official government description says it protects information processed by public and private bodies, establishes minimum processing requirements, creates the Information Regulator, addresses unsolicited electronic communications and automated decision-making, and regulates cross-border information flows. The statute commenced in phases. The South African Government records provisions beginning in April 2014, July 2020, June 2021, and July 2021, with the main processing, rights, and enforcement provisions in force by 1 July 2021. The 6 March 2026 notice under section 112(2)(c) is limited to health-information processing by eight named responsible-party categories: insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, and institutions working for those bodies. It does not create a general non-health deletion right for data-broker records. This page is a source-backed orientation, not legal advice. POPIA can support access, correction, deletion, objection, and complaint steps in the circumstances described by the Act, but it does not create one universal data-broker form, required field set, or guaranteed removal outcome.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Protection of Personal Information Act 4 of 2013
Short code
POPIA
Jurisdiction
South Africa
Enacted
2013
Last major update
Phased commencement completed on 1 July 2021; 6 March 2026 regulations under section 112(2)(c) cover health-information processing by specified responsible parties and commenced on publication
Regulator
Information Regulator of South Africa
Private right of action
Limited

Scope, who POPIA covers

POPIA applies to processing personal information entered in a record by automated or non-automated means when the responsible party is domiciled in South Africa, and in certain cases when a non-domiciled responsible party uses means in South Africa, unless those means are used only to forward the information. The Act contains exemptions and provision-specific conditions, so an online listing alone does not establish applicability.

Protected data

Personal information concerns an identified or identifiable living natural person and, where applicable, an identifiable existing juristic person. The Act separately regulates special personal information and children’s information, and sets conditions for lawfulness, purpose, quality, openness, security, retention, and further processing.

Data subject rights

Right, after providing adequate proof of identity, to ask whether a responsible party holds personal information and request the record or a description of it under section 23

Right under section 24 to request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully

Right to request destruction or deletion of a record that the responsible party is no longer authorised to retain

Right to object to processing on reasonable grounds relating to the person’s situation, subject to legislation and the Act’s exceptions

Right to make a free Form 1 objection, or substantially similar objection, using the delivery methods permitted by the current POPIA Regulations

Right to request correction or deletion through the prescribed Form 2 route where the section 24 conditions apply

Right to protection from certain decisions based solely on automated processing, including an opportunity to make representations in the circumstances described by section 71

Protection against electronic direct marketing unless the consent or existing-customer conditions in section 69 apply, including a free and low-formality opportunity to object

Right to submit a POPIA complaint to the Information Regulator in the prescribed manner and form

Notable features

POPIA is organised around eight conditions for lawful processing: accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards, and data-subject participation. It also contains dedicated chapters on special personal information, children, direct marketing, directories, automated decision-making, cross-border flows, complaints, and enforcement.

Enforcement & penalties

Regulator: Information Regulator of South Africa

Penalties: The Act contains offence-specific criminal penalties, including provisions that can carry a fine or imprisonment of up to 10 years for specified contraventions and up to 12 months for others. Its section 109 administrative-fine text states that a fine may not exceed R10 million, subject to the Act's conditions. These are statutory powers and maximums in the reviewed text, not a prediction of an individual case or current enforcement outcome.

Private right of action: Section 99 provides a civil action for damages against a responsible party for a breach of a provision referred to in section 73, subject to statutory defences and a court’s assessment of the case. A person should obtain South African legal advice before relying on a civil remedy or assuming that a privacy request creates a damages claim.

Relevance to data brokers

POPIA may be relevant when a data broker or directory processes personal information connected to South Africa, but applicability and available relief depend on the broker’s role, processing purpose, source, exemptions, and facts. No general Information Regulator data-broker complaint, deletion, or other broker-specific consumer channel was identified in the current official service list, forms, or complaint portal. The practical route is a Form 1 objection or Form 2 correction/deletion request to the responsible party or Information Officer, followed by a Form 5 general POPIA complaint if the request is ignored, refused, or mishandled. Credit bureaus have a separate sector-specific route under the Credit Bureau Association code; that is not a general data-broker route. The March 2026 notice is limited to health information and its eight listed responsible-party categories, does not list general data brokers, and does not create a general non-health deletion right. A public or people-search listing is not, by itself, proof that removal is mandatory; verify the broker’s current privacy notice and request route and preserve delivery evidence.

Generate requests in under 60 seconds

Generate removal requests for 1,034 US/global profiles, $9

OfflistMe helps draft opt-out requests using the details you choose. Review the provider route and legal basis, then send from your own inbox. The tool is not legal advice and does not guarantee a broker's response.

FAQ

What is POPIA in South Africa?+

POPIA is the Protection of Personal Information Act 4 of 2013. The South African Government describes it as a law that protects personal information processed by public and private bodies, establishes processing requirements, creates the Information Regulator, and regulates issues including direct marketing, automated decision-making, and cross-border flows.

Who can POPIA apply to?+

The Act applies to processing personal information in a record by automated or non-automated means where the responsible party is domiciled in South Africa, and in certain cases to a non-domiciled party using means in South Africa. Exemptions and provision-specific conditions still matter; a listing visible from South Africa does not alone prove that every provision applies.

Can I ask a South African organization for my personal information?+

Section 23 allows a data subject who provides adequate proof of identity to ask whether a responsible party holds personal information and to request a record or description of that information, subject to the Act and applicable access-law grounds. Use the organization’s current published privacy or information-officer route and keep the request evidence.

Can POPIA support correction or deletion of broker data?+

Section 24 allows a request to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained, and to delete records no longer authorised for retention. The section has conditions and exceptions, so POPIA does not make every broker listing removable on demand.

Does POPIA restrict unsolicited electronic marketing?+

Section 69 generally prohibits processing personal information for direct marketing by electronic communication unless the data subject consented or the existing-customer conditions apply. Those conditions include a reasonable, free opportunity to object, and marketing communications must identify the sender and provide a contact for stopping further messages.

How do I complain about a POPIA issue?+

Send a Form 1 objection or Form 2 correction/deletion request to the responsible party or Information Officer first where appropriate. If the matter is unresolved, submit a written Form 5 complaint through the Information Regulator’s eServices portal or another listed channel. The published rules describe acknowledgement and reference within 14 days, pre-investigation notices within 21 days, a 21-day response period for the responsible party, and an aim to complete pre-investigation within 30 days; the portal’s approximately three-month simple-case and up-to-12-month complex-case periods are practical estimates, not statutory guarantees. A Form 20 internal-review request may be made within 14 days on the current guidance, and a High Court appeal may be available within 180 days; check the official pages before filing.

What does South Africa’s March 2026 POPIA notice cover?+

The notice concerns health-information processing by eight listed responsible-party categories: insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, and institutions working for those bodies. It does not list general data brokers and does not create a general deletion right for ordinary non-health broker data; POPIA’s ordinary rights and limitations, including section 24 where applicable, remain the relevant framework.

Does POPIA guarantee that a data broker will remove my information?+

No. POPIA provides rights and regulatory routes, but the result depends on the responsible party, the processing purpose and source, the request facts, statutory exceptions, and the current route. OfflistMe can help draft a request for review and sending; it does not decide legal applicability or guarantee a broker response.

Official sources & citations

Other international privacy regimes

POPIA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:

United Kingdom · enacted 2018What is UK GDPR?Canada · enacted 2000What is PIPEDA?Brazil · enacted 2018What is LGPD?India · enacted 2023What is DPDP Act?Australia · enacted 1988What is Privacy Act 1988?Japan · enacted 2003What is APPI?China · enacted 2021What is PIPL?France · enacted 1978What is Loi Informatique et Libertés?Germany · enacted 2018What is BDSG?Argentina · enacted 2000What is Law 25.326?Philippines · enacted 2012What is RA 10173?Malaysia · enacted 2010What is Malaysia PDPA?United Arab Emirates · enacted 2021What is UAE PDPL?Republic of Korea · enacted 2011What is Korea PIPA?Netherlands · enacted 2018What is UAVG?Nigeria · enacted 2023What is NDPA?Pakistan · enacted 2016What is PECA + Art. 14?Peru · enacted 2011What is Law 29733?Saudi Arabia · enacted 2021What is PDPL?Thailand · enacted 2019What is Thai PDPA?Türkiye · enacted 2016What is KVKK?Viet Nam · enacted 2025What is Law No. 91/2025?Poland · enacted 2018What is Poland GDPR + UODO Act?Portugal · enacted 2019What is Portugal GDPR + Lei 58/2019?Romania · enacted 2018What is Romania GDPR + Law 190/2018?Bangladesh · enacted 2026What is Act No. 63 of 2026?Chile · enacted 2024What is Law 21.719?Colombia · enacted 2012What is Law 1581?Egypt · enacted 2020What is Law No. 151 of 2020?Indonesia · enacted 2022What is UU PDP?Israel · enacted 1981What is Privacy Law 5741-1981?Kazakhstan · enacted 2013What is Law No. 94-V?Mexico · enacted 2025What is LFPDPPP (2025)?Albania · enacted 2024What is Law 124/2024?Armenia · enacted 2015What is HO-49-N?Azerbaijan · enacted 2010What is Law 998-IIIQ?Bosnia and Herzegovina · enacted 2025What is Law 12/25?Hungary · enacted 2011What is Info tv. + GDPR?Iceland · enacted 2018What is Act No. 90/2018 + GDPR?Jamaica · enacted 2020What is Data Protection Act 2020?Kenya · enacted 2019What is Data Protection Act 2019?Kyrgyzstan · enacted 2025What is Digital Code?Latvia · enacted 2018What is PDL?Luxembourg · enacted 2018What is Law of 1 August 2018?Malta · enacted 2018What is Chapter 586?Republic of Moldova · enacted 2024What is Law no. 195/2024?Mongolia · enacted 2021What is Law on Personal Data Protection?Montenegro · enacted 2008What is Law on Personal Data Protection?Morocco · enacted 2009What is Law 09-08?Estonia · enacted 2018What is IKS?Georgia · enacted 2023What is Law No. 3144?Ghana · enacted 2012What is Act 843?Greece · enacted 2019What is Law 4624/2019?North Macedonia · enacted 2020What is Law 42/2020?Russian Federation · enacted 2006What is 152-FZ?Senegal · enacted 2008What is Law No. 2008-12?Serbia · enacted 2018What is Law 87/2018?Slovakia · enacted 2018What is Act No. 18/2018 Coll.?Slovenia · enacted 2022What is ZVOP-2?Sri Lanka · enacted 2022What is PDPA?Tunisia · enacted 2004What is Organic Law No. 2004-63?Ukraine · enacted 2010What is Law No. 2297-VI?Bulgaria · enacted 2001What is PDPA?Croatia · enacted 2018What is Act on the Implementation of the GDPR?Cyprus · enacted 2018What is Law 125(I)/2018?Czechia · enacted 2019What is Act No. 110/2019 Coll.?Austria · enacted 1999What is DSG?Belgium · enacted 2018What is Belgian Data Protection Act?Denmark · enacted 2018What is Databeskyttelsesloven?Finland · enacted 2018What is Data Protection Act 1050/2018?Norway · enacted 2018What is Personal Data Act?Afghanistan · enacted 2010What is Sectoral Privacy Protections?Algeria · enacted 2018What is Law No. 18-07 + Law No. 25-11?Andorra · enacted 2021What is LQPD?Angola · enacted 2011What is Law No. 22/11?Antigua and Barbuda · enacted 2013What is Data Protection Act 2013?Bahamas · enacted 2003What is DPA 2003?Bahrain · enacted 2018What is Law No. 30 of 2018?Barbados · enacted 2019What is Data Protection Act 2019-29?Belarus · enacted 2021What is Law No. 99-Z?Belize · enacted 2021What is Data Protection Act 2021?Benin · enacted 2018What is Code du numérique, Book V?Bhutan · enacted 2018What is ICM Act 2018 + NDGF 2025?Bolivia (Plurinational State of) · enacted 2009What is Art. 21(2), 25, 130–131 + Law 254?Botswana · enacted 2024What is Data Protection Act 2024?Brunei Darussalam · enacted 2025What is PDPO 2025?Burkina Faso · enacted 2021What is Loi n°001-2021/AN?Burundi · enacted 2026What is Law No. 1/03 of 2026?Cabo Verde · enacted 2001What is Lei n.º 133/V/2001?Cambodia · enacted 2019What is Fragmented privacy framework?Cameroon · enacted 2024What is Law No. 2024/017?Central African Republic · enacted 2024What is Law No. 24.001?Costa Rica · enacted 2011What is Ley 8968?Ecuador · enacted 2021What is LOPDP?El Salvador · enacted 2024What is LPDP?Dominican Republic · enacted 2013What is Ley 172-13?Sweden · enacted 2018What is GDPR + Data Protection Act?Malawi · enacted 2024What is Malawi DPA 2024?Mali · enacted 2013What is Mali Law 2013-015?Mauritania · enacted 2017What is Mauritania Law 2017-020?Mauritius · enacted 2017What is Mauritius DPA 2017?Monaco · enacted 2024What is Monaco Law 1.565?Nepal · enacted 2018What is Nepal Privacy Act 2075?Oman · enacted 2022What is Oman PDPL?Panama · enacted 2019What is Panama Ley 81/2019?Paraguay · enacted 2025What is Paraguay Law 7593/2025?Qatar · enacted 2016What is Qatar Law No. 13 of 2016?Rwanda · enacted 2021What is Rwanda Law 058/2021?Saint Lucia · enacted 2011What is Saint Lucia DPA 2011?Togo · enacted 2019What is Togo Law 2019-014?Turkmenistan · enacted 2017What is Turkmenistan Law 519-V?United Republic of Tanzania · enacted 2022What is Tanzania PDPA 2022?Uruguay · enacted 2008What is Uruguay Ley 18.331?Vanuatu · enacted 2024What is Vanuatu DPPA 2024?Zimbabwe · enacted 2021What is Zimbabwe Cyber and Data Protection Act?Chad · enacted 2015What is Chad Law 007/PR/2015?Comoros · not enacted in this profileWhat is Comoros Personal Data Law 2014?Congo · enacted 2019What is Congo Law 29-2019?Côte d'Ivoire · enacted 2013What is Côte d'Ivoire Law 2013-450?Cuba · enacted 2022What is Cuba Law 149/2022?Democratic People's Republic of Korea · enacted 2022What is DPRK Information Law materials?Democratic Republic of the Congo · enacted 2023What is DRC Digital Code 2023?Djibouti · enacted 2025What is Djibouti Digital Code 2025?Equatorial Guinea · enacted 2016What is Equatorial Guinea Law 1/2016?Eswatini · enacted 2022What is Eswatini Data Protection Act 2022?Ethiopia · enacted 2024What is Ethiopia Proclamation No. 1321/2024?Fiji · enacted 2018What is Fiji Privacy Framework?Gabon · enacted 2023What is Gabon Law 025/2023?Grenada · enacted 2023What is Grenada Data Protection Act 2023?Guinea · enacted 2016What is Guinea Law L/2016/037/AN?Guyana · enacted 2023What is Guyana Data Protection Act 2023?Haiti · enacted 2018What is Haiti 2018 Data Privacy Order?Iran (Islamic Republic of) · enacted 2003What is Iran Electronic Commerce Act 2003?Jordan · enacted 2023What is Jordan Personal Data Protection Law No. 24 of 2023?Kiribati · enacted 2025What is Kiribati Data Protection Act 2025?Kuwait · enacted 2024What is Kuwait CITRA Decision 2024/26?Lao People's Democratic Republic · enacted 2017What is Lao Law 25/NA?Lebanon · enacted 2018What is Lebanon Law 81/2018?Lesotho · enacted 2011What is Lesotho Data Protection Act 2011?Liberia · not enacted in this profileWhat is Liberia Data Protection Act 2024?Libya · enacted 2022What is Libya Law No. 6 of 2022?Liechtenstein · enacted 2026What is Liechtenstein DSG 2026?Madagascar · enacted 2015What is Madagascar Law 2014-038?Marshall Islands · enacted 2025What is Marshall Islands PDPA 2025?Mozambique · not enacted in this profileWhat is Mozambique Privacy Framework?Myanmar · enacted 2017What is Myanmar Privacy and Security Law?Nicaragua · enacted 2012What is Nicaragua Law No. 787?Niger · enacted 2022What is Niger Law No. 2022-59?Saint Kitts and Nevis · enacted 2018What is Saint Kitts and Nevis DPA No. 5 of 2018?Saint Vincent and the Grenadines · enacted 2003What is Saint Vincent and the Grenadines Privacy Act No. 18 of 2003?San Marino · enacted 2018What is San Marino Law No. 171/2018?Sao Tome and Principe · enacted 2016What is Lei n.º 03/2016?Seychelles · enacted 2023What is Seychelles Data Protection Act 2023?Somalia · enacted 2023What is Somalia Data Protection Act 2023?Syrian Arab Republic · enacted 2024What is Law No. 12 of 2024?Tajikistan · enacted 2018What is Law No. 1537?Tonga · enacted 2025What is Privacy Act 2025?Trinidad and Tobago · enacted 2011What is Trinidad and Tobago DPA 2011?Uganda · enacted 2019What is Uganda DPA 2019?United States of America · enacted 2013What is U.S. Privacy Law?Uzbekistan · enacted 2019What is Law No. O‘RQ-547?Venezuela (Bolivarian Republic of) · enacted 1999What is Constitution Article 28?Yemen · enacted 2012What is Law No. 13 of 2012?Zambia · enacted 2021What is Zambia Data Protection Act 2021?Holy See · enacted 2024What is Decree DCLVII?State of Palestine · not enacted in this profileWhat is Palestinian Data Protection Law (draft)?

Related concepts & guides