Stay Compliant. Stay Protected.
The Protection of Personal Information Act (POPIA) is South Africa’s data privacy law, designed to safeguard personal information and regulate how it is collected, stored, and shared.
The Protection of Personal Information Act (Act No. 4 of 2013)
POPIA is South Africa’s data privacy law. It regulates how businesses and organisations collect, use, store, and share personal information to protect individuals’ privacy rights.
What is Personal Information?
Any information that identifies a person, including:
- Name, ID, contact details
- Race, gender, age, marital status
- Beliefs or opinions
- Biometrics and online identifiers
Key POPIA Principles
- Consent – Get permission before using personal data
- Purpose Limitation – Use data only for its intended purpose
- Minimality – Collect only what’s necessary
- Rights – People can access, correct, or delete their data
- Security – Protect data from misuse or breaches
- Accountability – You are responsible for compliance
- Openness – Be transparent about data handling
Who Must Comply with POPIA?
All South African entities processing personal data:
Businesses (all sizes), NGOs, schools, and government
Non-Compliance Risks:
Fines up to R10 million and reputational harm.
What is PAIA?
The Promotion of Access to Information Act (Act No. 2 of 2000)
PAIA gives individuals the right to access records held by public or private bodies to protect their rights.
iComply SA – Your POPIA & PAIA Compliance Partner
POPIA Compliance Services
- Appoint and train your Information Officer
- Create data privacy policies
- Perform audits & risk assessments
- Draft consent forms & breach plans
- Provide employee training
- Manage third-party data agreements
PAIA Compliance Services
- Draft and publish your PAIA Manual
- Assist with Information Regulator registration
- Handle annual submissions
- Align with POPIA for integrated access and privacy controls
