← Frameworks / Data Protection

Protection of Personal Information Act (Act 4 of 2013)

South Africa's comprehensive data protection law, closely modelled on EU GDPR principles. Establishes 8 conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Covers responsible party obligations, information officers, data subject rights, transborder data flows, enforcement by the Information Regulator, and criminal offences. Mandatory for all public and private bodies processing personal information in South Africa.

Clause Title SP 800-53 Controls
s5 Rights of data subjects
s8 Condition 1 — Accountability
s9 Condition 2 — Lawfulness of processing
s10 Condition 2 — Minimality
s11 Condition 2 — Consent, justification and objection
s12 Condition 2 — Collection directly from data subject
s13 Condition 3 — Collection for a specific purpose
s14 Condition 3 — Retention and restriction of records
s15 Condition 4 — Further processing limitation
s16 Condition 5 — Information quality
s17 Condition 6 — Documentation by responsible party
s18 Condition 6 — Notification to data subject when collecting personal information
s19 Condition 7 — Security measures on integrity and confidentiality of personal information
s20 Condition 7 — Information processed by operator
s21 Condition 7 — Security measures regarding information processed by operator
s22 Condition 7 — Notification of security compromises
s23-24 Condition 8 — Access to personal information and correction of personal information
s25 Condition 8 — Manner of access
s26-27 Prohibition on processing special personal information — general authorisation
s28-33 Authorisation for processing specific categories of special personal information
s34-35 Processing of personal information of children
s55 Information officer — duties and responsibilities
s56 Deputy information officers — designation and delegation
s57-59 Prior authorisation by Information Regulator
s69 Direct marketing by means of unsolicited electronic communications
s70 Directories
s71 Automated decision-making
s72 Transborder information flows — transfers outside the Republic
s73-99 Enforcement — complaints, investigations, and regulatory powers
s100-109 Offences, penalties, and administrative fines