What Is POPIA? Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's principal comprehensive personal-information statute. The official government description says it protects information processed by public and private bodies, establishes minimum processing requirements, creates the Information Regulator, addresses unsolicited electronic communications and automated decision-making, and regulates cross-border information flows. The statute commenced in phases. The South African Government records provisions beginning in April 2014, July 2020, June 2021, and July 2021, with the main processing, rights, and enforcement provisions in force by 1 July 2021. The 6 March 2026 notice under section 112(2)(c) is limited to health-information processing by eight named responsible-party categories: insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, and institutions working for those bodies. It does not create a general non-health deletion right for data-broker records. This page is a source-backed orientation, not legal advice. POPIA can support access, correction, deletion, objection, and complaint steps in the circumstances described by the Act, but it does not create one universal data-broker form, required field set, or guaranteed removal outcome.
At a glance
- Full name
- Protection of Personal Information Act 4 of 2013
- Short code
- POPIA
- Jurisdiction
- South Africa
- Enacted
- 2013
- Last major update
- Phased commencement completed on 1 July 2021; 6 March 2026 regulations under section 112(2)(c) cover health-information processing by specified responsible parties and commenced on publication
- Regulator
- Information Regulator of South Africa
- Private right of action
- Limited
- Statutory citation
- Protection of Personal Information Act 4 of 2013
Scope, who POPIA covers
Protected data
Data subject rights
Right, after providing adequate proof of identity, to ask whether a responsible party holds personal information and request the record or a description of it under section 23
Right under section 24 to request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully
Right to request destruction or deletion of a record that the responsible party is no longer authorised to retain
Right to object to processing on reasonable grounds relating to the person’s situation, subject to legislation and the Act’s exceptions
Right to make a free Form 1 objection, or substantially similar objection, using the delivery methods permitted by the current POPIA Regulations
Right to request correction or deletion through the prescribed Form 2 route where the section 24 conditions apply
Right to protection from certain decisions based solely on automated processing, including an opportunity to make representations in the circumstances described by section 71
Protection against electronic direct marketing unless the consent or existing-customer conditions in section 69 apply, including a free and low-formality opportunity to object
Right to submit a POPIA complaint to the Information Regulator in the prescribed manner and form
Notable features
POPIA is organised around eight conditions for lawful processing: accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards, and data-subject participation. It also contains dedicated chapters on special personal information, children, direct marketing, directories, automated decision-making, cross-border flows, complaints, and enforcement.
Enforcement & penalties
Regulator: Information Regulator of South Africa
Penalties: The Act contains offence-specific criminal penalties, including provisions that can carry a fine or imprisonment of up to 10 years for specified contraventions and up to 12 months for others. Its section 109 administrative-fine text states that a fine may not exceed R10 million, subject to the Act's conditions. These are statutory powers and maximums in the reviewed text, not a prediction of an individual case or current enforcement outcome.
Private right of action: Section 99 provides a civil action for damages against a responsible party for a breach of a provision referred to in section 73, subject to statutory defences and a court’s assessment of the case. A person should obtain South African legal advice before relying on a civil remedy or assuming that a privacy request creates a damages claim.
Relevance to data brokers
POPIA may be relevant when a data broker or directory processes personal information connected to South Africa, but applicability and available relief depend on the broker’s role, processing purpose, source, exemptions, and facts. No general Information Regulator data-broker complaint, deletion, or other broker-specific consumer channel was identified in the current official service list, forms, or complaint portal. The practical route is a Form 1 objection or Form 2 correction/deletion request to the responsible party or Information Officer, followed by a Form 5 general POPIA complaint if the request is ignored, refused, or mishandled. Credit bureaus have a separate sector-specific route under the Credit Bureau Association code; that is not a general data-broker route. The March 2026 notice is limited to health information and its eight listed responsible-party categories, does not list general data brokers, and does not create a general non-health deletion right. A public or people-search listing is not, by itself, proof that removal is mandatory; verify the broker’s current privacy notice and request route and preserve delivery evidence.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What is POPIA in South Africa?+
POPIA is the Protection of Personal Information Act 4 of 2013. The South African Government describes it as a law that protects personal information processed by public and private bodies, establishes processing requirements, creates the Information Regulator, and regulates issues including direct marketing, automated decision-making, and cross-border flows.
Who can POPIA apply to?+
The Act applies to processing personal information in a record by automated or non-automated means where the responsible party is domiciled in South Africa, and in certain cases to a non-domiciled party using means in South Africa. Exemptions and provision-specific conditions still matter; a listing visible from South Africa does not alone prove that every provision applies.
Can I ask a South African organization for my personal information?+
Section 23 allows a data subject who provides adequate proof of identity to ask whether a responsible party holds personal information and to request a record or description of that information, subject to the Act and applicable access-law grounds. Use the organization’s current published privacy or information-officer route and keep the request evidence.
Can POPIA support correction or deletion of broker data?+
Section 24 allows a request to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained, and to delete records no longer authorised for retention. The section has conditions and exceptions, so POPIA does not make every broker listing removable on demand.
Does POPIA restrict unsolicited electronic marketing?+
Section 69 generally prohibits processing personal information for direct marketing by electronic communication unless the data subject consented or the existing-customer conditions apply. Those conditions include a reasonable, free opportunity to object, and marketing communications must identify the sender and provide a contact for stopping further messages.
How do I complain about a POPIA issue?+
Send a Form 1 objection or Form 2 correction/deletion request to the responsible party or Information Officer first where appropriate. If the matter is unresolved, submit a written Form 5 complaint through the Information Regulator’s eServices portal or another listed channel. The published rules describe acknowledgement and reference within 14 days, pre-investigation notices within 21 days, a 21-day response period for the responsible party, and an aim to complete pre-investigation within 30 days; the portal’s approximately three-month simple-case and up-to-12-month complex-case periods are practical estimates, not statutory guarantees. A Form 20 internal-review request may be made within 14 days on the current guidance, and a High Court appeal may be available within 180 days; check the official pages before filing.
What does South Africa’s March 2026 POPIA notice cover?+
The notice concerns health-information processing by eight listed responsible-party categories: insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, administrative bodies, pension funds, employers, and institutions working for those bodies. It does not list general data brokers and does not create a general deletion right for ordinary non-health broker data; POPIA’s ordinary rights and limitations, including section 24 where applicable, remain the relevant framework.
Does POPIA guarantee that a data broker will remove my information?+
No. POPIA provides rights and regulatory routes, but the result depends on the responsible party, the processing purpose and source, the request facts, statutory exceptions, and the current route. OfflistMe can help draft a request for review and sending; it does not decide legal applicability or guarantee a broker response.
Official sources & citations
- South African Government: Protection of Personal Information Act 4 of 2013
- Department of Justice: Protection of Personal Information Act 4 of 2013 (full text)
- Justice notice archive: POPIA regulation notice, Government Gazette 54268 / GoN 7198
- Information Regulator South Africa: POPIA complaints and investigations
- Information Regulator eServices portal
- Information Regulator: POPIA forms
- Information Regulator: POPIA Regulations
- Information Regulator: POPIA complaints
- Information Regulator: POPIA complaint portal
- Information Regulator: Rules of Procedure for handling POPIA complaints
- Information Regulator: Credit Bureau Association code
Other international privacy regimes
POPIA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
